Security Bearish 7

170M EU Users Exposed: TikTok's Default Settings Fail Minors' Privacy, EU Says

Cybersecurity analysis of TikTok's default privacy configuration that exposed 170 million EU users to grooming and cyberbullying, highlighting critical design flaws that turned a popular platform into a vector for child predators.

· 4 min read · Verified by 3 sources ·
Share

Key Takeaways

  • Cybersecurity analysis of TikTok's default privacy configuration that exposed 170 million EU users to grooming and cyberbullying, highlighting critical design flaws that turned a popular platform into a vector for child predators.

Mentioned

TikTok company European Commission company ByteDance company Thomas Regnier person Digital Services Act (DSA) company Meta company META Apple company AAPL

Key Intelligence

Key Facts

  1. 1The European Commission found TikTok violated the DSA by failing to protect children's privacy; adult users could view minors' profiles and content.
  2. 2Children aged 13–15 can easily switch from private to public accounts; private accounts of 16–17-year-olds are visible to anyone on the internet.
  3. 3TikTok has 170 million users in the EU, with 7% of children aged 12–15 spending 4–5 hours daily on the app.
  4. 4If TikTok fails to adequately respond, the EU can impose a fine of up to 6% of its global annual revenue.
  5. 5In February 2026, the EU had already found TikTok breached DSA obligations over 'addictive design' features like autoplay and infinite scrolling.
  6. 6TikTok issued a statement saying it shares the goal of protecting minors and is committed to continuous improvement of its safeguards.

Who's Affected

Minors (13-15)
user_groupNegative
Minors (16-17)
user_groupNegative
Predators/Cyberbullies
threat_actorPositive
TikTok
companyNegative
Platform Safety Confidence

Analysis

For cybersecurity professionals, the EU's findings reveal a fundamental product security flaw: default privacy configurations designed for engagement rather than protection create an attack surface for grooming, cyberbullying, and predatory behavior. With 7% of children aged 12–15 spending 4–5 hours daily on the platform, the scale of exposure is vast, and the technical remedy—effective default privacy—is a clear indication of how design choices can either mitigate or amplify digital threats to vulnerable populations.

On July 24, 2026, the European Commission formally announced that TikTok had violated the Digital Services Act (DSA) by failing to adequately protect the privacy of minors on its platform. The findings center on privacy default settings that permitted adults to view the profiles and content of users under 17, directly contradicting the DSA’s mandate for robust safeguards for children online. Thomas Regnier, Commission spokesperson, was unequivocal: “Children’s content must never be visible to strangers.” The infractions are twofold: children aged 13 to 15 can “easily” switch their accounts from private to public, while the private accounts of 16- and 17-year-olds are visible to anyone on the internet. This systemic vulnerability, according to the Commission, exposed minors to grooming, cyberbullying, and predatory behavior—a failure deemed unacceptable under EU law.

While TikTok’s exact global revenue is not publicly broken out by the company, industry estimates place ByteDance’s 2025 revenue well above $100 billion.

The development is the latest in a series of aggressive enforcement actions by Brussels, which has positioned itself as the world’s leading tech regulator. Meta and Apple have faced their own DSA proceedings, but TikTok’s case now carries particular weight given its enormous user base in the bloc: an estimated 170 million users, the majority of whom are children. The Commission highlighted alarming usage patterns, noting that 7% of children aged 12 to 15 spend four to five hours daily on the app. This scale raises the stakes significantly; any penalty will be calculated as a percentage of the company’s global annual revenue, capped at 6%. For ByteDance, TikTok’s parent, this could translate into billions of dollars.

The earlier DSA ruling against TikTok in February 2026—targeting “addictive design” features like autoplay and infinite scrolling—set a precedent that the platform’s design choices prioritize engagement over user welfare. The current privacy findings deepen that regulatory arc, suggesting a pattern of systematic non-compliance with Europe’s digital safety framework. Regnier stressed that “putting default settings for minors is not a beauty contest under the DSA. It must be effective,” signaling the Commission’s intolerance for cosmetic fixes. The technical remedy required is straightforward: ensure that minors’ accounts are private by default, with no easy toggle to make them public, and that even private accounts are shielded from strangers’ views.

The potential financial penalty is formidable. While TikTok’s exact global revenue is not publicly broken out by the company, industry estimates place ByteDance’s 2025 revenue well above $100 billion. A 6% fine would therefore be a multibillion-dollar sanction, dwarfing many GDPR fines and rivaling the record penalties seen in antitrust cases. Beyond the monetary impact, a non-compliance decision could compel design changes that alter the platform’s virality and engagement mechanics, possibly affecting its commercial model.

TikTok’s immediate response has been conciliatory but guarded: “Protecting minors online is a goal we share, and we are committed to building on our strong track record of continuous improvement.” The company has the opportunity to present its defense before the Commission finalizes its decision. If the response is insufficient, the EU can issue a non-compliance decision and impose the fine. The procedural timeline remains fluid, but the findings themselves are a definitive regulatory statement that will influence how other platforms design age-appropriate experiences.

What to Watch

The broader implications extend beyond TikTok. The DSA’s provisions on minor safety are being stress-tested, and this enforcement action clarifies that regulators will not hesitate to scrutinize default settings and architectural choices. For the tech industry, it signals a shift from content moderation to systemic product safety—an area where cybersecurity and privacy intersect with child protection law. Legal experts will watch closely to see whether TikTok contests the findings in court, potentially triggering a landmark legal battle over the DSA’s extraterritorial reach and the definition of “safety by design.” For investors, the risk of recurring regulatory action adds a premium to compliance costs and may dampen valuation multiples for social media firms reliant on youthful demographics.

Looking ahead, the EU’s resolve seems firm. TikTok must now demonstrate concrete, verifiable changes—likely including technical audits of age-verification systems and default privacy safeguards. The case will serve as a bellwether for the DSA’s enforcement capacity and could accelerate similar actions in other jurisdictions. As children’s online safety climbs the global regulatory agenda, the precedent set here will echo in boardrooms and legislatures worldwide, making this not just a European issue but a defining moment for digital platform governance.

Sources

Sources

Based on 3 source articles

Cite This Page

"170M EU Users Exposed: TikTok's Default Settings Fail Minors' Privacy, EU Says." Cyber Intelligence Brief, July 24, 2026. https://getcyberbrief.com/story/tiktok-privacy-minors-cyber-risk-default-settings

How we covered this story

Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.

Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.

Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.

See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.