CiberLATAMbywhalemate

Brazil's ANPD Fines TikTok R$153.7 Million

Brazil’s ANPD fined ByteDance Brasil for child data violations and ordered the removal of improperly collected information and a compliance plan.

Whalemate Labs · AI-assisted researchPublished:Updated 5 min read

Brazil’s ANPD fined ByteDance Brasil, TikTok’s parent company, R$ 153.7 million for irregular processing of children’s and teenagers’ data. It also ordered the deletion of data collected improperly and a compliance plan to strengthen protections for minors.

Update August 28, 2026: ANPD clarified that the failures occurred in two TikTok access modes, the "feed sem cadastro" and the "feed com cadastro," where children’s and teens’ data was processed without a valid legal basis or safeguards to prevent it. More details also emerged on the fines, deadlines to pay or appeal, and orders to delete data and report technical measures.

Brazil’s ANPD has fined ByteDance Brasil, TikTok’s parent company, a total of R$ 153.7 million for irregular processing of personal data belonging to children and teenagers. The sanction, announced on August 25, 2026, also orders the deletion of data collected improperly and requires a specific compliance plan to strengthen protections for minors on the platform.

What did ANPD decide in the TikTok case?

The Brazilian authority imposed penalties on ByteDance Brasil for violations tied to the processing of minors’ personal data, according to its official statement and Decision Order No. 27/2026/CGS/SFI published in the Official Gazette. Technical Note No. 50/2024/CGF/ANPD identified practices that did not comply with the LGPD in the "feed sem cadastro" and "feed com cadastro," where children’s and teenagers’ personal data was processed without a valid legal basis and without measures to prevent it.

The file cites simple fines for violations of Articles 7, 6, VIII, and 6, X of the LGPD, as well as the deletion of personal data from teenagers between 13 and 18 years old registered on the platform. Media coverage says the first-instance decision imposes three simple fines totaling R$ 153,769,671.33, with the option of a 25% reduction if the company gives up its right to appeal and pays within the deadline, along with daily fines for failing to meet the ordered obligations.

G1 reported that, beyond the fine, ANPD ordered the company to submit a compliance plan to strengthen protections for minors. Exame said the sanction is split into three installments tied to different LGPD violations, including Article 6, X, and that there is a 25% discount on the total if the company waives an appeal and pays within 20 business days.

What data did the authority order deleted?

ANPD ordered the deletion of data from teenagers aged 13 to 18 whose legal representative was not regularized within 60 business days, and it required notice to third parties with whom that data was shared. The measure also requires a technical report signed by the DPO and system audit logs, which must be submitted within five business days after that period, under penalty of daily fines.

How is this enforcement shift explained?

The fine against TikTok fits into a period of stronger regulatory and enforcement powers for ANPD, which since May 2026 has had authority to regulate, inspect, and investigate LGPD and Marco Civil da Internet violations after Decrees No. 12,975 and 12,976 took effect.

Recent legal analysis says the authority has been consolidating its role as a regulator through resolutions, guidance, and technical notes since 2021, with a focus on sanctions methodology in 2023 and on security incidents, the data protection officer, and international data transfers in 2024. Cescon Barrieu also noted that the Digital ECA, in force since March 2026, recognizes ANPD as the autonomous administrative authority responsible for overseeing the protection of children and teenagers in the digital environment, monitoring compliance, and issuing rules and procedures.

What other obligations came under ANPD’s scrutiny?

On August 21, 2026, ANPD began monitoring major digital platforms, app stores, and generative AI tools to verify compliance with the Marco Civil da Internet, as amended by Decrees 12,975/2026 and 12,976/2026, and with the Digital ECA. The authority said it aims to confirm the adoption of proactive measures to prevent criminal content, digital violence, and online fraud.

In parallel, Diario do Centro do Mundo reported that ANPD will notify social networks, AI tools, and app stores to answer questionnaires within 10 days about protecting women in the digital environment and preventing scams and fraud. That approach shows the use of its new enforcement powers through formal information requests.

What changes for incident reporting compliance?

ANPD Resolution CD/ANPD No. 15/2024 keeps and clarifies the three-business-day deadline to report security incidents to ANPD and to data subjects when there is a relevant risk or harm, counted from the controller’s awareness of the incident.

Gutemberg Amorim added that the deadline applies only to events with the potential for relevant risk or harm, and that for small-scale processing agents, the practical effect is to double the time available to notify. Sindhoesg and Jusdocs also agree that the three-business-day deadline remains in force under the LGPD for incidents with that level of impact.

What regulatory consequences does the case expose?

The LGPD provides for administrative fines of up to 2% of a company’s, group’s, or conglomerate’s revenue in Brazil, capped at R$ 50 million per violation, in addition to warnings, daily fines, publication of the violation, blocking, deletion of data, and suspension of processing activities, according to specialized articles cited in the material.

BSA Advogados said ANPD enforcement can lead to additional measures and the application of administrative sanctions under the LGPD, raising compliance challenges for companies operating in Brazil. At the same time, international media reported the fine against ByteDance Brasil at the same amount, equivalent to about 25.57 million euros, in line with the LGPD and focused on the protection of children’s and teenagers’ data.

G1 also said the company has 10 days to file an appeal or 20 business days to pay the fine, and that it can receive a 25% reduction if it waives the appeal and pays within the deadline. According to that same report, the authority is maintaining the order to delete the data collected improperly and submit a compliance plan.

Sources

View all