European Governments Move to Restrict Social Media Use by Minors
The European Commission issued preliminary findings that TikTok’s product design—including infinite scroll, autoplay, push notifications, and personalized recommendations—may breach the EU Digital Services Act (DSA) by failing to adequately assess and mitigate risks to users’ physical and mental well-being, particularly for minors and vulnerable users. If confirmed, the Commission said the violations could result in penalties of up to 6% of TikTok’s global annual turnover, and it signaled expected design changes such as screen-time breaks, adjustments to recommendation systems, and disabling or reducing features deemed to drive compulsive use.
Separately, Spain announced plans to ban social media access for children under 16 and require age verification by platforms, aligning with a broader European trend toward statutory restrictions on minors’ social media use. The announcement follows similar initiatives across Europe, including Australia’s under-16 restriction (cited as precedent), the Netherlands’ push to bar under-15s, French legislation targeting under-14s, and the UK studying a ban for children 15 and under—indicating accelerating regulatory pressure on platforms to implement enforceable child-safety and access controls.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
5 events from the most recent confirmed update back to the earliest known activity.
TikTok rejects EU allegations and prepares defense
TikTok disputed the Commission's characterization of its platform as 'categorically false' and said it would challenge the preliminary findings. The company was given the opportunity to review the case file and submit a written response before any final decision.
EU issues preliminary DSA findings against TikTok over addictive design
The European Commission notified TikTok of preliminary findings that its design features, including infinite scroll, autoplay, push notifications, and recommender systems, likely violate the DSA by failing to adequately protect users' well-being, particularly that of minors. The Commission said TikTok could face fines of up to 6% of global annual turnover and may need to change core product design if the findings are confirmed.
Spain announces plan to ban social media for children under 16
Spanish Prime Minister Pedro Sanchez announced plans to ban children under 16 from accessing social media and to require platforms to implement age verification, while signaling forthcoming legislation to regulate social media content.
Australia implements under-16 social media restriction
Australia implemented a comparable restriction barring children under 16 from social media, becoming a reference point for similar youth-access proposals later discussed in Europe.
European Commission opens DSA investigation into TikTok
The European Commission opened a formal investigation into TikTok under the Digital Services Act, examining whether the platform properly identified and mitigated systemic risks tied to features such as infinite scroll, autoplay, push notifications, and personalized recommendations, especially for minors.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
4 references tracked. Mallory keeps watching after this page renders.
TikTok under EU pressure to change its addictive algorithm - Help Net Security
helpnetsecurity.com
Open sourceEU threatens TikTok with massive fine over addictive design features | The Record from Recorded Future News
therecord.media
Open sourceEU says TikTok faces large fine over "addictive design"
bleepingcomputer.com
Open sourceSpain will ban social media for kids under 16 | The Record from Recorded Future News
therecord.media
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


