São Paulo, Brazil – Brazil has fined TikTok owner ByteDance R$153.7 million ($29.8 million) for improperly processing the personal data of children and teenagers, the first financial penalty imposed on a social media company by the country’s data protection authority.
The National Data Protection Authority, known by its Portuguese acronym ANPD, said TikTok failed to prevent minors from having their data processed without a valid legal basis and lacked sufficient safeguards to stop children and teenagers from accessing parts of the platform.
The regulator estimates that the personal data of at least 8 million minors may have been processed because of inadequate age verification mechanisms.
The news came the same week that Tik Tok’s competitor, Meta, which owns Facebook and Instagram, agreed to a $17 billion settlement in a US court for child safety allegations.
The penalty, announced on August 25, comes as Brazilian authorities are taking a closer look at how some of the world’s largest technology companies protect their young users. Days before announcing the TikTok fine, the ANPD opened monitoring proceedings involving 22 digital services, including social networks, artificial intelligence platforms and app stores.
The TikTok investigation focused on two ways people can use the platform in Brazil.
- One involves registered users with accounts.
- The other, known as the “logged-out feed,” allows people to watch videos without creating an account.
The ANPD identified violations of Brazil’s data protection law in both forms of access.
“The mechanisms adopted by the company were not sufficient to prevent, from the outset, the improper processing of personal data belonging to children and adolescents,” the ANPD said, citing the findings of its enforcement division.
According to the regulator, TikTok committed five violations of Brazil’s General Data Protection Law (LGPD), including processing minors’ data without an adequate legal basis and failing to demonstrate that its safeguards were effective.
The platform’s response
TikTok argued during the proceedings that processing some of the information was permitted because users accepted its terms of service, creating a contractual relationship. The ANPD rejected that reasoning in the cases involving minors, finding that children and teenagers would need parental representation or assistance for such a contract to be valid.
The regulator also found that TikTok had not done enough to prevent minors from registering for accounts or to prevent their data from being processed when they accessed the platform without one.
TikTok said that the penalty relates to conduct from 2021 and does not reflect changes the company has made since then. “The decision imposing the fine refers to an earlier period (2021) and does not reflect the actions provided for in this plan or the measures voluntarily implemented since then, which ensure compliance with the LGPD in both the logged-in and logged-out experiences.” The statement was provided to Brazilian news outlet G1.
The company said the safety of children and teenagers is an “absolute priority” and that it has maintained a “transparent and collaborative” dialogue with the regulator. “We will continue engaging with the ANPD while we assess the appropriate measures,” the company said.
ByteDance can appeal the decision. The company has 10 business days from notification to file an appeal and 20 business days to pay the fine. It can receive a 25% reduction if it gives up its right to appeal and pays within the required period.
The size of the penalty was calculated using ByteDance’s gross revenue in Brazil in 2025, excluding taxes. The company’s revenue figures were not disclosed because they are protected by tax confidentiality. The ANPD also ordered ByteDance to delete data collected in violation of the law.
A different TikTok for users without accounts
The ANPD also ordered changes to how TikTok handles younger users in Brazil. ByteDance must implement a compliance plan that changes how TikTok operates for children and teenagers in Brazil, particularly for people who access the service without creating an account.
For registered users under 16, TikTok will have to automatically apply its most restrictive privacy settings. Those settings can only be changed with authorization from a parent or guardian. The platform must also strengthen parental supervision tools and introduce stricter content filters.
Users accessing the platform without an account will be limited to 12 hours of use. They will not be allowed to publish videos, comment, send direct messages or use other social features. They will also be unable to follow accounts, gain followers, post livestreams or watch them.
Now, TikTok must stop showing advertisements entirely to logged-out users in Brazil and restrict the feed to content considered appropriate for all ages. Personalization will also be sharply limited.
The platform will still be able to process a narrower set of information, including language and regional data used to select relevant content, basic device information used for fraud prevention, and data needed for the application to function properly.
TikTok’s logged-out feed allows people to browse videos without providing an age during account registration. According to Reuters, the feature is not available in the United States or Europe. Brazilian regulators had already challenged the feature before imposing this week’s fine. In 2024, the ANPD ordered the suspension of the logged-out feed as part of its investigation into whether TikTok was adequately protecting children and teenagers.
ByteDance later presented a compliance plan to the regulator. The ANPD’s board approved it, while requiring the company to comply with new age verification obligations under Brazil’s Digital Statute for Children and Adolescents. The company positioned itself and said that the plan had been presented to and approved by the ANPD in 2025 and said measures implemented since then ensure that both its registered and logged-out services comply with Brazilian data protection law.
According to the ANPD, ByteDance sought a reduction based partly on its compliance plan, but the agency concluded that a reduction required evidence that the measures had actually been implemented.
