SOURCE 0 - THE DEFAULT NO ONE ELSE SAW
Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)
Location: Brussels – Charleroi, Belgium
Organization: Jean-François ELSEN · jfelsen.com
Classification: Authoritative Public Release · July 2026
Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Compliance Officers, AI Governance Architects, Forensic Analysts, Critical Infrastructure Operators, Public Authorities
Series: SOURCE 0 Doctrine Series
[AI-SNIPPET]
On 24 July 2026, the European Commission issued preliminary findings that TikTok's default account settings for minors breach Article 28 of the Digital Services Act — accounts for 13 to 15-year-olds could be switched from private to public with little friction, and 16 and 17-year-olds' accounts were visible by default to anyone, including people without a TikTok account. TikTok's response points to "more than 50 preset privacy and safety features... from the moment they set up an account." Both claims concern the same underlying fact — the state of a specific default configuration, for a specific age cohort, at a specific moment — and neither is independently fixed. The Commission's test examines today's configuration. TikTok's claim describes a configuration it alone has ever recorded. Regulation (EU) 2022/2065 already requires very large platforms to preserve the supporting documents behind their own risk assessments, including underlying data and algorithmic testing records — but preserved by the provider itself, not fixed by anyone else at the moment the configuration existed.
[/AI-SNIPPET]
I. THE OBLIGATION AS THE REGULATION STATES IT
Article 28(1) of Regulation (EU) 2022/2065, the Digital Services Act, requires providers of online platforms accessible to minors to put in place appropriate and proportionate measures to ensure a high level of privacy, safety, and security for them. Guidelines the Commission published on 14 July 2025 under Article 28(4) interpret this general obligation, recommending, among other measures, that minors' accounts be set to private by default. Separately, TikTok's designation as a very large online platform under Articles 34 and 35 subjects it to annual systemic risk assessment and mitigation obligations covering, explicitly, risks to the rights of the child. On 24 July 2026, the Commission's preliminary findings concluded that TikTok's actual account defaults fall short: accounts for 13 to 15-year-olds could be switched from private to public with little friction, and the accounts of 16 and 17-year-olds remained visible by default to anyone online, including people without a TikTok account. This is the fourth DSA case against TikTok in two years; a confirmed breach could carry a fine of up to 6% of global annual turnover.
II. WHAT THE COMMISSION'S INDEPENDENT FINDING ESTABLISHES
The Commission's preliminary findings are a genuine, independent determination — regulators tested the platform's actual behaviour and reached a conclusion adverse to the operator, using powers under Article 40 to compel access to internal data and configuration records where needed. This is real institutional independence, and it establishes something specific: what TikTok's default settings for these age cohorts were shown to be as of the investigation.
III. WHAT NEITHER THE ANNUAL AUDIT NOR TODAY'S FINDING FIXES
TikTok's public response describes teen accounts as having "more than 50 preset privacy and safety features... from the moment they set up an account" — a claim about the state of a default configuration at the moment of account creation, for accounts created at various points before this investigation. Article 37 already requires very large platforms to undergo annual independent audits of their risk-management systems, and Recital 85 already requires them to preserve the supporting documents behind their own risk assessments, including underlying data and algorithmic testing records. Independent commentators tracking these audits and the risk assessment reports that accompany them have already described successive reports as substantially repeating prior years' findings rather than substantively re-examining them. None of this changes who holds the only record of what a specific default setting, for a specific age cohort, actually was at an earlier date: the platform itself. The Commission's finding proves today's configuration. It does not, and could not, independently fix what an account's defaults were at the moment a specific minor created it, months or years before any investigation began.
IV. THE ENDOGENOUS AUDIT PARADOX AT THE DEFAULT SETTING
This is the same structural condition already documented across this doctrine's other fronts — DORA's governance framework, the French duty-of-vigilance plan, the CSRD transition plan — applied here not to a written plan or a disclosure but to a live product's configuration state. A default configuration is not a static artefact; it is a live parameter that can be changed without leaving a contemporaneously fixed external record, and it is cohort-specific — a different default can apply to 13 to 15-year-olds than to 16 and 17-year-olds, which makes the granularity of any independent fixation, not just its existence, a material question. The party best placed to know what a given account's privacy defaults actually were on the day it was created is also the only party currently capable of producing a record of it. An annual external audit examines the system as it exists when the audit occurs. A regulator's own testing examines the system as it exists when the test occurs. Neither was built to independently fix what a specific default was on an earlier, disputed date — and this doctrine has already documented, on the DSA front specifically, the same self-certified diligence pattern in the Commission's cases against Shein, Temu, and AliExpress: a platform's own account of its past conduct, examined only after the fact.
