Instagram's €405 million fine and TikTok's €345 million fine, both issued by Ireland's DPC, are usually filed under the same broad heading — 'children's data' — as though that fully explains what happened. The actual findings are narrower and, for anyone advising a platform with underage users, more instructive than the number suggests.
In Instagram's case, the DPC found that teenage users running business or creator accounts had their phone numbers and email addresses made publicly visible by default, as a byproduct of how those account types were configured. Nobody set out to expose a thirteen-year-old's phone number to the internet; it fell out of a product decision made for adult creators and never revisited for minors. TikTok's fine turned on a similar default-settings problem — child accounts set to public unless a user actively changed them — compounded by a 'Family Pairing' feature that the DPC found did not adequately verify that the paired adult was actually the child's parent.
The common thread is not malicious data harvesting. It is that platforms built one set of defaults for their general user base and applied it uniformly to minors, treating GDPR's heightened protection for children's data as a policy layer to bolt on rather than a design constraint to build around. Under Article 8 and recital 38, protections for children are not a stricter version of the adult rules — they are a different starting assumption: that a minor cannot be expected to understand the consequences of a public default the way an adult user is assumed to.
For any organisation processing data from users who might be under eighteen, the practical test these cases suggest is blunt: don't ask whether your privacy policy mentions children. Ask whether your default settings were ever actually tested against a thirteen-year-old user, or whether that scenario simply inherited the adult configuration by omission.