The European Commission has formally determined that TikTok's platform architecture poses significant risks to child safety, publishing its findings on July 24 and triggering what could become a landmark enforcement action against the Chinese-owned social media giant. The investigation identified multiple design flaws that expose young users to harmful interactions and inappropriate contact, violations the Commission says contravene the Digital Services Act, the EU's comprehensive regulatory framework governing online platform behaviour.
At the heart of the Commission's concerns is TikTok's default setting allowing children to maintain public profiles visible to non-users of the platform. This architectural choice fundamentally differs from privacy-focused competitors and creates pathways for potential predators to discover and contact young people. The Commission's statement emphasises that such exposure creates "unwanted contact from potential perpetrators and a risk that content can be used for cyberbullying," transforming what might appear as innocent self-expression into genuine safety vulnerabilities. The openness of these profiles compounds the problem by making young creators' activities discoverable to strangers without authentication barriers.
Equally troubling to regulators is TikTok's algorithmic recommendation system, which actively promotes content created by 16- and 17-year-olds to broader audiences on the platform. Unlike passive visibility, the algorithm's active curation amplifies teenage creators' reach, intensifying both the benefits of viral fame and the accompanying risks of harassment, exploitation, and inappropriate solicitation. The Commission contends this design choice violates the Digital Services Act's mandate that platforms build protective measures into their core infrastructure rather than treating safety as an optional feature users must manually activate.
TikTok's account discoverability mechanisms have likewise drawn regulatory criticism. The Commission found that private accounts—ostensibly more restrictive than public ones—remain surprisingly easy for users to locate and follow, undermining the privacy expectations young users and their parents might reasonably hold when selecting such settings. This gap between theoretical and practical privacy protection reflects a recurring pattern in social media design where safety features exist nominally but fail functionally due to architectural shortcuts or inadequate enforcement mechanisms.
The enforcement pathway now before TikTok offers the company an opportunity to respond to these allegations in writing, though the trajectory appears largely determined. Should the Commission ultimately conclude that TikTok has violated EU law—a likely outcome given the specificity of its findings—the company faces financial penalties reaching six percent of its global annual turnover, a calculation that could easily exceed hundreds of millions of euros given ByteDance's estimated revenue scale. This potential fine carries both immediate financial implications and broader precedential weight, signalling the Commission's willingness to deploy its maximum enforcement powers against platforms failing child protection standards.
The investigation's timing intersects meaningfully with broader European momentum toward age restrictions on social media. France recently became the first EU member state to legislate a social media ban for children under 15, a law passed by overwhelming parliamentary majority on July 21 that represents a significant policy shift toward more paternalistic approaches to digital protection. European Commission President Ursula von der Leyen has previously advocated for such age restrictions, suggesting that TikTok's failures may accelerate adoption of this more restrictive regulatory model across EU member states.
For Malaysian and Southeast Asian observers, this EU enforcement action carries important implications. The region's social media regulatory landscape remains less developed than Europe's, with fewer binding safety requirements imposed on platforms. TikTok's estimated user base exceeds 200 million across Europe, making it one of the continent's most consequential technology platforms, yet its dominance in younger Southeast Asian markets—where digital literacy and regulatory oversight may be more limited—suggests that EU enforcement pressure could prompt improvements benefiting regional users as well. Technology companies typically implement changes globally rather than maintaining fragmented compliance approaches, meaning European standards often establish de facto global baselines.
TikTok's defence rests on claims that teen accounts include more than 50 pre-set privacy and security features activated from account creation, and that the platform restricts direct messaging capabilities for younger teenagers more strictly than competitors. The company argues these measures demonstrate meaningful commitment to child safety, a position that frames the Commission's allegations as potentially exaggerated critiques of genuinely protective architecture. However, the Commission's distinction between features that exist theoretically and protections that function practically suggests TikTok's counterclaim may underestimate the effectiveness gap between nominal and actual safeguards.
The February allegations regarding algorithmic addictiveness, which preceded this latest investigation, compound regulatory pressure on the platform. That investigation identified design patterns that potentially encourage excessive use, a concern distinct from but complementary to child safety issues. Together, these parallel enforcement tracks suggest the Commission views TikTok as systematically prioritising engagement metrics and user growth over the protective requirements the Digital Services Act mandates, establishing a broader pattern of regulatory non-compliance rather than isolated technical oversights.
This investigation exemplifies how the EU's Digital Services Act functions as an enforcement mechanism distinct from earlier legislative frameworks. Rather than establishing vague principles, the Act enables regulators to mandate specific architectural changes and hold platforms accountable through substantial financial penalties. TikTok now faces pressure to redesign core features—potentially reducing algorithmic promotion of teen content, restricting default profile visibility, and enhancing privacy controls—that affect platform functionality and user experience globally. The outcome will likely establish important precedents governing how platforms must balance growth mechanisms with child protection across all markets, with implications extending well beyond European borders into the Southeast Asian digital ecosystem.
