“A high level of protection should not be an opt-in; it should be the default.” Henna Virkkunen, Executive Vice-President for Tech Sovereignty, Security and Democracy, on the European Commission’s preliminary findings against TikTok.

European Commission Press Release IP/26/1679, “Commission preliminary finds TikTok in breach of Digital Services Act for failing to ensure safe accounts for minors”, Brussels, 24th July 2026.

Background

Can a platform built on visibility be trusted to keep children invisible? On 24th July 2026, the European Commission answered with a preliminary but pointed “no”, issuing formal preliminary findings that TikTok’s account settings for minors fall short of the Digital Services Act (DSA), the European Union’s flagship platform-accountability statute.

The findings emerge from formal proceedings commenced on 19th February 2024, an investigation that traversed TikTok’s interface, internal data and documents, and interviews with law enforcement officers and experts in child protection, child abuse and neuro-psychology. TikTok now has the opportunity to inspect the investigation file and respond in writing; should the findings be confirmed, a non-compliance decision may issue, carrying a fine of up to six per cent (6%) of TikTok’s global annual turnover.

Key Regulatory Holdings and Their Analytical Weight

1. Safety by Default, Not by Election

The Commission’s central argument is that protection of minors cannot be an opt-in feature. Under the DSA, platforms accessible to minors must guarantee a high level of privacy, safety and security by design. 

The Commission would require minors’ content to be visible, by default, only to followers the minor has affirmatively accepted; content should never be accessible to a global audience outside the platform; and minors’ content should not be recommended to other users through the For You Feed. The regulatory philosophy is unmistakable: where the data subject is a child, the burden of configuring safety shifts from the child to the platform.

2. Design Is Conduct: The Interface Itself Is the Infringement

Notably, the Commission did not anchor its findings on any single incident of harm. The breach is located in the settings architecture itself, the defaults, the discoverability pathways, the recommender amplification. This marks a decisive regulatory shift from policing content to auditing design, and it converts product decisions ordinarily made by engineers into questions of legal compliance.

3. Preliminary, but Perilous

The findings do not prejudge the final outcome. Yet the procedural posture is itself instructive: with parallel preliminary findings on addictive design (February 2026) and researcher data access (October 2025), and binding commitments already extracted on advertising transparency (December 2025), TikTok is being regulated iteratively, module by module. The ongoing inquiry into the “rabbit hole effect” and age misrepresentation signals that the design-scrutiny frontier is still expanding.

THE KENYAN NEXUS: A REGIME ALREADY ARMED

Kenya has no Digital Services Act. But it would be a grave miscalculation to conclude that Kenyan law is silent on the questions Brussels has posed. The Data Protection Act, 2019 (the “DPA”) speaks to them directly, and the Office of the Data Protection Commissioner (“ODPC”) has already drawn blood on this precise terrain.

A. Children’s Data Enjoys Statutory Primacy

Section 33 of the DPA prohibits the processing of personal data relating to a child unless consent is given by the child’s parent or guardian and the processing is in a manner that protects and advances the rights and best interests of the child, a conjunctive test that consent alone cannot satisfy.

B. Privacy by Design Is Already Kenyan Law

Section 41 of the DPA obliges every data controller and processor to implement data protection by design and by default. The Commission’s quarrel with TikTok that safety was configured as an election rather than a default is, in substance, a section 41 argument. Kenyan practitioners should not regard the EU findings as foreign jurisprudence; they are a persuasive roadmap for how our own “by design and by default” obligation may be litigated and enforced.

THE DOMESTIC FRONT: PARLIAMENT AND THE COMMUNICATIONS AUTHORITY CLOSE IN

The Brussels findings do not land in a Kenyan vacuum. They land in the middle of an active domestic regulatory pivot, one that has moved decisively from the rhetoric of banning TikTok to the machinery of regulating it.

Parliament Rejects a Ban, Chooses Regulation

In its report on Petition No. 41 of 2023 regarding the Regulation of TikTok in Kenya, considered by the National Assembly in February 2026, the Public Petitions Committee ruled out an outright ban as untenable, an infringement of fundamental rights that would stifle the digital economy and the youth livelihoods built upon it. 

In its place, the Committee recommended institutionalised regulation and periodic compliance reviews by State agencies, and directed the Ministry of Interior and the Ministry of Information, Communications and the Digital Economy to report back within four months on age verification, localisation of Kenyan user data, and digital literacy programmes. The ODPC was expressly tasked with engaging social media platforms and reporting to Parliament on their compliance with Kenyan law.

A DSA-Shaped Amendment to KICA Is on the Table

Most consequentially, the Committee recommended amendment of the Kenya Information and Communications Act to mandate the Communications Authority of Kenya to regulate social media platforms operating in the country with audits of AI-driven moderation systems also proposed. 

If enacted, this would graft a DSA-style platform-accountability jurisdiction onto Kenyan law, transforming the Communications Authority from a licensing regulator into a design-and-conduct supervisor of global platforms.

