Brazil Fines TikTok Over Minors’ Data Processing
On August 25, 2026, Brazil’s National Data Protection Authority (Autoridade Nacional de Proteção de Dados, ANPD) fined TikTok parent ByteDance BRL 153.7 million, approximately RMB 200 million, and ordered it to delete certain data belonging to underage users.
The investigation covered both browsing as a visitor and using a registered account. Visitors can watch content without registering, but TikTok still records device, location, and viewing data at this stage and uses it to adjust recommendations.
The ANPD found that TikTok lacked a valid legal basis for processing the data of visitors under 18 and failed to prevent children under 13 from entering before processing began. When minors registered accounts, the platform still lacked a valid legal basis and failed to prevent children under 13 from registering. The materials submitted by ByteDance were also insufficient to show that the relevant safeguards were effective.
The investigation concerned TikTok’s data processing activities in 2021. ByteDance told Reuters that it believed the penalty did not take account of measures adopted since then or a compliance plan already approved by the ANPD, and that the company was evaluating its next steps. ByteDance may appeal to the ANPD’s Board of Directors within ten business days after receiving notice.
I. The Five Violations Found by the ANPD
The ANPD’s published penalty report lists five violations and the corresponding fines:
- Visitor data was processed without a lawful basis. Users under 18 could browse without registering, while TikTok continued to process their personal data. The ANPD imposed a fine of approximately BRL 35.76 million (about RMB 46.69 million).
- Visitor mode lacked controls to keep children out. TikTok did not prevent children under 13 from entering before data processing began. The ANPD imposed a fine of approximately BRL 35.76 million (about RMB 46.69 million).
- Registration data was processed without a lawful basis. TikTok processed the personal data of users under 18 during registration, but the process in place at the time could not form a valid contract. The ANPD imposed a fine of approximately BRL 27.42 million (about RMB 35.79 million).
- The registration mechanism failed to prevent children under 13 from registering. The ANPD imposed a fine of approximately BRL 27.42 million (about RMB 35.79 million).
- There was insufficient evidence that the safeguards were effective. The materials submitted by ByteDance did not adequately demonstrate that the safeguards used for visitor access and account registration were effective. The ANPD imposed a fine of approximately BRL 27.42 million (about RMB 35.79 million).
The five fines total BRL 153,769,671.33 (approximately RMB 201 million). The third violation also carried a data deletion order covering registered users aged 13 through 17. ByteDance has 60 business days to correct the lack of parental representation or assistance for these accounts. If the issue remains unresolved after that period, ByteDance must delete the relevant personal data and instruct third parties that received the data to delete it as well.
Within five business days after the 60-business-day period ends, ByteDance must also submit a technical report, system audit logs, and a statement signed by its data protection officer to the ANPD.
The investigation report further states that the absence of valid parental involvement during registration also affects the legal basis for processing browsing histories, behavioral profiles, interaction metrics, and identifiers generated by the account afterward. The ANPD therefore allowed ByteDance an opportunity to correct the issue. If correction fails, the deletion obligation extends to data generated through the relevant accounts.
Of the first four violations, two concern the legal bases required under Article 7 of the LGPD, and two concern the prevention principle under Article 6(VIII). The fifth violation is based on the accountability principle in Article 6(X).
II. ByteDance’s Defense
ByteDance relied on Article 7(V) of the LGPD. This provision permits a controller to process personal data to perform a contract or complete procedures preliminary to entering into a contract. The ANPD therefore had to decide two separate questions: whether a visitor formed a contract with the platform by clicking to accept its terms, and whether a minor registering for an account had the civil capacity required to enter into a contract.
(1) The Contractual Relationship in Visitor Mode
ByteDance argued that users had to accept TikTok’s terms of service when they first opened the app and that this step created a visitor-access contract. It also argued that visitor mode processed less data and that children entered the platform only occasionally. After the enforcement proceeding began, ByteDance further submitted that legitimate interests would be a more appropriate legal basis for processing visitor data.
The ANPD rejected these arguments. In visitor mode, users did not need to create an account, and the platform did not verify whether a child was represented by a parent or guardian or whether an adolescent had received parental assistance. A click accepting the terms alone did not establish that a valid contract had been formed between the visitor and the platform.
The limited volume of data processed and the allegedly low frequency of child access did not alter the platform’s obligation to establish a legal basis for processing. ByteDance’s later reliance on legitimate interests could not cure processing that had already occurred.
(2) Minors’ Civil Capacity During Registration
Account registration is subject to the Brazilian Civil Code’s rules on minors’ civil capacity. Users under 16 need a parent or guardian to represent them when entering into a contract. Users aged 16 or 17 need parental assistance.
At the time, TikTok’s registration page merely informed users that continuing meant they accepted the terms of service and confirmed that they had read the privacy policy. Although the longer terms of service referred to parental representation or assistance, the registration process did not verify whether a parent or guardian was actually involved.