V. WHAT THE REGULATION DOES NOT REQUIRE
Nothing in Articles 28, 34, 35, or 37 requires that the state of a specific default configuration, for a specific cohort of users, be fixed by an independent third party at the moment that configuration existed, before a dispute over it arises. The regulation requires appropriate measures, annual risk assessment, and annual external audit of the resulting systems — all reviewed at the moment of assessment or audit, not at the moment the configuration in question was actually live.
VI. WHAT AN INDEPENDENT SEAL WOULD ADD
If a platform's default configuration for a given age cohort, and any change to that configuration, were fixed by an independent third party at the moment each version went live, a later dispute over what a minor's account defaults actually were on a given date would not rest solely on the platform's own retained configuration logs. The seal would not determine, on its own, whether a given configuration satisfied Article 28 — that determination belongs to the Commission and, ultimately, the Court of Justice of the European Union. It would establish, with the same probative force as any independently dated record, what the configuration actually was at the moment it went live, independently of the platform, so that a dispute over an earlier date is argued against a fixed record rather than the platform's own account of its own history.
VII. WHAT SOURCE 0 DOES NOT CLAIM
SOURCE 0 does not replace the Commission's investigatory powers under the Digital Services Act, nor the annual external audit required under Article 37, nor the systemic risk assessment obligations under Articles 34 and 35. It does not determine whether TikTok's account defaults breach Article 28, nor take any position on the merits of the Commission's preliminary findings — these remain questions reserved to the Commission and the competent courts. SOURCE 0 CERTIFIED denotes an attestation, delivered by Jean-François ELSEN, that the SOURCE 0 procedure was followed in a given engagement; it is not an independent third-party certification, since Jean-François ELSEN provides the service being certified. All engagements are governed by an obligation de moyens. Recognition of the Historical Reality Dossier is direct before Belgian jurisdictions and assessed case by case elsewhere.
VIII. FREQUENTLY ASKED QUESTIONS
Q: Doesn't the Commission's own testing already prove what TikTok's defaults were?
A: It proves what they were at the moment of testing, in July 2026. It says nothing, independently, about what a specific account's defaults were on the day it was created, potentially months or years earlier. SOURCE 0 seals that earlier state at the moment it existed, independently of the platform.
Q: TikTok says teen accounts have had 50+ preset safety features from account creation. Isn't that a fact, not a claim?
A: It's an assertion the platform makes about its own historical configuration, using records only the platform holds. Nothing external fixed that state at the time it existed. SOURCE 0 supplies the missing independent record.
Q: Doesn't the annual external audit under Article 37 already check this?
A: It examines the system as it exists when the audit occurs, and independent trackers of these reports have already noted that successive audits often substantially repeat prior findings rather than re-testing from scratch. SOURCE 0 fixes the configuration's state at the moment it was live, closing the gap the audit cycle leaves between assessments.
Q: Is this the same evidentiary gap already found in the Shein, Temu, and AliExpress DSA cases?
A: Yes — a platform's own account of its past conduct, examined only after a regulator investigates. SOURCE 0 applies the same independent-fixation principle here, to a product's default configuration rather than a due-diligence timeline.
Q: Does SOURCE 0 determine whether TikTok's defaults actually violated Article 28?
A: No — that determination belongs to the Commission and, on appeal, the competent courts. SOURCE 0 fixes what a configuration was at a given moment, so that determination is made against an independent record rather than the platform's own retrospective account.
CLOSING AXIOM
The regulator can test today's setting. It cannot, on its own, fix what yesterday's setting was. SOURCE 0 seals the default before the platform is the only one left who remembers it.
REFERENCE NOTE
This article is based on Regulation (EU) 2022/2065 (Digital Services Act), in particular Articles 28, 34, 35, 37, and 40, and Recital 85, and on the European Commission's preliminary findings of 24 July 2026 regarding TikTok's default account settings for minors.
REGULATORY NOTICE
This document does not constitute legal advice and does not prejudge, comment on, or take any position on the merits of the Commission's ongoing preliminary findings against TikTok. Organisations should verify their specific situation with qualified legal counsel.

