On July 24, 2026, the European Commission issued preliminary findings that TikTok had violated the Digital Services Act by failing to adequately protect the privacy and safety of its minor users. The core finding: TikTok’s default settings allow accounts belonging to users under 18 to be set to “public,” making their videos and profiles visible to anyone — including people who have never created a TikTok account.
This is a preliminary finding, not a final decision. TikTok is contesting it and has the right to respond before any ruling is made. But the Commission has reached final decisions on similar preliminary findings before, and the potential penalty — up to 6% of TikTok’s total annual global revenue — focuses attention.
For parents who use TikTok to share family photos and videos, the Commission’s findings surface a set of privacy questions that exist regardless of how the regulatory process concludes.
What the EU Found TikTok Did Wrong
The Digital Services Act is the EU’s primary framework for regulating how large platforms treat users, particularly vulnerable populations. Under the DSA, very large online platforms like TikTok (with more than 45 million monthly active users in the EU) face heightened obligations, particularly around risk assessments and protecting minors.
The Commission’s findings focus on TikTok’s default settings for accounts identified as belonging to users under 18:
Accounts can be set to public by default. TikTok’s current settings allow minor users to choose whether their account is public or private. The Commission found that the option to make a minor’s account public — visible to anyone on the internet — should not be available by default. The standard should be private by default, with minors having to actively choose public visibility.
Content visible to unauthenticated users. When a minor’s account is set to public, their videos are viewable by people who don’t have TikTok accounts. This means content posted by a child is accessible through web searches and embeds, without any account requirement or age gate.
Risk of contact by adults. Public minor accounts can receive comments and messages from unverified users, including adults. The Commission found TikTok’s controls insufficient to prevent the unwanted contact and predatory behavior risks this creates.
TikTok can respond and present its defense before the Commission decides whether to proceed to a formal non-compliance decision. But the Commission’s preliminary findings reflect a consistent pattern in how regulators have described TikTok’s minor safety practices across multiple investigations.
Why “Default Public” Is the Core Problem
Privacy default settings are, in practice, the privacy settings most people have. Research on digital behavior consistently shows that the majority of users never change default settings — they accept whatever state the app shipped in. Default settings aren’t a neutral starting point; they’re the effective policy for most users.
TikTok is designed around public content. Its core value proposition — a discovery feed that surfaces content from accounts you don’t follow — depends on content being broadly accessible. Public-by-default benefits TikTok’s core product metrics.
For adult users who understand and consent to that visibility, public-by-default is a reasonable product choice. For users under 18, the Commission argues (and consumer advocates broadly agree) that the same default is inappropriate — that children’s content should be private by default, with visibility expanded only through an intentional choice.
The same critique has been applied to other platforms. In 2022, the UK’s Age Appropriate Design Code (also known as the Children’s Code) required platforms to implement privacy-protective defaults for users likely to be children. Google, Apple, and other platforms made changes under pressure from that code. TikTok has made incremental changes in specific markets, but the Commission found those changes insufficient under the DSA’s more demanding framework.
What “Public” Actually Means on TikTok
When a TikTok account is set to public, its content is accessible to:
- Any TikTok user, whether following the account or not, appearing in For You feed recommendations
- Anyone with the link, who can view the video without being logged into TikTok
- Web crawlers and search engines, indexing and surfacing the content in search results
- Third-party embedding, allowing TikTok videos to be displayed on external websites
- Archiving services, which may capture and preserve public content even after the original is deleted
This means a video posted publicly by a child doesn’t stay on TikTok. It can appear in Google searches by the child’s name or description. It can be embedded in third-party articles or forums. It can be downloaded and re-posted elsewhere. The upload is permanent in a practical sense — once content is indexed and redistributed, deleting it from TikTok doesn’t remove it from everywhere it’s reached.
For children specifically, public TikTok videos create a searchable, permanent record that includes: the child’s appearance (and how it changes over time), their voice, their school (visible from uniforms or building backgrounds), their neighborhood (visible from surroundings), their friend group, their daily routines, and their interests and personality.
The Parent-Account Dimension the Ruling Doesn’t Reach
The DSA findings about minor accounts address one part of the family photo sharing problem — the part where a minor is the account holder. But a significant share of children’s content on TikTok is posted not on the child’s own account, but on their parent’s account.
When a parent posts a video of their child on their own adult TikTok account, TikTok’s minor-specific settings don’t apply. The adult account owner can post publicly without restriction — including videos that feature the child prominently. The child isn’t the account holder, so they have no control over the content and receive no protection from minor-specific settings.
This is the sharenting dimension. “Sharenting” — the practice of parents sharing content featuring their children on social media — has become a significant privacy issue as the children depicted grow old enough to have opinions about the content.
France’s sharenting law (2024) gives children the right to request removal of photos and videos shared by their parents. The EU’s GDPR provides children with rights to erasure of data about them. But enforcement of these rights for social media content is difficult in practice — platforms process enormous volumes of content, and individual removal requests require documentation and follow-up that most families don’t navigate.
The TikTok DSA case, if it results in stronger default protections, addresses minor account holders. It doesn’t change the rules for adults posting content featuring children.
How TikTok’s Data Practices Compound the Visibility Problem
Beyond what other users can see, TikTok itself collects significant data from both account holders and the content they post.