Brazil increases scrutiny of online platforms
TikTok is one of several digital platforms currently under scrutiny by Brazilian regulators. Earlier in August, the ANPD ordered Discord to suspend livestreaming in Brazil as a preventive measure after identifying failures in safeguards intended to prevent serious violations involving children and teenagers.
Unlike the TikTok case, the Discord action was not a financial penalty. The platform was ordered to suspend livestreams and similar video-sharing features until it could demonstrate that it had adopted effective measures to protect minors.
On August 21, four days before announcing the TikTok fine, the ANPD began two monitoring actions covering 22 digital services. The regulator is examining whether companies are complying with rules intended to protect children, teenagers and women online.
ByteDance has 10 business days from notification to appeal the R$153.7 million fine. If it waives its right to appeal and pays within the required period, the company can receive a 25% reduction.
Featured image credit: ANPD Brazil.
Facts Only
* Brazil's National Data Protection Authority (ANPD) fined ByteDance R$153.7 million ($29.8 million).
* The fine concerns the processing of personal data of children and teenagers on TikTok.
* The ANPD estimates at least 8 million minors' data may have been processed without adequate age verification.
* ByteDance has 10 business days to appeal and 20 business days to pay.
* A 25% reduction is available if the company waives its right to appeal and pays on time.
* The penalty is based on ByteDance's 2025 gross revenue in Brazil, excluding taxes.
* ANPD ordered ByteDance to delete data collected in violation of the General Data Protection Law (LGPD).
* Logged-out users in Brazil will be limited to 12 hours of use and barred from social features, livestreams, and advertisements.
* Users under 16 must have the most restrictive privacy settings applied automatically.
* ANPD opened monitoring proceedings involving 22 digital services on August 21.
* Discord was ordered to suspend livestreaming in Brazil earlier in August.
* Meta agreed to a $17 billion settlement in a US court for child safety allegations during the same week as the TikTok announcement.
Executive Summary
Brazil's National Data Protection Authority (ANPD) has imposed a R$153.7 million fine on ByteDance for violating the General Data Protection Law (LGPD). The regulator found that TikTok failed to implement sufficient age verification and safeguards, potentially exposing the data of 8 million minors. The violations occurred across both registered accounts and the "logged-out feed," a feature that allows video consumption without an account—a functionality not available in the US or Europe.
ByteDance contends that the fine relates to conduct from 2021 and does not account for subsequent compliance measures implemented in 2025. While TikTok argues that terms of service established a contractual relationship with users, the ANPD rejected this, noting that minors require parental assistance for such contracts to be valid. Beyond the financial penalty, the ANPD has mandated strict operational changes, including limiting logged-out usage to 12 hours, removing ads for non-account holders, and enforcing restrictive privacy settings for those under 16. This action is part of a broader Brazilian regulatory trend targeting 22 digital services to enhance the protection of children, teenagers, and women online.
Full Take
The strongest version of this narrative is that Brazil is establishing itself as a rigorous global regulator of the "attention economy," moving beyond mere warnings to tangible financial and operational penalties to protect vulnerable populations. By targeting the "logged-out feed," the ANPD is addressing a specific architectural loophole that allows platforms to harvest data while bypassing the friction of age-gate registration.
The narrative is straightforward and descriptive; it balances the regulator's findings with the company's defense without employing engineered emotional triggers or forced binaries. It presents a factual conflict between a regulator's legal interpretation of "consent" for minors and a corporation's "contractual" interpretation.
Patterns detected: none
The driving paradigm is the shift from corporate self-regulation to state-mandated compliance. It echoes the global trajectory seen with the GDPR in Europe, where the burden of proof for data legality has shifted from the user (to opt-out) to the company (to prove a valid legal basis). The unstated assumption is that algorithmic personalization is inherently risky for minors, regardless of the content itself.
The implication is a fragmented global internet where "feature parity" disappears. If the logged-out feed is banned or crippled in Brazil but exists elsewhere, the user experience becomes geographically determined by local legal thresholds rather than product design. This increases the cost of entry for tech firms but increases the agency of the state over the digital environment.
Bridge Questions:
1. How does the definition of "parental representation" vary across cultures, and can a digital interface ever truly verify it?
2. If financial penalties are calculated based on revenue, does this create a "cost of doing business" model where fines are simply budgeted expenses?
3. What are the privacy implications of the "compliance plans" themselves, which may require platforms to collect *more* sensitive data to verify age?
Counterstrike Scan: An influence campaign pushing this narrative would likely use "moral panic" framing to justify sweeping censorship or state surveillance under the guise of "child safety." However, this account sticks to the legal mechanisms of the LGPD and specific operational mandates, remaining structurally clean of such patterns.
