← All articles

The EU's TikTok Minors Finding Is a Preview of DSA Enforcement for Every Creator Platform

Oarized · 26 July 2026

What Brussels Actually Found

On 24 July 2026, the European Commission announced that TikTok's handling of minors' accounts preliminarily breaches the Digital Services Act (DSA). The finding is narrow and specific: TikTok lets users aged 13 to 15 switch their accounts from private to public with little friction, and the accounts of 16- and 17-year-olds are visible to anyone online, including people who never log in to TikTok at all. Content posted by older minors can also be surfaced through the For You feed to any user, not just accepted followers.

The Commission's framing matters more than the specific toggle. Investigators concluded this is not a UI oversight but a default-settings failure: the platform's baseline configuration, the one a 13-year-old lands on without changing anything, does not keep their profile private in practice. That is the standard the Commission is applying — "privacy by design, not by request." A safety feature that exists but isn't the default doesn't count as protection under the DSA's reading.

This is a preliminary finding, not a final ruling. TikTok now gets to examine the Commission's case file and respond before any binding decision is issued — the same procedural sequence that preceded the Commission's separate February 2026 preliminary finding against TikTok over infinite scroll, autoplay and push notifications as addictive-by-design features. That case and this one are running on parallel tracks, both under the same platform, both unresolved. Two live systemic-risk proceedings against one company in the same year is itself a signal of how much scrutiny large platforms serving under-18 users are now getting in the EU.

The Legal Mechanics: Systemic Risk, Not a Single Bug

The DSA doesn't treat this as a routine content-moderation complaint. TikTok is a Very Large Online Platform (VLOP) under the regulation, which means it is subject to Articles 34 and 35: an obligation to assess "systemic risks" stemming from its service design, including risks to minors' physical and mental well-being, and to put in place "reasonable, proportionate and effective" mitigation measures. Defaulting a 13-year-old's account to public, in the Commission's reading, is a design choice that generates exactly that kind of systemic risk — exposure to unwanted contact, cyberbullying and predatory behaviour — rather than an isolated incident.

That categorization is what makes the enforcement path different from a privacy fine under the GDPR. If the Commission's preliminary finding is confirmed after TikTok's response, Article 74 of the DSA allows fines of up to 6% of a company's total worldwide annual turnover for the underlying infringement, with a separate, lower cap of 1% for procedural failures like not responding to information requests. For a company the size of TikTok, that ceiling is a large enough number that it functions less as a fine and more as a forcing mechanism to change the product.

The Commission has also been explicit that periodic penalty payments can run alongside a fine — recurring charges, calculated as a share of average daily income, that keep accruing until the platform actually implements the required changes. That structure is designed to prevent a company from treating a one-time fine as a cost of doing business and leaving the underlying defaults unchanged.

Why This Reaches Past TikTok

Only a handful of platforms cross the VLOP threshold (45 million-plus monthly EU users) and face Article 34/35 obligations directly. But the reasoning in this finding is not TikTok-specific, and it is the kind of reasoning that shapes how the Commission — and national regulators applying the DSA's general provisions to smaller platforms — will look at any service where minors can hold accounts, post content, or appear in content posted by others.

That matters directly for UGC clipping and creator-payout platforms operating in the Netherlands and the EU, even those far below VLOP scale. Clip libraries built from public social content routinely include creators, or people incidentally filmed, who are under 18. A payout platform's onboarding flow is itself a set of defaults: what a new account can see, who can contact a creator, whether a profile is public before identity or age is verified. The Commission's core objection to TikTok — that the safe setting must be the one nobody has to actively choose — is a standard that travels well beyond social feeds into any product where minors might be users, subjects, or beneficiaries of a payout.

There is also a compliance-signalling effect. Platforms that already treat "privacy by default for minors" as a design requirement, rather than an optional setting buried in account preferences, are the ones least exposed if a national Digital Services Coordinator — the Netherlands' is the Autoriteit Consument & Markt — starts asking the same questions of a smaller platform that the Commission is currently asking TikTok.

What Operators Should Check Now

For anyone running a platform that could plausibly host or pay out to a minor — directly as a user, or indirectly through UGC that features one — this finding is a useful checklist, not just a headline about TikTok.

  • Audit default visibility. Check what a new account with an under-18 birthdate actually defaults to: public or private, discoverable in search or not, contactable by strangers or not. The Commission's objection was specifically about defaults, not the mere existence of a privacy toggle.
  • Check algorithmic surfacing separately from account privacy. TikTok's issue wasn't only account settings — content from 16- and 17-year-olds was being recommended through the For You feed regardless of the account's own privacy status. A platform can get account defaults right and still expose minors' content through a separate recommendation or discovery layer.
  • Revisit age-verification timing. If age is confirmed after an account is already public and active, that gap is itself a risk window. The systemic-risk framing applies to the sequence of events, not just the end state.
  • Document the reasoning, not just the setting. Article 35 mitigation obligations are about demonstrating a reasonable, proportionate process — regulators are asking platforms to show their work, not just point to a settings page.

None of this requires VLOP scale to be relevant. It requires having minors anywhere in the product, whether as account holders or as people appearing in monetized content.