Government & Policy

ByteDance gets 24 hours to show EU a DSA risk assessment for TikTok Lite

Comment

TikTok logo seen on an Android mobile device screen with the European Union (EU) flag in the background.
Image Credits: Chukrut Budrul/SOPA Images/LightRocket / Getty Images

TikTok owner ByteDance is facing fresh questions about its compliance with the European Union’s Digital Services Act (DSA), an online governance and content moderation framework that puts a legal obligation on larger platforms to mitigate systemic risks in areas like youth mental health.

The EU’s latest concerns about TikTok’s DSA compliance center on the launch of TikTok Lite. This is a version of the video sharing app which recently launched (“test launched”, per TikTok) in France and Spain — letting users over 18 years old there earn points for certain in-app activities, such as liking content or following new creators. TikTok says these points can be redeemed for gift cards or “coins” that can be gifted to creators.

The reward-linked engagement feature looks to have triggered concern in the EU about potentially addictive design which could have a negative impact on young people’s mental health. The European Commission oversees platforms’ compliance with DSA system risk requirements.

In a press release announcing the request for information (RFI), the Commission said it’s asked TikTok for more details on the risk assessment it should have carried out before deploying the new app in the EU.

“This concerns the potential impact of the new ‘Task and Reward Lite’ programme on the protection of minors, as well as on the mental health of users, in particular in relation to the potential stimulation of addictive behaviour,” it wrote, adding that it’s also requesting info about the measures TikTok has put in place to mitigate such systemic risks.

TikTok has been given 24 hours to provide the risk assessment for TikTok Lite. It has until April 26 to provide other requested information, after which the Commission said it will analyse its reply and assess next steps, such as whether or not to open a formal investigation.

Reached for comment on the Commission’s RFI, a TikTok spokesperson said: “We have already been in direct contact with the Commission regarding this product and will respond to the request for information.”

ByteDance, which owns TikTok, is one of around two dozen larger online platforms that are subject to the strictest layer of DSA rules — requiring them to take steps to mitigate systemic risks use of their platforms could cause. Penalties for failing to comply with the regulation can reach up to 6% of global annual turnover which could lead to some hefty fines for TikTok for any confirmed compliance failures.

The wider impact of the pan-EU regulation is likely to be on platforms’ product design choices, with EU enforcers having powers that could potentially force the reform of entire business models if they’re found to have toxic impacts.

TikTok is already under investigation in the EU in relation to a number of DSA obligations, including in the area of protection of minors and the risk management of addictive design and harmful content, after the Commission announced a formal probe back in February. But the latest RFI suggests the EU is worried there are more issues of concern.

It’s particularly interesting to see the Commission intervening so swiftly after a tentative product release — as the TikTok Lite app only appears to have been live in the two markets for a very brief period. The Commission says it launched this month. (And here, for example, is a Spanish YouTube video on the reward feature which was posted just under a week ago where the vlogger says the program for earning money “just by watching videos” has only just been made available, and so far only on some Android devices.)

It’s not clear whether TikTok conducted a DSA risk assessment for the new reward program ahead of launching TikTok Lite in the two EU markets. A TikTok spokesman did not respond when we asked about that. But the regulation’s focus on systemic risk essentially makes such a step obligatory for features that are likely to appeal to minors.

TikTok did tell us it requires TikTok Lite users to verify that they are 18 or older in order to collect points through their use of the app. Asked about the robustness of the age verification technology it’s using, its spokesman said the processes involved can include things like “submitting a selfie with a photo ID (e.g passport or drivers license), credit card authorisations etc”.

Other restrictions on the reward program TikTok highlighted are a maximum limit on rewards it said is “roughly” equivalent to €1 per day. It also said there’s a maximum daily video time limit for rewards of one hour — so, presumably, you can only earn points for one hour’s worth of video watching, after which you won’t accrue any more points that day.

How clearly such limits are communicated to TikTok Lite users may be one area of interest to EU enforcers as they ask the platform about its design choices.

