Skip to content

Europe · Analysis

Independent · Brussels & Berlin

Technology · Digital regulation

EU Commission finds TikTok and Meta in breach of Digital Services Act transparency rules

The European Commission has issued preliminary findings that both platforms failed to give researchers adequate access to public data, while Meta also fell short on user tools for reporting illegal content and appealing moderation decisions.

By , Technology Editor

Published

7 min read

The European Commission said on Friday it had preliminarily concluded that TikTok and Meta both violated transparency obligations under the Digital Services Act, the EU's flagship legislation for platform accountability. The executive arm of the European Union accused the two companies of failing to give researchers adequate access to public data, a requirement designed to allow independent scrutiny of how content spreads and what effects it may have on users, including minors.

In a statement, the Commission said its investigation found that Facebook, Instagram and TikTok "may have put in place burdensome procedures and tools for researchers to request access to public data. This often leaves them with partial or unreliable data, impacting their ability to conduct research, such as whether users, including minors, are exposed to illegal or harmful content." The finding strikes at a central pillar of the DSA: the idea that systemic risks cannot be assessed if the platforms that hold the data control who gets to see it.

What the Digital Services Act requires of platforms

The Digital Services Act, which entered into force in November 2022 and became fully applicable to very large online platforms and search engines in August 2023, imposes a tiered set of obligations. For platforms designated as very large, those with more than 45 million monthly active users in the EU, Article 40 requires them to provide vetted researchers with access to publicly available data to study systemic risks. The Commission's preliminary view is that both companies have made that access harder than the law allows, through procedural hurdles, technical limitations or both.

The regulation also mandates that platforms give users simple mechanisms to notify illegal content and effective ways to challenge content moderation decisions. The Commission said Meta, for both Instagram and Facebook, fell short on both counts. That part of the finding does not apply to TikTok, at least in this preliminary decision.

Meta's response and the changes it cites

Ben Walters, a spokesperson for Meta, rejected the Commission's conclusions. "We disagree with any suggestion that we have breached the DSA, and we continue to negotiate with the European Commission on these matters," he said. Walters added that the company had introduced changes to its content reporting options, appeals process and data access tools since the DSA came into force and was "confident that these solutions match what is required under the law in the EU." The company did not specify which changes it believes bring it into compliance, nor did it address the researcher access point in detail.

Meta's position reflects a broader pattern: the company has engaged extensively with the Commission on DSA implementation, publishing transparency reports and detailing product changes. But the Commission's preliminary finding suggests those changes have not, in the regulator's view, met the statutory threshold for researcher access or user-facing tools.

TikTok raises a conflict with GDPR

TikTok's response took a different tack. A company spokesperson said the platform was "committed to transparency and values the contribution of researchers" and noted that almost 1,000 research teams had been given access to data through its Research Tools. But the spokesperson added a legal argument: "requirements to ease data safeguards place the DSA and GDPR in direct tension. If it is not possible to fully comply with both, we urge regulators to provide clarity on how these obligations should be reconciled."

The General Data Protection Regulation restricts the processing of personal data, and TikTok argues that providing researchers with broad access to public data could conflict with data minimisation and purpose limitation principles. The Commission has previously acknowledged the need to balance the two regimes but has not issued binding guidance that resolves the tension. TikTok's invocation of GDPR is likely to become a central point of contention if the case proceeds to a formal non-compliance decision.

A pattern of enforcement under the new regulatory framework

The preliminary findings come against a backdrop of escalating enforcement. In April 2025, the Commission fined Meta 200 million euros under the Digital Markets Act for the way it obtained user consent for data collection across its services, the first time the competition-focused legislation had been used to impose a financial penalty. The DMA targets gatekeeper platforms and their market behaviour, while the DSA targets content governance and systemic risk. Together they form a twin regulatory architecture that the EU argues is necessary to constrain the power of the largest digital platforms.

TikTok, owned by China-based ByteDance, has also faced action under existing data protection law. Earlier in 2025, Ireland's Data Protection Commission, which acts as TikTok's lead supervisory authority in the EU, imposed a 530 million euro fine over transfers of European user data to China. That decision was made under the GDPR, not the DSA, but it illustrates the multiple regulatory fronts on which TikTok is now engaged.

What the fines could mean in practice

If the Commission's preliminary findings are upheld after the companies have had an opportunity to respond in writing, it can issue a non-compliance decision. The DSA allows fines of up to 6% of a company's total worldwide annual turnover. For Meta, which reported revenue of 134.9 billion US dollars in 2023, a maximum fine would exceed 8 billion dollars. For ByteDance, whose revenue is not publicly disclosed in the same detail but is estimated by analysts to be in the tens of billions of dollars, the exposure is similarly large. In practice, the Commission has calibrated fines below the statutory maximum in earlier cases, but the ceiling is designed to be a credible deterrent.

The Commission also has the power to impose periodic penalty payments of up to 5% of average daily worldwide turnover for each day of continued non-compliance after a decision. That mechanism is intended to force timely remediation rather than simply punish past behaviour.

Sources

  1. CNBC

    cnbc.com · 2025-10-24

People mentioned

  • Ben Walters

    Spokesperson, Meta

Organisations

European Commission · Meta · TikTok · ByteDance

Related analysis

Selected because they share topics with this article

The newsletter

One important European story. Explained properly.

Delivered to your inbox on the days we publish. No daily digest, no push notifications, no advertising.

We store your address only to send the briefing. Unsubscribe in one click.