Skip to content

TikTok Brazil fine: ANPD's BRL 153.7M children's data ruling

Filip LuchianencoUpdated 4 min read

Last updated: 2026-10-03

On August 25, 2026, Brazil's National Data Protection Agency (ANPD) announced a R$ 153.7 million fine on ByteDance, which the release calls TikTok's "controladora" (controlling company), over children's and teenagers' data. The sanction is Despacho Decisório nº 27/2026/CGS/SFI in proceeding 00261.006648/2024-02, signed August 24 against ByteDance Brasil Tecnologia Ltda., for BRL 153,769,671.33 under the LGPD, Brazil's general data protection law. It covers TikTok's feed without an account ("feed sem cadastro") and with one ("feed com cadastro").

What did the ANPD find in the TikTok decision?

Per the release, TikTok processed children's and teenagers' data in both modes "sem hipótese legal adequada" (without an adequate legal basis), and "faltavam evidências concretas da efetividade das medidas técnicas e organizacionais" (concrete evidence of the effectiveness of the technical and organizational measures was lacking).

Conduct (ANPD wording, summarized) Feed LGPD provision Fine (BRL)
1. Processing data of under-18s without a valid legal basis to provide the logged-out feed Without account Art. 7 35,760,388.68
2. Failing to adopt measures to prevent processing of under-13s' data in the logged-out feed Without account Art. 6, VIII (prevention) 35,760,388.68
3. Processing data of under-18s to register them without a valid legal basis, with no valid contract With account Art. 7 27,416,297.99, plus data deletion
4. Failing to adopt effective measures to prevent under-13s from registering With account Art. 6, VIII 27,416,297.99
5. Failing to demonstrate effective measures proving compliance Both Art. 6, X (accountability) 27,416,297.99
Total 153,769,671.33

Source: ANPD Relatório de Instrução nº 2/2026/CGS/SFI, Table 2, adopted as the decision's reasoning.

The instruction report traces the case to a complaint of March 23, 2021 about data from people using the app without registering. The infraction notice it summarizes charged that registration relied only on the "age gate", "método em que basta a declaração de idade do usuário" (a method where the user's declared age is enough).

The decision also orders deletion of data of registered users aged 13 to 18 whose "representação ou assistência legal" (legal representation or assistance, by a parent or guardian) is not regularized within 60 business days, notice to third-party recipients, and a DPO-signed report with system logs, under a daily fine of BRL 137,081.49 per missed obligation.

TikTok told g1 that the agency approved its compliance plan in 2025, that "A decisão que impôs a multa se refere a um período anterior (2021) e não reflete as ações previstas nesse plano nem as medidas voluntariamente implementadas desde então" (the decision refers to an earlier period, 2021, and does not reflect the actions in that plan nor the measures voluntarily implemented since then), and that it is assessing "as medidas cabíveis" (the appropriate measures).

Can ByteDance appeal the ANPD fine?

The decision allows an appeal to the ANPD's Board within 10 business days of the August 24, 2026 notification; waiving the appeal and paying within 20 business days cuts the fine 25% to BRL 115,327,253.49. On October 3, 2026, the sanctions decisions page listed the case as "Processo em andamento" (proceeding ongoing); whether ByteDance appealed, waived or paid is not stated there or in the release.

What must TikTok's logged-out feed do now?

On August 25, in a separate supervision proceeding, the ANPD published the Board's ruling on an earlier ByteDance appeal: following rapporteur Vote nº 4/2026, it approved ByteDance's compliance plan. Per the release, the logged-out experience is limited to 12 hours, shows only all-ages content and no ads in Brazil, and limits collection to "dados mínimos de idioma e região" (minimal language and region data), basic device information for fraud protection, and app performance data.

The vote records that, per a data inventory in the case file (SEI document 0184133), TikTok "ainda coletaria dados tipicamente utilizados para a finalidade de direcionamento de publicidade" (would still collect data typically used for ad targeting) in the logged-out feed, naming "o Identifier for Advertisers – IDFA, o Google Advertising ID – GAID (ou AAID), o Identifier for Vendors – IDFV e o Android ID" (Vote nº 4/2026, para. 40). ByteDance told the ANPD that "esses dados não são utilizados, direta ou indiretamente, para fins de publicidade" (these data are not used, directly or indirectly, for advertising). The rapporteur, Lorena Giuberti Coutinho, found no reference in ByteDance's submissions or the specialist literature that clearly confirms it, and the vote directs the enforcement unit to examine the four identifiers. Korea's PIPC fined TikTok in July 2026 over third-party behavioral data linked to GAID and IDFA.

An ANPD technical note of June 12, 2026, cited in the vote, found "indícios" (indications) of practical shortfalls in the logged-out feed, which ByteDance says it reactivated on February 2, 2026. ByteDance answered in its final submissions that most plan measures were not yet due when the tests ran (paras. 48–49).

The Board's approval requires ByteDance to apply the ECA Digital's age-verification rules (Lei 15.211/2025), in force since March 17, 2026, on the ANPD's March 20, 2026 timeline and under its final age-assurance guide. See also the US state laws on app-store age signals, Italy's Character.AI age-verification decision, and TikTok's US children's privacy cases: the $400 million COPPA settlement and the minor privacy litigation ruling.

What can a scan and a traffic capture show about a logged-out feed?

When I scan an Android app, the static report lists, with file and line, references to the Google Advertising ID API (AdvertisingIdClient.getAdvertisingIdInfo) in builds with an attribution SDK, and the android_id settings key in builds with an ad or attribution SDK. That is presence in the build. A traffic capture of the logged-out mode on a test device records which of the four identifiers appear in each request, which host receives it, and whether it is sent before or after the age screen (what a scan checks). A capture covers one device on one date; what a recipient does with an identifier is outside it (the limits of a scan).

I run these investigations for lawyers and researchers working with lawyers, on one app or a list in bulk. Sign up for a CanITrustThat account to run your own research, or let us run an investigation for you.

App privacy law, applied to real apps.

Posts on new laws, fines and studies, and teardowns of the apps those laws apply to.

How we use your address: privacy notice. Prefer a feed reader? Use the RSS feed.