BB2G Solutions · Scorecard

Platform Accountability Scorecard

A comparison of what major platforms say their child-safety policies do, set beside the public enforcement record. The scorecard is an assessment against an open rubric. The ledger is documented fact. They are not the same thing.

Published-policy rubric US, UK, EU records Findings kept apart from allegations
Start here

In plain language.

A platform can publish a rule, call it a safeguard, and still leave the important question unanswered: does the rule exist for every child, how does it work, and has any regulator made the company change it? This page separates those questions.

Five things this page does

1. A promise is not enforcement. The scorecard records published policy language. It does not treat a company policy as proof that the policy works.

2. The grading is ours. Each status is an assessment against the stated rubric, not a government finding. The source link in every cell lets you challenge the assessment.

3. Missing detail matters. If the supplied policy does not state an age-assurance method, data-retention rule, or consent flow, the cell says so. It does not guess.

4. An investigation is not a verdict. Open UK inquiries, EU preliminary findings, and US trial allegations are shown as open or preliminary. They are not labeled as established wrongdoing.

5. A fine announced is not always money paid. The ledger preserves the record's language: settlement, fine, penalty, demanded amount, or not published.

The working tool

Published-policy scorecard.

This is an assessment against the published rubric below, built only from the policy pages supplied with this record. “Documented” means the linked page describes the policy. “Partial” means it describes only part of the criterion. “Not stated” means the supplied page does not state the relevant detail. It is not a performance grade and not a regulatory finding.

Confirmed official policy or regulator record Reported credible journalism Contested preliminary or disputed record Allegation asserted, not established

Compare the same criterion across platforms.

Use a criterion control to reduce the matrix to one column. On a phone, this changes the cards below without asking you to read a wide table sideways.

Assessment labels: documented, partial, or not stated. These are editorial readings of the linked published policy.

Loading the published-policy scorecard.

PlatformDefault privacy for minorsAge assuranceParent controlsResearcher accessRetention disclosure

Rubric criteria are visible in the matrix headers. A cell saying “not stated” is limited to the supplied linked policy page; it does not establish that a platform has no policy elsewhere.

The evidence

Enforcement is a jurisdictional record.

The ledger below is separate from the assessment. It tracks actions under named law, their procedural posture, and the money described in the public record. The contrast is structural: the UK and EU records identify regulator action under the Online Safety Act, the DSA, and GDPR; the current US entries include a settlement that resolves allegations and a state case that is still at trial.

United States

Litigation and privacy orders.

The supplied current record identifies a U.S. Department of Justice $400 million TikTok/ByteDance settlement resolving allegations without a liability determination, while the 29-state Meta case is still a trial. Historic FTC privacy and COPPA penalties are in the ledger.

United Kingdom

Named Online Safety Act action.

Ofcom fined TikTok GBP 1.875 million for inaccurate safety-control data and has opened named child-safety inquiries. An open inquiry remains an inquiry, not a finding.

European Union

DSA steps plus large GDPR fines.

The DSA entries are preliminary findings with no DSA fine imposed in this record. Separately, the ledger records The Guardian reporting EUR 1.2 billion in Meta data-transfer enforcement under EU data-protection law.

Loading documented enforcement actions.

JurisdictionYear / dateMatterLaw or regimeProcedural postureOutcome and what it cost
What to do with it

Use the scorecard as a reading guide, not a verdict.

The useful question is not “which company has the highest grade?” It is which safeguard can be checked, who can enforce it, and which missing public detail should be released next.

Choose one criterion.

Use the scorecard controls to compare one claimed safeguard at a time. Read the exact policy language behind each assessment before relying on it.

Separate policy from record.

Move from a policy cell to the enforcement ledger. A documented platform policy is not evidence of compliance, and an open investigation is not a finding.

Ask for the missing disclosure.

Where a cell says “not stated,” ask the company or regulator to publish the age-assurance method, consent flow, retention rule, or independent compliance result.

Read the procedural posture.

Use “settlement,” “fine,” “preliminary finding,” and “open investigation” precisely. The amount column tells you what was announced, not necessarily what was paid.

What is still unknown

The public record has holes.

This scorecard is intentionally narrow. These are the material facts that the supplied sources do not publish or do not settle.

Independent effectiveness

The supplied platform pages describe controls. They do not publish a comparable independent measure of whether those controls reduce harm, evade age misstatement, or work consistently across countries.

Comparable age assurance

Several supplied policy pages do not state a technical age-assurance method. To close that gap, each platform would need to publish the method, error rates, appeals process, and country-specific deployment.

Fine paid versus announced

Some records give a settlement or fine amount but do not state payment completion. The named regulator or court would need to publish payment status, collection dates, and any appeal outcome.

Open matters

The UK investigations, EU preliminary findings, and US state trial have no final merits result in the supplied record. Only a final regulator decision or court disposition can resolve them.

Watch

How to read accountability claims.

A short walkthrough of the policy rubric, the assessment labels, and the difference between an enforcement action and a finding of wrongdoing.

The platform record, explained

Published safeguards, regulatory action, and the procedural language that keeps each from being overstated.

Conclusions

What this record supports.

The conclusions are limited to the linked policy pages and enforcement records. They do not turn a platform's published policy into a compliance finding.

The public-policy comparison is thinner than the marketing suggests.

The supplied policies describe real controls, but they do not disclose the same details for every platform or criterion. That prevents a clean performance ranking and is why the assessment keeps “not stated” visible.

Named safeguards are not evidence that safeguards work.

Meta, TikTok, and Google describe parental or teen-account controls in the supplied pages. The supplied policy pages do not themselves establish measured effectiveness. Treating them as proof would erase the difference between a company statement and an audit.

The sharpest live contrast is procedural, not rhetorical.

Ofcom’s record includes a named Online Safety Act fine and named open inquiries; the European Commission’s DSA record includes preliminary findings; the current US Meta action is still a state trial, while the TikTok settlement expressly resolves allegations without a liability determination.

Europe’s largest money figure here is not a DSA fine.

The EUR 1.2 billion Meta data-transfer penalty in the ledger arose under EU data-protection enforcement. The DSA items in this record are preliminary and list no imposed fine. Conflating them would overstate what the DSA record shows.

The uncomfortable conclusion for enforcement advocates: the ledger cannot prove child safety.

A penalty can compel disclosure, change a process, or punish a violation. It cannot, by itself, demonstrate that a child is safer on the platform. That evidence needs transparent, independently checkable outcome data that this record does not contain.