Beyond the fine: What the TikTok case reveals About LGPD enforcement

In August, Brazil's ANPD fined ByteDance Brazil for LGPD violations related to processing children's data, offering insight into the agency's evolving enforcement priorities.

Contributors:
Ana Silvia Martins
CDPO/BR
Partner
Failla Lima e Riva Advogados
Maria Eduarda Andrade
CDPO/BR
Lawyer
Editor's note
The IAPP is policy neutral. We publish contributed opinion pieces to enable our members to hear a broad spectrum of views in our domains.
This article is part of an ongoing series that will explore issues or recent developments in data, cybersecurity and artificial intelligence governance.
In August 2026, Brazil's data protection agency, the Agência Nacional de Proteção de Dados, fined ByteDance Brazil, the entity responsible for TikTok, BRL153.7 million for violating the country's General Data Protection Law in its processing of children's and adolescents' personal data. The size of the fine itself is noteworthy, but the decision is equally significant for what it reveals about how the ANPD is shaping its enforcement approach. The agency's assessment went beyond the existence of a legal basis for processing. It also examined the effectiveness of preventive measures and the controller's ability to demonstrate compliance with the law.
The investigation began in 2021 following a complaint submitted to the agency and continued over several years. During this period, ByteDance was required to provide clarifications and additional information regarding its processing activities. The ANPD also reviewed data protection impact assessments submitted by the company and subsequently ordered the adoption of specific measures, including the preparation of a compliance plan and the implementation of mechanisms relating to age verification and the legal representation or assistance of adolescents.
The assessment focused in particular on the processing of children's and adolescents' data under two forms of access to the platform: the "feed with registration" and the "feed without registration." Among the issues considered were whether a valid legal basis existed for the processing, whether performance of a contract could validly support such processing and whether the mechanisms adopted to prevent underage users from accessing or registering on the platform were effective.
In its first decision in the enforcement proceeding, the ANPD found five violations of the LGPD, relating to the absence of a valid legal basis for certain processing activities and breaches of the principles of prevention and accountability.
With respect to the principle of prevention, the agency concluded that ByteDance failed to adopt sufficient measures to prevent the processing of personal data of children and adolescents under the age 13 through the feed without registration and to prevent those users from registering on the platform. Regarding the feed with registration, the assessment also considered shortcomings in the company's age-verification mechanisms and the lack of adequate review of those mechanisms throughout the investigation.
The accountability principle was addressed in similarly concrete terms. According to the analysis incorporated into the decision, the company was unable to demonstrate the effectiveness of the measures it had adopted or provide sufficient technical detail to enable a proper understanding of its processing activities and operations. In the ANPD's assessment, the absence of such evidence prevented the company from providing a concrete and verifiable demonstration of compliance.
This aspect of the decision is particularly relevant because it highlights the practical dimension of accountability. The existence of policies, procedures or controls does not, in itself, satisfy the principle. Controllers must be able to demonstrate that the measures they have established were implemented and effective in practice.
The ANPD also found that processing was conducted without a valid legal basis in both the feed without registration and in the registration process for children and adolescents. With respect to the latter, the decision emphasized the absence of a valid contractual relationship due to insufficient mechanisms for legal representation or assistance, undermining reliance on performance of a contract as the legal basis for processing.
This finding is significant because it shows that the assessment of a legal basis cannot be separated from the legal conditions on which that basis depends. Where processing relies on performance of a contract, the validity of the underlying contractual relationship itself becomes part of the assessment of whether that legal basis may properly be relied upon in the circumstances.
In addition to the fines, the ANPD ordered the deletion of personal data related to adolescents between ages 13 and 18 whose legal representation or assistance is not regularized within the prescribed period. The obligation also extends to third parties that received the data. ByteDance must identify these recipients, notify them of the deletion requirement and provide the agency with evidence that the notifications have been made.
In practice, complying with an order of this nature requires more than a data retention policy or a data inventory. An organization must be able to locate the relevant information, understand how it flows across its environment, identify the recipients to whom it was disclosed and demonstrate that deletion has in fact been completed.
The evidentiary standard set out in the decision is also significant. The company must submit a detailed technical report, system audit logs and a formal statement signed by its data protection officer. If the ANPD considers those materials insufficient, it may require an external and independent audit.
The case also forms part of a broader regulatory environment aimed at strengthening the protection of children and adolescents in the digital sphere. Brazil's Digital Statute for Children and Adolescents, or ECA Digital, which has been in force since March 2026, introduced new requirements including age assurance obligations. In approving ByteDance's compliance plan, the ANPD also required the company to incorporate these new requirements in accordance with the timetable and regulatory guidance.
It is important, however, to distinguish between these two regulatory dimensions. The violations established in the enforcement proceeding arise under the LGPD. The ECA Digital, by contrast, is part of the regulatory framework currently applicable to the company's operations and will shape the compliance measures that must be implemented going forward.
The TikTok case therefore provides an important indication of how the ANPD's enforcement practice is evolving. Its significance lies not only in the size of the fines, but also in the compliance standard that the decision helps to make more tangible.
In this context, accountability is no longer an abstract obligation. It requires evidence. Organizations must be able to demonstrate that the measures they adopt have been implemented, are appropriate to the risks involved and operate effectively in practice.

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.
Submit for CPEsContributors:
Ana Silvia Martins
CDPO/BR
Partner
Failla Lima e Riva Advogados
Maria Eduarda Andrade
CDPO/BR
Lawyer



