TikTok DSA Non-Compliance Finding Issued by EU Over Privacy Settings

Article Content
On July 24, 2026, the European Commission delivered a historic regulatory directive against Big Tech platform architecture, issuing formal preliminary findings of TikTok DSA non-compliance regarding the platform’s handling of minor accounts and inadequate default privacy configurations. The announcement marks a critical enforcement milestone under the European Union’s landmark Digital Services Act (DSA), signaling that international regulators are moving beyond superficial policy checks and directly interrogating code-level user experiences, default account states, and recommendation algorithms. Following an exhaustive multi-year investigation initiated in February 2024, EU regulators concluded that TikTok’s privacy safeguards fail to satisfy mandatory statutory requirements, exposing millions of teenage users—specifically those aged 13 to 17—to unauthenticated web exposure, algorithmic amplification, and unsolicited contact from bad actors.
Under the legal framework of the DSA, particularly Article 28(1), Very Large Online Platforms (VLOPs) that are accessible to minors are legally obligated to guarantee a high baseline level of privacy, safety, and security by design and by default. The regulatory doctrine is absolute: basic protective measures cannot be relegated to obscure opt-in menus, complex multi-step toggles, or easily bypassed user prompts. As Executive Vice-President for Tech Sovereignty, Security, and Democracy Henna Virkkunen explicitly stated during the announcement, “A high level of protection should not be an opt-in; it should be the default.” Commission spokesperson Thomas Regnier reinforced this enforcement posture, noting that “putting default settings for minors is not a beauty contest under the DSA—it must be effective.” By identifying structural failures in how TikTok handles young users’ visibility, the Commission has made clear that user experience choices designed to maximize engagement at the expense of minor privacy constitute actionable regulatory breaches.
Anatomy of TikTok DSA Non-Compliance: Key Architectural Flaws
The preliminary findings detailed by the European Commission reveal systemic design choices within TikTok’s infrastructure that continuously erode user privacy and undermine default safety assurances. Rather than isolating transient software bugs or individual technical glitches, regulators focused on deliberate operational patterns embedded within the application’s user interface and backend distribution systems.
1. Frictionless Privacy Downgrades for Younger Minors
For users between 13 and 15 years of age, TikTok implements a nominal default private setting. However, EU investigators determined that this protection is routinely undermined by frictionless interface controls. The application interface presents minimal friction for young teens seeking to convert their accounts from private to public mode. By failing to integrate meaningful friction, contextual warnings, or secondary verification controls, TikTok allows vulnerable users to easily disable their default privacy shields, leaving their accounts accessible to external data harvesting and unmonitored outreach.
2. Algorithmic Exposure and External Scraping for Older Minors
The regulatory indictment is even more pronounced regarding older teens aged 16 and 17. Under TikTok’s current architecture, accounts belonging to this demographic are permitted to operate in public modes that broadcast content directly to unauthenticated web browsers—allowing individuals without a TikTok account or verified age profile to view, capture, and archive their media. Furthermore, content uploaded by 16- and 17-year-olds is automatically ingested into TikTok’s algorithmic recommendation engine, the global “For You” feed (FYF). This systemic push mechanism distributes youth-generated media across the network, fundamentally mixing minor content into adult feeds.
3. Profile Discoverability and Metadata Leakage
Crucially, the Commission discovered that even when a minor explicitly selects and maintains a Private Account, TikTok’s systemic data architecture continues to leak personal metadata. A private account setting on TikTok does not render the user invisible. External parties can discover private minor profiles by traversing the public “Followers” and “Following” graph structures of connected accounts. Additionally, profile photographs remain globally unmasked and visible to anyone on or off the platform, while basic metadata—including usernames, bio snippets, and social connections—remains indexable. This structural metadata leakage creates significant exposure vectors, granting potential threat actors an unmonitored window into a child’s digital life.
Systemic Risks and the Long-Term Digital Footprint
The EU’s regulatory action extends beyond short-term privacy oversights, pointing toward the long-term societal harms produced by permanent data exposure. When youth-generated content and behavioral metadata are broadcast across the open internet, the digital footprint created during adolescence follows individuals permanently into adulthood.
Regulators highlighted three severe vectors of systemic risk generated by TikTok’s current implementation:
- Predatory Grooming and Unsolicited Contact: Unrestricted visibility and unauthenticated web access allow malicious actors to monitor minor profiles, analyze posting schedules, and initiate unwanted contact across third-party communication channels.
