Skip to content
🚨 DPDP Rules 2025: Compliance Deadline 36 weeks awayRead handbook →

Brussels Just Fined 'Public by Default': What the EU's TikTok Ruling Warns Indian Platforms About the DPDP Act

The EU's July 24 finding that TikTok failed to protect minors by default is a preview of how India's DPDP children's-data rules could bite by 2027.

D
DPDPBot Research Team
🕐 10 min read

#Brussels Just Fined 'Public by Default': What the EU's TikTok Ruling Warns Indian Platforms About the DPDP Act

On 24 July 2026, the European Commission told TikTok that letting a 13-year-old flip their account to "public" with a couple of taps is not a design quirk — it is a systemic legal violation. That single decision is the clearest signal yet of where enforcement of children's-data law is heading globally, and it lands squarely on the desk of every platform preparing for India's DPDP Act children's-data rules. India's regime is stricter on paper than Europe's, but it will not be enforced until 2027. The TikTok case shows Indian businesses exactly what that enforcement could look like when it arrives — and where their current product design leaves them exposed.

The European Commission's preliminary finding is blunt: "TikTok accounts of minors do not meet the safety standards required under the Digital Services Act." Users aged 13 to 15 could switch from private to public with almost no friction, and the accounts of 16- and 17-year-olds were visible to anyone online, TikTok login or not. Content from older minors was being surfaced through the "For You" feed to complete strangers. Under the DSA, ByteDance now faces a possible fine of up to 6% of global annual turnover — for a company its size, a number in the billions of dollars. This is the fourth set of preliminary DSA findings against TikTok in roughly two years, following a February 2026 finding over infinite scroll, autoplay and its recommender system.

For Indian readers the instinct is to shrug: TikTok has been banned in India since 2020. That instinct is wrong. The ruling is not really about TikTok. It is about a legal principle — that platforms must deliver a high level of privacy and safety by default to children — and about which regulators are now willing to put a percentage-of-revenue price tag on getting it wrong. India has written an even more aggressive version of that principle into law. The only thing it has not done yet is switch on the meter.

#What the DPDP Act actually demands for children

The Digital Personal Data Protection Act, 2023 treats anyone under 18 as a child — not 13, not 16, but 18. That definition alone makes India's scope far broader than the EU's or the US COPPA regime, which cap "child" protections at 13. Two obligations sit at the centre of Section 9.

First, verifiable parental consent. Before processing any child's personal data, a Data Fiduciary must obtain the consent of a parent or lawful guardian, verified in a way that reasonably confirms the person is an adult and entitled to act for that child. A checkbox that says "I am over 18" does not qualify. Rule 12 of the DPDP Rules, 2025 — notified on 13 November 2025 — spells out how that verification is expected to work, leaning on identity tokens, virtual age tokens and consent-manager infrastructure rather than self-declaration.

Second, and more radical, an absolute prohibition. Section 9(3) bars Data Fiduciaries from tracking or behaviourally monitoring children, and from directing targeted advertising at them. As legal analysts have repeatedly noted, this ban cannot be unlocked by consent. Even if a parent agrees, even if the teenager begs for a personalised feed, the fiduciary still may not profile them for ads. Europe's DSA nudges platforms toward privacy-protective defaults and bans profiling-based ads for minors; India's DPDP writes the prohibition as a flat statutory wall.

Read the TikTok findings against that wall and the contrast is stark. The Commission is spending its enforcement energy forcing TikTok to make teen accounts private by default and to stop pushing minors' content into a public recommendation engine. India's law would go further — the recommender-driven profiling of a 17-year-old that the EU is investigating is not merely a bad default under the DPDP Act; for anyone under 18 it is arguably prohibited outright.

#Why "by default" is the phrase that should worry Indian product teams

The most important word in the Commission's decision is default. Investigators did not accuse TikTok of hiding privacy settings or lying about them. They accused it of shipping a product where the safe choice was not the automatic one — where a child had to actively navigate toward protection instead of away from it. That is a design standard, not a consent standard.

Indian platforms have spent the "build year" of 2026 focused almost entirely on the consent standard: rewriting privacy notices, wiring up consent managers ahead of the November 2026 consent-manager deadline, mapping data flows. Comparatively little attention has gone to whether products are architected to protect minors when nobody clicks anything. The DPDP Act's Section 9(3) prohibition is precisely a by-default obligation — it does not care what consent was collected. A social app, an ed-tech platform, or a gaming service that profiles teenage users to serve them recommendations or ads will not be saved by a well-drafted consent flow. The EU just demonstrated that regulators are perfectly comfortable treating the default configuration itself as the violation.

For the large global platforms that will almost certainly be named Significant Data Fiduciaries in India — Meta, Google, Snap, and the ed-tech and gaming companies with tens of millions of young Indian users — this is not abstract. SDF status brings mandatory Data Protection Impact Assessments, independent audits and a resident Data Protection Officer. A DPIA that fails to flag "our default settings expose 16-year-olds to strangers" is the kind of gap that turns into an enforcement file. The TikTok case is, in effect, a worked example of what a children's-data DPIA is supposed to catch.

#The enforcement gap: strict law, silent regulator

Here is the uncomfortable asymmetry. India has the stricter statute; Europe has the credible enforcer.

