Skip to Content
ANALYSISMEMBER

Beyond the fine: What the TikTok case reveals about LGPD enforcement

In August, Brazil's ANPD fined ByteDance Brazil for LGPD violations related to processing children's data, offering insight into the agency's evolving enforcement priorities.

Published
Subscribe to IAPP newsletters

Contributors:

Ana Silvia Martins

CDPO/BR

Partner

Failla Lima e Riva Advogados

Maria Eduarda Andrade

CDPO/BR

Lawyer

Failla Lima e Riva Advogados

Editor's note

The IAPP is policy neutral. We publish contributed opinion pieces to enable our members to hear a broad spectrum of views in our domains.

In August 2026, Brazil's data protection agency, the Agência Nacional de Proteção de Dados, fined ByteDance Brazil, the entity responsible for TikTok, BRL153.7 million for violating the country's General Data Protection Law in its processing of children's and adolescents' personal data. The size of the fine itself is noteworthy, but the decision is equally significant for what it reveals about how the ANPD is shaping its enforcement approach. The agency's assessment went beyond the existence of a legal basis for processing. It also examined the effectiveness of preventive measures and the controller's ability to demonstrate compliance with the law.

The investigation began in 2021 following a complaint submitted to the agency and continued over several years. During this period, ByteDance was required to provide clarifications and additional information regarding its processing activities. The ANPD also reviewed data protection impact assessments submitted by the company and subsequently ordered the adoption of specific measures, including the preparation of a compliance plan and the implementation of mechanisms relating to age verification and the legal representation or assistance of adolescents.

The assessment focused in particular on the processing of children's and adolescents' data under two forms of access to the platform: the "feed with registration" and the "feed without registration." Among the issues considered were whether a valid legal basis existed for the processing, whether performance of a contract could validly support such processing and whether the mechanisms adopted to prevent underage users from accessing or registering on the platform were effective.

In its first decision in the enforcement proceeding, the ANPD found five violations of the LGPD, relating to the absence of a valid legal basis for certain processing activities and breaches of the principles of prevention and accountability.

Contributors:

Ana Silvia Martins

CDPO/BR

Partner

Failla Lima e Riva Advogados

Maria Eduarda Andrade

CDPO/BR

Lawyer

Failla Lima e Riva Advogados

MEMBER

Unlock this exclusive content and more

Join the IAPPAlready a member? Sign in

Membership opens up a world of resources

In-depth knowledge

From original research reports and daily news coverage to legislative trackers and infographics, we have the information you need to stay ahead of change.

A global network

Make valuable professional connections through more than 160 local IAPP KnowledgeNet chapters in 70 countries.

Access to the experts

Connect with top thinkers in privacy, AI governance and cybersecurity for fresh ideas and insights.

Learn what you get from membership