- Cyberbullying and Harassment Cycles: Publicly accessible videos and unmasked profile photos serve as prime targets for malicious scraping, targeted harassment, deepfake generation, and cross-platform cyberbullying campaigns that minors possess little technical means to mitigate.
- Automated Data Harvesting and Profiling: Unauthenticated web endpoints permit commercial web scrapers and AI data-gathering bots to harvest minor content, building persistent behavioral profiles without consent or oversight.
Regulatory Consequences: The 6% Financial Catalyst
The issuance of preliminary findings sets off a structured legal procedure under the Digital Services Act. TikTok now has the opportunity to review the European Commission’s investigative evidence, inspect non-confidential files, and submit formal written defense responses. The European Board for Digital Services will also be formally consulted during the evaluation period.
However, should TikTok fail to convince regulators or refuse to enact structural modifications to its global platform architecture, the financial and operational penalties are severe:
- Financial Penalties: Under DSA Article 52, the European Commission holds statutory authority to levy administrative fines reaching up to 6% of the platform’s global annual turnover. For TikTok’s parent company, ByteDance, such a fine would translate into billions of Euros in punitive damages.
- Mandatory Structural Remediation: Beyond financial sanctions, the EU can issue binding non-compliance decisions ordering TikTok to overhaul its algorithmic recommendation architecture, restrict unauthenticated web access, and re-engineer default account workflows for all users under 18 years of age.
- Periodic Penalty Payments: To enforce compliance, the Commission can impose periodic penalty payments of up to 5% of average daily global turnover for every day of continued non-compliance.
This enforcement action represents a broader, uncompromising regulatory posture adopted by Brussels against tech conglomerates including Meta, Apple, and Alphabet. As European regulators aggressively enforce systemic safety standards, Big Tech platforms can no longer rely on superficial compliance checks or decorative safety toggles.
The Technical User Strategy: Executing a Manual Privacy Audit
While European regulators negotiate platform-level remedies with ByteDance, everyday users, parents, and privacy-conscious individuals cannot afford to wait for corporate structural overhauls. Given that default platform settings remain inherently permissive across many regions, executing a comprehensive manual privacy audit is essential to secure personal accounts against unwanted discoverability and data harvesting.
To systematically mitigate data leakage and platform tracking, users should execute the following technical audit protocol:
Step 1: Enforce Strict Private Account Boundaries
Navigate to Settings and Privacy > Privacy and confirm that Private Account is actively enabled. Ensure that this configuration is locked and re-verified periodically, as platform updates can occasionally alter interface prompts. For accounts belonging to minors, parents should utilize Family Pairing controls to lock account visibility settings entirely.
Step 2: Neutralize Profile Discoverability and Syncing
In the Privacy sub-menu, select Suggest your account to others and disable all underlying options, including Contacts, Facebook Friends, and People who open or send links to you. Next, enter Sync contacts and Facebook friends and toggle both sync settings to off. Severing these connections prevents TikTok from mapping your off-platform social graph and surfacing your account via mutual contacts.
Step 3: Restrict Metadata, Following Lists, and Direct Interactions
To block external graph traversal and unauthenticated indexing, audit the following granular interaction controls:
- Set Following List to Only Me to prevent third parties from auditing your social network.
- Configure Liked Videos and Favorite Sounds to Only Me to mitigate algorithmic profiling.
- Set Direct Messages, Duet, Stitch, and Downloads to No One or Friends Only.
- Disable Profile Views and Post Views to reduce exposure to automated tracking bots.
Step 4: Block Unauthenticated Web Access and Personalization
Navigate to Settings and Privacy > Security > Web Browsing and restrict unauthenticated access states where available. Additionally, under Ads > Personalization, disable targeted advertising based on off-platform activity and data partner tracking.
The Horizon of Algorithmic Accountability
The European Union’s non-compliance findings against TikTok mark a decisive paradigm shift in global tech governance. By explicitly targeting default settings, profile discoverability leaks, and algorithmic pushing into recommendation feeds, the Digital Services Act is redrawing the boundaries of platform responsibility. For years, social media platforms operated under a paradigm where engagement maximization drove code design, leaving user safety as an opt-in afterthought. Brussels has made it unequivocally clear: under modern digital law, privacy by default is non-negotiable.
As TikTok prepares its formal defense, the broader technology industry must take note. Architectural design choices that expose vulnerable demographics to systemic risk are no longer merely ethical oversights—they are high-stakes legal liabilities capable of reshaping the global digital landscape.
Written by
TempMail Ninja
Digital privacy and online security expert. Passionate about creating tools that protect users' identity on the internet.