The Communications Authority’s Child Online Protection Guidelines Anticipated Brussels

The Industry Guidelines for Child Online Protection and Safety in Kenya, issued by the Communications Authority under the Kenya Information and Communications (Consumer Protection) Regulations, 2010 and operationalised in April 2025, already require licensees and service providers to adopt safety and data-protection-by-design principles, deploy age verification mechanisms, apply heightened default privacy settings for children, publish corporate child online safety policies, and maintain complaint and takedown processes. 

The Platform Is Already Self-Policing- Under Pressure

TikTok’s own Community Guidelines Enforcement Report for the first quarter of 2026, released on 23rd July 2026, discloses the removal of 884,591 videos in Kenya between January and March 2026 (99.7% detected proactively), the deletion of 48,739 accounts suspected to belong to users under thirteen, and the interruption of 103,847 LIVE rooms alongside a joint working group with the Communications Authority and the National Cohesion and Integration Commission on harmful content. The scale of the purge is itself an admission of the scale of the risk; and proactive self-policing, however vigorous, is precisely what regulators in both Brussels and Nairobi have concluded cannot substitute for enforceable design standards.

WHAT TO LOOK OUT FOR

a. The KICA Amendment Bill

The proposed amendment empowering the Communications Authority to regulate social media platforms will be the single most consequential development to track. Its drafting choices scope, due-process safeguards, penalty architecture, and treatment of algorithmic design will determine whether Kenya adopts a measured DSA-style co-regulatory model or a blunter instrument vulnerable to constitutional challenge under Articles 33 and 34.

b. Regulatory Convergence and Age Assurance

Expect the ODPC and the Communications Authority to draw on the EU’s Guidelines on the protection of minors when auditing platforms, schools, advertisers and content creators — and expect age verification and data localisation to dominate the ministerial reports due before Parliament.

c. The Global Ripple of EU-Mandated Design

Design changes forced upon TikTok in Brussels private-by-default accounts, curtailed recommender amplification of minors’ content frequently ship globally. Kenyan minors may inherit the benefit; Kenyan platforms should not wait to inherit the standard.

d. Compliance Audit Points for Kenyan Controllers

Any entity processing children’s data; platforms, schools, churches, sports academies, advertisers, influencer agencies should interrogate: 

  1. whether defaults are set to the most protective configuration;
  2. whether age verification and parental consent mechanisms under Regulation 12 are demonstrable;
  3. whether a data protection impact assessment under section 31 of the DPA has been undertaken where processing presents high risk to children; and
  4. whether the best-interests limb of section 33, not merely consent, can be evidenced.

THE BOTTOM LINE

Brussels has declared that childhood is not content, and that the default must protect. Kenya’s statute book already says the same; the ODPC has already enforced it against exposure of minors on TikTok itself; Parliament has chosen regulation over prohibition; and a KICA amendment that would arm the Communications Authority with platform-supervision powers is now on the legislative horizon. 

For platforms, institutions and advertisers operating in Kenya, the question is no longer whether the design-scrutiny wave will arrive, it is already gathering on two continents at once. The only question is whether their default settings, consent architecture and impact assessments will withstand it when it breaks.

This article is provided free of charge for information purposes only; it does not constitute legal advice and should not be relied on as such. No responsibility for the accuracy and/or correctness of the information and commentary as set out in the article should be held without seeking specific legal advice on the subject matter. If you have any query regarding the same, please do not hesitate to contact the Data Protection & ICT Law Department at WAICTLaw@wamaeallen.com.

About the author

Partner at Wamae & Allen

Caxstone specializes in civil, employment and labour disputes, constitutional law, family law and succession, and environment and land matters. He has amassed a wealth of knowledge and experience in litigation which is evident in the successes obtained for clients. He is an active member of the Employment and Labour Relations Court Bar-Bench committee.

Associate

Frankline M. Otieno is a dispute resolution associate, recommended professional and committed to offering sustainable client-centred solutions to legal issues.Frankline is astute in commercial litigation, securities law, banking law, intellectual property litigation, public procurement, land law litigation, Judicial Review and Administrative law litigation, sports law, tax litigation, administrative law, consumer protection law, competition law and constitutional litigation.

Associate

Denis Mutugi specializes in Commercial Litigation and Alternative Dispute Resolution.
Denis graduated with a Bachelor of Laws, LLB (Hons) from The University of Nairobi in 2021 and was admitted to the Roll of Advocates of the High Court of Kenya in the year 2023.
Denis has amassed a considerable wealth of experience in conducting legal research on various complex legal matters touching on Commercial, Insurance, Employment and Insolvency law and bankruptcy.

Associate

Nadio George is a dedicated Advocate of the High Court of Kenya, passionate about legal excellence, societal progress, and environmental stewardship. Admitted to the Roll of Advocates in 2023, he combines deep legal expertise with a strong commitment to making meaningful contributions to both the legal profession and the community.

Subscribe To Our Newsletter

Join our mailing list to receive the latest news and legal updates from our team.

You have successfully subscribed to Wamae & Allen Quarterly.