The Data Protection Board of India was finally constituted this year — its chairperson and members were appointed on 6 June 2026, and a grievance portal is now live. But the substantive obligations most Indian businesses must meet — notice and consent, breach notification, data-principal rights, and crucially the Section 9 children's-data regime — sit inside an implementation window that runs to 13 May 2027. The consent-manager framework lands around 13 November 2026. Until then, India's world-leading children's-data prohibitions are, functionally, unenforced text.

That gap matters because it shapes corporate behaviour. When a law is written but not policed, compliance becomes a bet on when the regulator will move. The EU's TikTok action changes the odds. It gives the DPBI a template, a precedent, and political cover: a peer regulator has established that "public by default for minors" is a punishable systemic failure, and has attached a revenue-based penalty to it. When India's children's-data provisions go live in 2027, the Board will not be starting from a blank page. It will be starting from Brussels' homework.

There is a second reason to watch closely. This same fortnight, Indian commentators have been openly questioning whether the DPBI is independent enough to enforce against powerful actors at all, given that it sits under the Ministry of Electronics and Information Technology — the very ministry that courts big-tech investment. The TikTok case is a live demonstration of what an independent regulator does with children's-data violations. It sets a bar the DPBI will inevitably be measured against, especially in cases touching global platforms or the government's own data practices.

#GDPR, the DSA, and DPDP: three tools, one target

It is worth being precise about the machinery, because the comparison drives the compliance lesson. The EU enforced this through the Digital Services Act, its content-and-platform-safety regime, not the GDPR. The DSA's "protection of minors" guidelines demand safety and privacy by design; the GDPR separately governs the lawful basis for processing a child's data. Europe, in other words, attacks children's data protection from two directions at once — product-design rules and data-processing rules.

India folds much of that into a single instrument. The DPDP Act is a data-processing law, but Section 9(3)'s ban on behavioural monitoring and targeted advertising reaches into product design in a way the GDPR alone does not. In principle, India has collapsed the DSA's design mandate and the GDPR's consent mandate into one statute. In practice, it has done so with fewer carve-outs for teenagers: where the EU debates whether a 16-year-old deserves a lighter touch than a 13-year-old, India draws no such line before 18. That breadth is India's greatest strength and its biggest enforcement headache — verifying parental consent for every under-18 user across a country of a billion-plus people is a genuinely unsolved operational problem, which is part of why Rule 12 leans so heavily on tokenised, consent-manager-mediated verification.

The practical takeaway for anyone building for Indian users: do not treat the EU's TikTok finding as foreign news. Treat it as a dry run of an audit you will face. The questions the Commission asked TikTok — What is the default visibility of a minor's account? Can a child expose themselves to strangers without friction? Are minors being profiled for recommendations or ads? — are the exact questions a DPDP-era DPIA will ask, and the exact questions the DPBI will ask when a complaint about a child's data crosses its new grievance portal.

#What Indian businesses should do before 2027

The window between now and May 2027 is not a grace period to be idled away; it is the last cheap opportunity to fix architecture before mistakes become penalties. Concretely:

  • Audit your defaults, not just your consent flows. Map every setting that affects a minor — account visibility, discoverability, location sharing, contactability — and ask whether the protective option is the automatic one. If a child has to opt into privacy, you are building the exact product the EU just penalised.
  • Kill profiling of under-18 users. Section 9(3) is not a consent problem you can paper over. If your recommender or ad stack ingests signals from users you know or should reasonably know are minors, that pipeline needs a hard cutoff, not a consent checkbox.
  • Design verifiable parental consent now. Waiting for the consent-manager ecosystem to mature is a trap; the November 2026 framework is the plumbing, but the parent-verification UX is yours to build. Start testing token-based age assurance against real Indian identity rails.
  • Fold "safety by default" into your DPIA. If you are heading for Significant Data Fiduciary status, your impact assessments should explicitly document children's default settings and profiling exposure. The TikTok findings are a ready-made checklist.

Our /resources library has practical templates for children's-data mapping and DPIA scoping under the DPDP framework, and our consent-manager guide walks through the verification models most likely to satisfy Rule 12.

#The bottom line

The EU did not just charge TikTok this week. It publicised a philosophy: children are entitled to privacy and safety by default, and platforms that ship anything less are breaking the law regardless of what consent they collected. India wrote a more demanding version of that philosophy into the DPDP Act two years ago — no profiling of minors, verified parental consent, an 18-year threshold that dwarfs the rest of the world's. The only variable left is enforcement, and the clock on that runs out in May 2027.

Platforms that read the TikTok ruling as someone else's problem are misreading it. It is a preview of their own compliance review, delivered eighteen months early and free of charge. The companies that treat the next year as a design overhaul — not a paperwork exercise — are the ones that will not be writing 6%-of-revenue cheques when India finally switches on the meter.


Sources: European Commission — preliminary DSA finding on TikTok and minors; DPDP Act Section 9; DPDP Rules 2025 — Rule 12; MediaNama on behavioural-monitoring rules; Data Protection Board of India; LiveLaw on DPBI independence.

Automate your DPDP compliance

Capture consent, honour data principal rights, and stay audit-ready — all in one platform.

Start free trial