Digital Transformation · July 24, 2026
TikTok Minor Safety Defaults Challenged by EU Under DSA
The European Commission has issued preliminary DSA findings against TikTok, ruling that privacy protections for minors must be on by default, not opt-in.
What happened
The European Commission has issued preliminary findings against TikTok under the Digital Services Act (DSA), concluding that the platform's current approach to protecting younger users falls short of the regulation's requirements. The central concern is that safeguards for minors are structured as opt-in features rather than being switched on by default — a design choice the Commission argues places an unreasonable burden on children and their families to actively seek protection.
Specifically, the Commission's preliminary findings indicate that TikTok should reconfigure the default privacy settings on accounts belonging to minors, moving away from "public" as the baseline. The DSA, which applies to large platforms operating in the European Union, requires that services used by children be designed with their safety as the starting point, not an afterthought accessible through settings menus.
Why it matters
This enforcement action is a direct challenge to a default-setting strategy that is well understood in behavioral economics: platforms routinely exploit status quo bias by making the least protective option the path of least resistance. When "public" is the default, the overwhelming majority of users — particularly younger, less digitally literate ones — will never change it. The Commission is, in effect, demanding that TikTok redesign its choice architecture so that safety is the default, not a conscious upgrade.
For service designers and CX practitioners, the lesson extends well beyond social media. Every default is a decision, and that decision communicates what an organisation truly values. Regulators across multiple jurisdictions are increasingly scrutinising whether default settings serve users or serve the platform's commercial interests. Brands that rely on passive consent and low-friction data exposure as part of their engagement model should treat this ruling as an early signal of where digital service design standards are heading.
The Renascence take
Most commentary on this story will focus on TikTok's regulatory risk or the EU's enforcement credibility. The more important insight sits underneath both: this is a dispute about who bears the cognitive cost of staying safe online, and regulators have decided that cost must not fall on a child.
Default settings are not neutral — they are the most powerful design decision a digital product team makes, because inertia guarantees most users will never move from them. TikTok's architecture transferred the burden of protection onto the least capable users in its ecosystem. Customer-obsessed operators should audit every default they ship, asking not "is this opt-outable?" but "would we be comfortable if a regulator described this default on the front page of a newspaper?" If the answer is no, the default is wrong — and it is only a matter of time before someone says so officially.
Sources
This briefing was written by the Renascence newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage.
More in Digital Transformation
Stay ahead of CX
Get the signal, not the noise.
The stories shaping customer experience — plus the Journal and Experience Loom — in your inbox.