“VLOPs [very large online platforms] and VLOSEs [very large online search engines] are obliged to carry out risk assessments prior to deploying functionalities that are likely to have a critical impact on risks to, for example, the mental well-being of the users and send this assessment to the Commission without undue delay,” a Commission spokesperson told us.

Consumer groups in Europe have previously raised concerns about various aspects of TikTok’s platform design, including its use of virtual currency to create engagement incentives. Complaints raised back in 2021 were funnelled through the Consumer Protection Cooperation Network, with the Commission involved in encouraging a dialogue between the two sides. Then, in June 2022, the procedure culminated in TikTok offering a series of commitments — including pledging to boost transparency around its digital coins and virtual gifts.

However judging by the Commission’s oversight of TikTok’s approach to DSA compliance the platform may need to go further to satisfy enforcers of the rebooted EU Internet rulebook, which came fully into force this February — but with systemic risk elements expected to be respected as of late August 2023.

This report was updated with comment from the Commission

EU opens formal probe of TikTok under Digital Services Act, citing child safety, risk management and other concerns

More TechCrunch

Tags

With President Joe Biden dropping out of the race, Vice President Kamala Harris may become the Democrats’ new nominee. In announcing his plans, Biden offered his “full support and endorsement…

What Kamala Harris has said about AI, tech regulation, and more

U.S. President Joe Biden has announced he no longer plans to seek reelection, a decision that follows weeks of growing pressure from some Democratic Party supporters, including high-profile tech investors…

Joe Biden drops out of presidential race

Google is expected to announce four Pixel devices: the Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL and Pixel 9 Pro Premium, running Android 15.

Made by Google 2024: Pixel 9, Gemini, a new foldable and other things to expect from the event

WazirX, one of India’s largest cryptocurrency exchanges, has “temporarily” suspended all trading activities on its platform days after losing about $230 million, nearly half of its reserves, in a security…

WazirX halts trading after $230 million ‘force majeure’ loss

Featured Article

From Yandex’s ashes comes Nebius, a ‘startup’ with plans to be a European AI compute leader

Subject to shareholder approval, Yandex N.V. is adopting the name of one of its few remaining assets, an AI cloud platform called Nebius AI which it birthed last year.

From Yandex’s ashes comes Nebius, a ‘startup’ with plans to be a European AI compute leader

Employees at Bethesda Game Studios — the Microsoft-owned game developer that produces the Elder Scrolls and Fallout franchises — are joining the Communication Workers of America. Quality assurance testers at…

Bethesda Game Studios employees form a ‘wall-to-wall’ union

This week saw one of the most widespread IT disruptions in recent years linked to a faulty software update from popular cybersecurity firm CrowdStrike. Businesses across the world reported IT…

CrowdStrike’s update fail causes global outages and travel chaos

Alphabet, the parent company of Google, is in advanced talks to acquire cybersecurity startup Wiz for $23 billion, the Wall Street Journal reported on Sunday. TechCrunch’s sources heard similar and…

Unpacking how Alphabet’s rumored Wiz acquisition could affect VC

Around 8.5 million devices — less than 1 percent Windows machines globally — were affected by the recent CrowdStrike outage, according to a Microsoft blog post by David Weston, the…

Microsoft says 8.5M Windows devices were affected by CrowdStrike outage

Featured Article

Some Black startup founders feel betrayed by Ben Horowitz’s support for Trump

Trump is an advocate for a number of policies that could be harmful to people of color.

Some Black startup founders feel betrayed by Ben Horowitz’s support for Trump

Featured Article

Strava’s next chapter: New CEO talks AI, inclusivity, and why ‘dark mode’ took so long

TechCrunch sat down with Strava’s new CEO in London for a wide-ranging interview, delving into what the company is prioritizing, and what we can expect in the future as the company embarks on its “next chapter.”

Strava’s next chapter: New CEO talks AI, inclusivity, and why ‘dark mode’ took so long

Featured Article

Lavish parties and moral dilemmas: 4 days with Silicon Valley’s MAGA elite at the RNC

All week at the RNC, I saw an event defined by Silicon Valley. But I also saw the tech elite experience flashes of discordance.