ByteDance argued that adolescents commonly register for social media platforms in everyday life, so parental supervision could be presumed. The ANPD rejected this analogy. Everyday transactions such as buying food or taking public transport generally end quickly. A TikTok account, by contrast, collects data over time, analyzes behavior, and serves personalized advertising, creating an ongoing impact on minors.
The ANPD concluded that a contract may provide a legal basis for processing minors’ data, provided that the contract is validly formed and that parental representation or assistance is implemented in accordance with Brazilian civil law. TikTok’s visitor and account-registration processes did not meet these conditions at the time.
III. Age Assurance and Evidence of Safeguards
The contractual legal basis determines whether the platform may begin processing the relevant data. TikTok’s terms of service already prohibited children under 13 from entering the platform. The ANPD therefore also examined whether the platform had preventive restrictions in place and whether ByteDance could show, with concrete evidence, that those restrictions worked in practice.
(1) Age Assurance and Preventive Controls
At the time, TikTok determined age primarily from the date of birth entered by the user. ByteDance stated that available technology could not completely prevent users from misstating their age and that the ANPD had not yet issued specific age-assurance standards. The company also said that visitor mode provided only limited content recommendations, did not serve targeted advertising, and used measures consistent with industry practice.
The ANPD instead assessed the risk in light of information already available to ByteDance. Between October 2022 and September 2023, ByteDance deleted more than 7.75 million Brazilian children’s accounts. According to the investigation report, this figure showed that access by children under 13 had reached a substantial scale.
Although visitors did not need to register, TikTok still recorded watch time, whether a video was completed or skipped, attempts to like or share content, device settings, language, and location, and used this information to adjust recommendations. The ANPD therefore found that ByteDance knew children could enter the platform but had not established effective restrictions before data processing began.
The prevention principle concerns whether safeguards operate before a risk materializes. Identifying and deleting children’s accounts afterward does not remedy the lack of protection when processing begins.
(2) Effectiveness of the Safeguards
In its defense, ByteDance stated that it continuously identified and deleted children’s accounts, had submitted a data protection impact assessment, and cooperated actively with the ANPD during the investigation.
The ANPD found that these materials listed policies, statements of principle, and the names of measures, but did not clearly show how the measures operated or what they achieved. They were therefore insufficient to demonstrate that the risk of children accessing the platform had been reduced.
Article 6(X) of the LGPD requires controllers to demonstrate that compliance measures are effective. The investigation report called for objective, verifiable, and auditable materials showing how measures were implemented, how identified problems were corrected, and whether the relevant risk had declined. The ANPD had previously required ByteDance to revisit its age-assurance mechanism, but the company still did not provide enough evidence to demonstrate the results of its remediation.
The accountability principle requires a company to use operational records and actual outcomes to show that its safeguards are effective. Evidence that a measure exists or remains in operation does not by itself satisfy this requirement.
IV. Kaamel’s Observations
In this case, the ANPD appears to have treated visitor mode as a separate data processing scenario. TikTok recorded device, location, and viewing data before a user created an account and used that information to adjust recommendations. Logged-out and unregistered use therefore also falls within the scope of a minors’ data compliance review.
Visitor mode raises the question of when data processing begins, while registration raises the validity of the contract. TikTok’s terms of service required minors to obtain parental permission, but the registration page asked users only to accept the terms and confirm that they had read the privacy policy. Because the registration process did not verify parental permission, the requirement in the terms could not support ByteDance’s claim that a valid contract had been formed.
In addition to contract validity and preventive controls, the ANPD examined the actual effect of the safeguards. ByteDance cited the deletion of more than 7.75 million children’s accounts as evidence that it continuously identified and removed such accounts. The ANPD viewed the same figure as an indication of the scale at which children under 13 accessed the platform. Account deletion records can show that a platform conducts remediation after the fact. Separate operational data is needed to show whether fewer children entered after age-assurance and access controls were introduced.
The penalty primarily concerns TikTok’s data processing activities in 2021 and is based on the LGPD and the Brazilian Civil Code. Brazil’s Digital Statute for Children and Adolescents (Estatuto Digital da Criança e do Adolescente, ECA Digital), which took effect in 2026, added requirements for age identification and platform safeguards but did not form the basis for the five violations in this case. A ByteDance compliance plan approved by the ANPD in a separate proceeding will also shape the platform’s subsequent remediation.
Companies designing safeguards for minors should begin with the actual product flow. Before launch, they should establish when visitor data collection and use begins and which legal basis applies. During registration, age assurance and parental involvement should be implemented in both the user interface and supporting processes. Companies should also record age-assurance results, actions taken on children’s accounts, and changes to safeguards, and periodically assess whether child access has declined. If a regulator opens an inquiry, these records will directly affect whether the company can demonstrate that its safeguards worked in practice.
Sources
- ANPD: Fine of BRL 153.7 million imposed on TikTok
- Public version of ANPD Investigation Report No. 2/2026
- ANPD: ECA Digital and implementation of age identification requirements
- Reuters: Brazil fines TikTok owner ByteDance for unlawful processing of teenagers data
- Historical BRL/CNY exchange rates (Investing.com)

