Brazil’s Data Protection watchdog fines TikTok over the mishandling of minors’ personal data

The Agência Nacional de Proteção de Dados (ANPD) imposed a fine of R$ 153.7 million on ByteDance, the controller of TikTok, for alleged breaches of Brazil’s Lei Geral de Proteção de Dados in relation to the processing of children’s and adolescents’ personal data. The sanction, published on 25 August 2026, also orders the deletion of irregularly collected data and requires ByteDance to implement a compliance plan.

Brazil’s Data Protection watchdog fines TikTok over the mishandling of minors’ personal data

The Agência Nacional de Proteção de Dados (ANPD) imposed a fine of R$ 153.7 million on ByteDance, the controller of the social media platform TikTok, in a sanction published in the Diário Oficial da União on Tuesday 25 August 2026. The sanction also orders the deletion of data that was collected irregularly and requires ByteDance to implement a compliance plan to improve the protection of children and adolescents on TikTok. The notice of the penalty was sent on Monday 24 August 2026, giving the company ten business days to appeal the decision to the Conselho Diretor of the ANPD.

According to the Superintendência de Fiscalização (SFI‑ANPD) in Technical Note No 50/2024/CGF/ANPD, the inspection identified practices that breach the Lei Geral de Proteção de Dados (LGPD) in two modes of access to the platform: the ‘feed without registration’ and the ‘feed with registration’. In both modes the agency found that personal data of children and adolescents were processed without a legal basis and that the company failed to adopt measures to prevent such processing. The sanction corresponds to five violations of articles 6 (incisos VIII and X) and 7 of the LGPD.

The identified infractions are:

– feed without registration – treating personal data of children and adolescents without a valid legal hypothesis; failing to adopt measures to prevent such processing.

– feed with registration – treating personal data of children and adolescents for registration without a valid legal hypothesis; failing to adopt measures to prevent registration of this audience.

– both experiences – failing to demonstrate effective measures capable of proving compliance with data‑protection norms.

In response, ByteDance committed to a compliance plan that includes automatically applying the most restrictive privacy settings to accounts of users under 16 years, with any change requiring parental authorisation, and strengthening parental‑control mechanisms. The plan also requires stricter content filters.

For the feed without registration, the plan limits the experience to twelve hours, prohibits users from creating content, commenting, sending direct messages, following or being followed, posting or watching live streams, and substantially limits personalisation of content. All advertisements are to be suspended in Brazil, and the feed must contain only material appropriate for all ages. Data collection for this mode will be reduced to the minimum necessary – language, region and basic device information for fraud protection and app performance.

The Conselho Diretor approved the compliance plan on a recourse basis, noting that ByteDance must observe the age‑verification requirement established by the Estatuto Digital da Criança e do Adolescente and comply with the timetable for reliable age‑verification mechanisms. The agency indicated that the company must follow the forthcoming guidance in the Guia Orientativo de Mecanismos de Aferição de Idade.

Go to Top