EU is investigating Instagram's handling of children's personal data, after complaints that contact information on business accounts was publicly visible
Instagram is being investigated by Ireland's Data Protection Commissioner (DPC) over its handling of children's personal data on the platform.
Context & Ripple Effects
Ireland's Data Protection Commission has become the de facto lead enforcer for Meta's European operations: it reported 19 cross-border investigations since GDPR took effect, with 11 targeting Facebook, WhatsApp, and Instagram alone. This new probe into how Instagram exposes children's personal data — triggered by complaints that contact information on teen-run business accounts was publicly visible — extends that caseload into minor-specific design choices rather than headline breaches like the 533M-account Facebook leak.
The complaint centers on a permission-boundary problem: features built for businesses were leaving minors' contact details exposed by default. The same regulator has already opened a parallel children's-data investigation into TikTok (over its handling of kids' data and transfers to China), signaling that youth privacy is becoming a distinct enforcement lane.
First-order effects
- Instagram and parent company Facebook must now answer to the DPC for default visibility settings on business accounts used by minors, with the immediate risk being forced changes to who can see contact information on teen profiles.
- The probe puts Meta's teen-growth machinery under regulatory scrutiny at the same time internal efforts to win back young users — influencer boosts and algorithm tweaks favoring teen-friendly content — are expanding the population of minors on the platform.
Second-order effects
- Rival platforms face pressure to audit their own child-facing defaults before complaints land: the DPC's willingness to open a TikTok probe shows the same playbook applies across apps competing for teen attention.
- A finding against Instagram would hand every EU privacy regulator a template for challenging 'business feature' designs that leak minors' data, raising the compliance cost of one-size-fits-all account types.
Third-order effects
- If the pattern holds, children's privacy becomes a standing enforcement category in Europe rather than an occasional scandal — and the eventual outcome, a €405M fine against Instagram for violating children's privacy, suggests these probes convert directly into recurring financial and design costs for Meta.
- Ireland's DPC cements its structural role as gatekeeper for US platforms in the EU, concentrating enforcement power — and criticism, given the pace of its caseload — in one small regulator overseeing companies that employ a significant share of its domestic workforce.
The trend: Children's privacy is emerging as a distinct GDPR enforcement front, with Ireland's DPC using investigations of Instagram and TikTok to force platforms to redesign defaults around minors.