The European Commission has formally charged TikTok with violating the bloc's strict online safety regulations, alleging that design features on the ByteDance-owned platform inadequately protect children from cyberbullying and predatory contact. The preliminary findings, announced on Friday, represent the fourth enforcement action against the short-video platform within two years, underscoring regulators' intensifying scrutiny of how the social media giant manages child protection across its services.

The charges fall under the Digital Services Act, a landmark piece of EU legislation that compels major technology platforms to implement robust safeguards against harmful and illegal content. By classifying these violations as preliminary findings rather than final determinations, the European Commission has triggered a formal process that could culminate in substantial financial penalties. Under DSA provisions, TikTok faces potential fines reaching 6 percent of its annual global turnover—a figure that could run into billions of euros given the company's massive worldwide revenue base.

At the core of the Commission's complaint lies a fundamental architectural concern: TikTok permits children to maintain publicly visible accounts without adequate default protections. This design choice means that content posted by minors can be viewed by anyone on the platform, dramatically expanding exposure to potential harm. The regulator argues that such visibility creates openings for abusers to identify and contact vulnerable young users, while simultaneously subjecting them to harassment from peers.

Beyond public accounts, the Commission identified additional vulnerabilities even within the platform's private account settings. Young users with private profiles remain discoverable through the 'following' and 'followers' lists attached to other accounts—a feature accessible not only to registered TikTok users but also to individuals browsing the platform without creating accounts themselves. This transparency mechanism, while perhaps intended to encourage community connection, effectively undermines the privacy protections that private accounts theoretically offer minors.

The regulatory body has proposed a straightforward remedial framework: TikTok should reconfigure default account settings for minors so that their content reaches only approved TikTok users rather than the broader internet audience. This approach aligns with the Commission's broader philosophy articulated by EU tech chief Henna Virkkunen, who emphasised that robust child protection should be embedded as a default feature rather than requiring parents and young users to navigate multiple opt-in settings. The burden, regulators contend, should rest on platforms to build safety mechanisms into their fundamental architecture rather than relegating protection to optional configurations.

TikTok has responded by defending its existing protections, noting that accounts for users under 18 already incorporate more than fifty preset privacy and safety features designed with expert consultation. The company highlighted that younger teen accounts default to private status and that users below a certain age threshold cannot access direct messaging functionality or have their content appear in the algorithmically-curated For You feed. These countermeasures, TikTok suggested, distinguish its platform from competitors in terms of youth safeguarding.

Despite TikTok's assertions of protective measures, the Commission's charges indicate that European regulators believe these safeguards remain insufficient or improperly configured. The distinction between available features and default settings proves critical to understanding the regulator's position. A privacy option that exists but requires users to discover and activate it differs fundamentally from one that operates automatically unless deliberately disabled—a distinction with profound implications for actual child protection outcomes.

The company now enters a formal response period during which it may examine the Commission's detailed allegations and submit counterarguments before the watchdog issues a final decision. This procedural window offers an opportunity for negotiated settlement or formal defence, though the regulatory trajectory suggests skepticism toward TikTok's current approach. The Commission's willingness to initiate formal charges despite the company's claimed protections indicates that officials view existing measures as falling short of DSA requirements regardless of their technical sophistication.

This latest enforcement action reflects broader tension between TikTok and European authorities concerning platform governance and accountability. Over the preceding two years, the Commission has pursued multiple cases against the platform, with TikTok seeking to resolve some disputes through negotiated concessions while others remain active. The accumulation of charges suggests that piecemeal commitments have failed to satisfy regulators' expectations for systematic redesign of how the platform handles minor users' data visibility and contact exposure.

For Southeast Asian technology policy observers, the EU's aggressive stance carries significant implications. Regional regulators increasingly look to European precedent when shaping their own digital governance frameworks, and TikTok's substantial user base in Malaysia and neighbouring countries means that compliance decisions made for European markets may influence global platform architecture. The question of whether default privacy settings for minors become universal features or remain jurisdiction-specific will shape the user experience for millions of Southeast Asian young people.

The financial exposure represented by potential DSA penalties extends beyond mere regulatory costs; the reputational damage and operational disruption accompanying enforcement actions impose additional competitive pressures on TikTok relative to rivals navigating similar regulatory environments. As the Commission proceeds toward a final determination, the resolution of this case may set precedents that reshape how platforms across the region approach youth protection architecture and default privacy configurations.