Insights

Brazil’s ANPD Fines TikTok BRL 153.7 Million Over Children’s and Adolescents’ Personal Data

Raphael Dutra

Harumi Miasato

Brazil’s National Data Protection Authority, the Agência Nacional de Proteção de Dados (ANPD), has imposed a BRL 153.7 million fine on ByteDance following an administrative enforcement proceeding concerning the processing of children’s and adolescents’ personal data on TikTok.

The sanction was announced on August 25, 2026.

In addition to the financial penalty, the regulator ordered the deletion of personal data collected unlawfully and required measures under a compliance plan aimed at strengthening the protection of younger users.

Under the procedure disclosed by the ANPD, the sanction may still be appealed to the Authority’s Board of Directors.

What violations did the ANPD identify?

The regulator examined two distinct ways of using TikTok.

The first involved users accessing content without creating an account, referred to by the ANPD as the unregistered feed.

The second involved registered TikTok accounts.

According to the regulator, the proceeding resulted in five violations of Brazil’s General Data Protection Law, or LGPD.

For the unregistered experience, the ANPD found that personal data belonging to children and adolescents had been processed without an appropriate legal basis and that sufficient measures had not been adopted to prevent such processing.

For registered users, the Authority identified issues involving the legal basis for processing younger users’ data during account creation and inadequate measures to prevent children from improperly registering for the service.

Across both experiences, the regulator also concluded that ByteDance had failed to demonstrate sufficiently effective measures to establish compliance with Brazilian data protection requirements.

Why has age assurance become a central issue?

The effectiveness of TikTok’s age-related controls had been under regulatory scrutiny for several years.

Information submitted by ByteDance and referenced by the ANPD showed that approximately 7.75 million children’s accounts were removed in Brazil between October 2022 and September 2023.

For the regulator, the scale of these removals raised material questions regarding whether the controls in place were capable of preventing underage users from accessing the platform in the first place.

This distinction is central to the enforcement approach.

Identifying an underage account after personal data has already been collected is not necessarily equivalent to preventing unlawful processing from occurring.

Is self-declared age enough?

Brazil’s regulatory framework has significantly evolved since the TikTok investigation began.

The Digital Child and Adolescent Statute, Law No. 15,211/2025, introduced specific obligations applicable to technology products and services directed at children and adolescents or likely to be accessed by them.

In March 2026, the ANPD also published preliminary guidance and an implementation timeline for reliable age-assurance mechanisms.

As a result, relying exclusively on a user’s self-declared date of birth may present significant compliance limitations, particularly for higher-risk services.

This does not mean that Brazilian law establishes one universal technology for age verification.

Companies must consider proportionality, privacy, data minimization, security, the nature of the service and the risks associated with access by minors.

What changes are required from TikTok?

The compliance measures disclosed by the ANPD include more restrictive privacy settings by default for users under 16.

Those settings may only be modified with authorization from the relevant parent or guardian.

TikTok must also strengthen parental supervision mechanisms and implement additional content protections.

The unregistered TikTok experience will be subject to additional restrictions, including:

  • no advertising in Brazil;
  • no ability to create content or comment;
  • no direct messaging;
  • no social-follow functionality;
  • no access to live-streaming features;
  • highly limited content personalization;
  • access only to content suitable for all ages;
  • reduced collection and processing of personal data.

ByteDance must also comply with age-assurance requirements under Brazil’s Digital Child and Adolescent Statute in accordance with the implementation schedule established by the regulator.

From compliance controls to compliance evidence

One of the most significant aspects of the decision for companies is the ANPD’s emphasis on effectiveness.

Organizations may have privacy policies, age gates and internal procedures in place.

However, the existence of a control does not necessarily demonstrate regulatory compliance if the company cannot show that the control materially reduces the identified risk.

For General Counsels, DPOs, Chief Compliance Officers, CISOs and product leaders, this creates a different set of governance questions:

  • How effective is the age-assurance mechanism?
  • What percentage of underage users bypass existing controls?
  • What personal data is processed before age is established?
  • How are potentially underage users detected?
  • What features are available when the user’s age remains uncertain?
  • Are privacy-protective settings enabled by default?
  • How is control effectiveness tested?
  • What evidence is maintained for regulatory review?

Product design becomes a regulatory concern

The enforcement action also demonstrates that children’s privacy cannot be addressed only through legal notices or privacy policies.

Where minors are likely to use a service, companies increasingly need to consider how product design affects data protection.

Relevant areas can include account creation, profiling, advertising, recommendation systems, messaging, live streaming, geolocation, parental controls and privacy defaults.

This brings together principles traditionally associated with Privacy by Design, Safety by Design and Age-Appropriate Design.

What should companies operating in Brazil review?

Digital businesses potentially accessed by children and adolescents may consider reviewing:

  • where minors are likely to interact with their products;
  • the reliability and proportionality of age-assurance mechanisms;
  • the legal bases supporting each category of processing;
  • data collected before age can be established;
  • default privacy and safety settings;
  • advertising and profiling involving younger users;
  • parental supervision mechanisms;
  • risk assessments;
  • testing and monitoring of existing controls;
  • documentation demonstrating compliance and effectiveness.

Children’s privacy becomes a board-level issue

The TikTok sanction comes as Brazil simultaneously implements the Digital Child and Adolescent Statute and expands regulatory scrutiny of major digital platforms.

For companies, this represents more than a privacy-policy update.

Children’s online protection increasingly affects product architecture, advertising, recommendation systems, age assurance, cybersecurity, data governance and corporate accountability.

Organizations operating digital services in Brazil should therefore consider stronger coordination between Legal, Privacy, Compliance, Cybersecurity, Product, Engineering, Marketing and executive leadership.

Conteúdo relacionado

Brazil’s ANPD Suspends Discord Live Streaming as Digital Child Protection Rules Move Into Enforcement

Brazil’s Superior Court Holds Online Travel Agency Liable for Failure to Provide Information and Assistance

Brazil’s Superior Court Allows Lifetime Spousal Support Set by Public Deed to Be Reviewed or Terminated

MENU