Brazil’s data protection authority fined TikTok parent company ByteDance 153.7 million reais, roughly $29.8 million, on Tuesday. The regulatory penalty targets systemic failures in handling children’s data across both logged-in accounts and guest browsing sessions, mandating strict new privacy settings, content filters, and data deletion across the platform.
While international regulators often focus enforcement efforts strictly on registered user profiles, Brazil’s National Data Protection Authority (ANPD) expanded its scope significantly. The agency determined that TikTok breached data privacy laws across both standard accounts and guest browsing sessions by collecting and processing young users’ personal information without a valid legal basis or adequate safeguards.
The Anatomy of the Fine and Regulatory Violations
The financial penalty, published in the country’s official gazette, totals 153.7 million Brazilian reais, which translates to approximately $29.8 million or $29.9 million. ANPD officials explained that the administrative proceeding identified violations of Brazil’s General Data Protection Law (LGPD).

The investigation dissected two primary access channels: the feed without registration,
which can be accessed without creating an account, and the feed with registration,
linked to a registered profile. In both cases, the ANPD found that the platform processed personal data belonging to children and adolescents without an adequate legal basis under the LGPD, and failed to adopt effective measures to prevent such processing.
National Data Protection Authority, ANPD ruling
An enforcement director with the regulatory body, Fabricio Lopes, stated at a press conference that TikTok was not taking the necessary measures to prevent adolescents from accessing the platform and from having the data of these children and adolescents processed.
He added that this data was being used to offer advertising to adolescents.
Furthermore, Lopes stated that the fine was a powerful signal to other platforms regarding how seriously the ANPD takes this work
and that the agency hoped they get the message.

Targeting the Unregistered Guest Experience
The most distinctive element of the Brazilian ruling involves guest browsing. While most global child safety enforcement to date has turned on accounts, Brazil’s regulator found that the data problem existed for people browsing without signing in at all.
The regulatory authority estimated that TikTok may have processed the data of at least 8 million children, highlighting what they said were systemic deficiencies within the platform’s age-verification mechanism. The company also failed to provide concrete evidence that its technical and organizational measures were effective in complying.
In addition to the fine of 153.7 million reais, the agency ordered parent company ByteDance to delete the data collected in violation of regulations. The ruling also mandates that ByteDance formulate an improved comprehension plan. The platform will be required to automatically apply stricter privacy settings to accounts belonging to children under 16, strengthen parental supervision systems, and implement stricter content filters. According to the agency, ByteDance has committed to implementing a compliance plan to improve the protection of children and adolescents.
The company can still appeal the decision in the next 10 days, according to the regulator.
