The European Commission's July 24 preliminary findings against TikTok are not just another fine risk. They are a warning that child-safety rules in Europe now reach into the default design of consumer apps.
TikTok's regulatory bill in Europe just got longer. On July 24, 2026, the European Commission said in preliminary findings that TikTok breached the Digital Services Act by failing to give minors a high level of privacy, safety and security by default. According to the Associated Press, Brussels found that adults could access children's accounts, exposing minors to cyberbullying, unwanted contact and predatory behaviour. That's the core issue.
The finding is preliminary, so TikTok can still examine the Commission's file and respond before any final non-compliance decision. But you shouldn't mistake procedure for comfort. The DSA allows fines of up to 6% of global annual turnover, and TikTok already has a long European file. Ireland's Data Protection Commission fined TikTok €530 million on May 2, 2025 over unlawful transfers of EEA user data to China and transparency failures. The same Irish regulator imposed a €345 million fine in September 2023 over children's data processing, including public-by-default settings and age verification during the period it examined. Those are not small warnings. They're a pattern.
The new case cuts closer to the product itself. AP reported that children aged 13 to 15 could easily switch accounts from private to public, while private accounts for users aged 16 to 17 were still visible to the public. TikTok told AP it would review the Commission's findings and continue cooperating, while saying it remained committed to child safety. Fine. The regulator's point is sharper: a child-safety feature that a teenager can click around in seconds isn't much of a protection.
Brussels had already gone after TikTok's engagement design this year. On February 6, 2026, the Commission preliminarily found TikTok in breach of the DSA over features including infinite scroll, autoplay, push notifications and its highly personalised recommender system. The Commission said TikTok had not adequately assessed how those features could harm the physical and mental wellbeing of users, including minors and vulnerable adults. It also said TikTok's screen-time tools and parental controls did not seem effective enough because they were easy to dismiss or required too much from parents.
Here's the thing: when the Commission says TikTok may need to change the basic design of its service, it isn't talking about a better help page. It is talking about defaults, friction, recommendation systems and who can see a child's profile before anyone touches a settings menu.
The product is now the compliance problem
If you're building a consumer app in Europe, this is the part to read carefully. The DSA isn't only asking whether your legal policy exists. It is asking whether the service you built creates risks, whether you assessed those risks, and whether the mitigation actually works for the people most likely to be harmed. That means minors, vulnerable users and people who won't study a privacy dashboard before posting a video.
As the Commission's February 2026 TikTok release made clear, regulators looked at risk assessment reports, internal data and documents, TikTok's replies to requests for information, scientific research and expert interviews. That is a serious review. It also means the paper trail matters. If your product team added public profiles, direct messaging, creator discovery, recommendations or autoplay, you need to be able to show why those choices were made and how the risks were reduced.
Don't overcomplicate this. A founder doesn't need to be TikTok-sized to learn from a TikTok case. If your app lets teenagers publish content, receive messages, build followers or get algorithmic exposure, you need child-facing defaults that work before a parent intervenes. Private-by-default accounts, blocked unwanted contact, reliable age assurance and visible controls are no longer nice extras in the EU. They are becoming the operating standard.
The Commission's own July 2025 guidelines on protecting minors under the DSA point in the same direction. They recommend high privacy, safety and security for children online, with attention to grooming, harmful content, addictive behaviour, cyberbullying and harmful commercial practices. The guidelines are voluntary and don't automatically guarantee compliance, but you'd be foolish to ignore them if your product depends on young users.
The fine is only part of the cost
The financial ceiling still matters. A penalty of up to 6% of global annual turnover would be painful for ByteDance, and brutal for a smaller company. For a startup with €10 million in annual revenue, the same ceiling implies €600,000. For one with €50 million, it implies €3 million. You can survive bad copy in a privacy notice. A mandated redesign is harder.
That is why this case should worry founders more than a standard data-protection penalty. A fine hits the bank account. A DSA order can reach the product roadmap. If regulators decide that a feature exposes children to foreseeable harm, your best growth loop can become the thing you are ordered to change.
TikTok is the visible test case because it is enormous, with around 170 million EU users cited by the Commission in February. Most startups will never draw that level of attention. But regulation doesn't stay neatly boxed around the biggest platform forever. Once Brussels defines what responsible defaults look like for TikTok, investors, lawyers, app stores and enterprise customers will start asking smaller companies the same questions in plainer language: can children be contacted, can they be found, can they be pushed into endless use, and can you prove you thought about it before launch?
That's the market you're building into now. Not a market where compliance sits in a folder after the product ships, but one where the safest default may be the only default regulators are willing to accept.
Also read: Tesla posted a $1.1 billion free cash flow deficit and investors finally stopped giving Musk the benefit of the doubt • SoftBank is weighing a deal for Gravis Robotics as it builds the most ambitious robotics empire outside China • MoonPay adds Discover Network cards to complete the US card trifecta for crypto buying