Lavish parties and moral dilemmas: 4 days with Silicon Valley’s MAGA elite at the RNC

Featured Article

Tracking the EV battery factory construction boom across North America

A wave of automakers and battery makers — foreign and domestic — have pledged to produce North American–made batteries before 2030.

Tracking the EV battery factory construction boom across North America

Featured Article

Faulty CrowdStrike update causes major global IT outage, taking out banks, airlines and businesses globally

Security giant CrowdStrike said the outage was not caused by a cyberattack, as businesses anticipate widespread disruption.

Faulty CrowdStrike update causes major global IT outage, taking out banks, airlines and businesses globally

CISA confirmed the CrowdStrike outage was not caused by a cyberattack, but urged caution as malicious hackers exploit the situation.

US cyber agency CISA says malicious hackers are ‘taking advantage’ of CrowdStrike outage

The global outage is a perfect reminder how much of the world relies on technological infrastructure.

These startups are trying to prevent another CrowdStrike-like outage, according to VCs

The CrowdStrike outage that hit early Friday morning and knocked out computers running Microsoft Windows has grounded flights globally. Major U.S. airlines including United Airlines, American Airlines and Delta Air…

CrowdStrike outage: How your plane, train and automobile travel may be affected

Prior to the ban, Trump’s team used his channel to broadcast some of his campaigns. With the ban now lifted, his channel can resume doing so.

Twitch reinstates Trump’s account ahead of the 2024 presidential election

This week, Google is in discussions to pay $23 billion for cloud security startup Wiz, SoftBank acquires Graphcore, and more.

M&A activity heats up with Wiz, Graphcore, etc.

CrowdStrike competes with a number of vendors, including SentinelOne and Palo Alto Networks but also Microsoft, Trellix, Trend Micro and Sophos, in the endpoint security market.

CrowdStrike’s rivals stand to benefit from its update fail debacle

The IT outage may have an unexpected effect on the climate: clearer skies and maybe lower temperatures this evening

CrowdStrike chaos leads to grounded aircraft — and maybe an unusual weather effect

There’s a man in Florida right now who wants to propose to his girlfriend while they’re on a beach vacation. He couldn’t get the engagement ring before he flew down…

The CrowdStrike outage is a plot point in a rom-com 

Here’s everything you need to know so far about the global outages caused by CrowdStrike’s buggy software update.

What we know about CrowdStrike’s update fail that’s causing global outages and travel chaos

This serves as an example for how easy it is to spread inaccurate information online during a time of immense global confusion and panic.

From the Sphere to false cyberattack claims, misinformation runs rampant amid CrowdStrike outage

Today is the final chance to save up to $800 on TechCrunch Disrupt 2024 tickets. Disrupt Deal Days event will end tonight at 11:59 p.m. PT. Don’t miss out on…

Last chance today: Secure major savings for TechCrunch Disrupt 2024!

Indian fintech Paytm’s struggles won’t seem to end. The company on Friday reported that its revenue declined by 36% and its loss more than doubled in the first quarter as…

Paytm loss widens and revenue shrinks as it grapples with regulatory clampdown

J. Michael Cline, the co-founder of Fandango and multiple other startups over his multi-decade career, died after falling from a Manhattan hotel, New York’s Deputy Commissioner of Public Information tells…

Fandango founder dies in fall from Manhattan skyscraper

Venture capital giant a16z fixed a security vulnerability in one of the firm’s websites after being warned by a security researcher.

Researcher finds flaw in a16z website that exposed some company data

Apple on Thursday announced its upcoming lineup of immersive video content for the Vision Pro. The list includes behind-the-scenes footage of the 2024 NBA All-Star Weekend, an immersive performance by…

Apple Vision Pro debuts immersive content featuring NBA players, The Weeknd and more

Biden centering Musk in his campaign is a notable escalation, considering he spent most of his presidency seemingly pretending the billionaire didn’t exist.

Elon Musk is now a villain in Joe Biden’s presidential campaign