TikTok’s privacy policy describes collection of: device identifiers, location data (precise location if permitted, inferred location from IP and SIM data), browsing behavior within the app, face and voice characteristics from videos uploaded for analysis, keystroke patterns, and contact list information. For videos posted on the platform, TikTok’s systems analyze content including faces, objects, text, and audio.
ByteDance, TikTok’s parent company, is headquartered in China. Data localization and access questions related to ByteDance’s access to TikTok user data have been the subject of multiple regulatory investigations. TikTok has stated that EU user data is stored on servers in Norway and Ireland with additional oversight through Project Clover, its data protection framework for Europe. The adequacy of these measures continues to be debated by regulators and security researchers.
The combination of public content visibility and extensive data collection means that a video posted publicly on TikTok generates two types of exposure: the content itself (visible to anyone) and data derived from the content (processed by TikTok’s systems and stored per ByteDance’s policies).
What Parents Are Actually Doing
The privacy conversation around children on social media has shifted noticeably in the past two years, driven by a combination of regulatory pressure, academic research on children’s digital wellbeing, and the first generation of “sharented” children reaching their teens and early twenties and expressing how they feel about having grown up online.
Several practical approaches have emerged among parents who want to share family memories without the exposures of public social media:
Private social media accounts with approved followers only. Setting any account to private limits visibility to a curated list of approved followers — grandparents, close family, trusted friends. This limits the audience significantly. It doesn’t change what the platform itself collects and retains, and it doesn’t protect against screenshots by followers.
Family-specific sharing platforms. Apps like Tinybeans are designed specifically for sharing with family members, with no public discovery features and no advertising model based on content analysis.
Platform-specific family sharing tools. Apple’s Shared Albums and Google Photos Shared Albums allow sharing photos and videos with a defined contact list. The sharing is private and controlled, though both Apple and Google retain the content and have their own data practices.
Dedicated private storage. Services like daftei store personal photos and videos privately by default — there’s no public profile, no algorithmic recommendations to drive public engagement, no social sharing feed. Files stored in daftei are encrypted in transit with TLS 1.3 and at rest with AES-256. daftei doesn’t sell user data, run advertising, or use stored content to train AI models. Family photos and videos stored there are accessible to the account holder, not visible to the internet.
The distinction between storing memories and broadcasting them matters more than it might seem. Social platforms are designed for broadcast — their defaults, algorithms, and incentives push content toward wider distribution. Private storage tools are designed for the opposite purpose: to keep content accessible to you and whoever you explicitly share it with.
When Your Child Has an Opinion About What You Posted
The children who appear in family social media content from ten years ago are teenagers now. In many cases, they have clear and sometimes distressed views about the content their parents shared without their knowledge or consent.
This is increasingly a legal issue, not just a family one. France’s sharenting law establishes that children have rights over content featuring them. GDPR’s right to erasure includes children’s data. Washington state’s digital likeness protection law (effective June 2026) extends protections to AI-generated content depicting minors.
The practical reality is that content posted publicly years ago is often technically irrecoverable even if the original post is deleted — it’s been indexed, screenshotted, embedded, and archived in places the original poster has no access to. The harm from sharenting that children describe is partly the content that exists, and partly the irreversibility of it.
Building a habit of private storage for family content — rather than public sharing — is the intervention that prevents this problem at the source, before it becomes something that needs to be addressed retroactively.
What Might Change After the TikTok Ruling
If the European Commission’s preliminary findings lead to a compliance decision, TikTok would likely be required to make accounts belonging to identified minors private by default and strengthen its age verification mechanisms. These changes would represent a meaningful improvement for the minor account holder dimension of the problem.
What regulatory action doesn’t change: the decision adults make about what to post featuring children on their own accounts. That’s a choice that regulation can inform but can’t fully govern — and it’s the dimension where family habits have the most direct impact on children’s digital footprint.
The DSA process against TikTok reflects where regulatory focus is heading: toward default-protective settings for vulnerable users, mandatory risk assessments for large platforms, and meaningful penalties for non-compliance. Whether or not TikTok’s defense succeeds in the current proceeding, this is the regulatory direction for children’s privacy on major platforms.
For parents making individual decisions about where to share family memories: the regulatory direction is informative, but the practical choice is yours. The question worth sitting with is whether the platform you’re posting on is designed to share content widely or to keep it private — and whether that design matches what you actually want for your family’s most personal moments.
A Note on the EU’s Broader DSA Trajectory
TikTok isn’t the only platform the European Commission has moved against under the DSA. Meta faced DSA-related pressure over addictive design for minors. X (formerly Twitter) has faced investigations over content moderation and transparency requirements. The Commission has also begun preliminary investigations into several other very large platforms.
The DSA framework represents an attempt to impose governance on platforms that have, for most of their existence, operated with minimal legal accountability for the harms they create. The TikTok minors’ privacy case is one instance of that framework being applied — and it illustrates both what the DSA can accomplish (forcing changes to defaults and architecture) and where it runs into limits (governing what individual users choose to share).
For families navigating these questions, the regulatory process is useful context, not a solution. The decisions that protect children’s privacy most effectively are made before content is posted, not after regulators weigh in.