On August 25, 2026, Brazil's Autoridade Nacional de Proteção de Dados (ANPD) fined ByteDance R$153.7 million — roughly $30 million — in what is the agency's largest penalty since its creation in 2020 and its first monetary sanction against a social media company. The ruling, published in the Diário Oficial da União and confirmed on ANPD's own site, found five violations of the Lei Geral de Proteção de Dados (LGPD, Law 13.709/2018) in how TikTok handled children's and teenagers' data — not just in registered accounts, but in the app's logged-out "guest" feed (ANPD; Agência Gov).
The steelman: age gates are theater, and ANPD knows it
Regulators have spent a decade watching platforms treat "are you 16?" checkboxes as a compliance formality rather than a real control. ANPD's finding — that TikTok's own mechanisms "were not sufficient to prevent, from the outset, the improper processing" of minors' data — is a fair diagnosis of an industry-wide problem, not a Brazil-specific overreach. Self-declared age has never been a meaningful gate, and platforms have had every commercial incentive not to fix that: more users, even underage ones misrepresenting their age, means more engagement and more ad inventory. If a regulator's job is to make the stated rule match the actual practice, ANPD found a real gap between TikTok's terms of service and its default behavior.
The more interesting part of the ruling is what it does not require: an account. ANPD's order applies equally to people who never signed up. As TNW's reporting on the decision notes, "most child-safety enforcement to date has turned on accounts" — age claimed at signup, settings applied afterward. Brazil instead treated the collection itself as the violation, regardless of whether the person browsing ever identified as a minor. That is a genuinely novel legal theory, and it travels: it doesn't depend on age verification working, because it doesn't ask the platform to verify anything before it stops collecting.
Where the remedy overshoots the finding
The five violations ANPD identified are specific and defensible: processing children's data without a valid legal basis, in both the logged-in and logged-out feeds, without adequate preventive safeguards (ANPD). Fining a company for collecting data it had no lawful basis to collect is a straightforward application of LGPD Articles 6 and 7, the same lawful-basis test the GDPR applies in Europe.
The remedy is broader than the diagnosis. ANPD ordered a flat 12-hour daily screen-time cap for all logged-out users in Brazil — not just minors, and not calibrated to any age signal at all, because by design there isn't one. It barred logged-out users from posting, live-streaming, or seeing anything but "all ages" content, and cut off targeted advertising in that mode nationwide (Euronews; TNW). An adult in São Paulo checking TikTok without an account now hits the same restrictions as the minors the order is meant to protect. That's not a proportionality quibble — it's the direct consequence of a legal theory that can't distinguish ages among people it never asked to identify themselves. The fix for "we can't verify who's a minor in guest mode" should be narrower data minimization for that mode, not a universal curfew applied to every adult who declines to log in.
The fine itself is calibrated; the enforcement pattern is not
R$153.7 million is a meaningful but not punitive number for a company of ByteDance's scale — a proportionate first monetary sanction rather than a company-ending one, which is the right instinct for a first-of-its-kind action. What should worry platforms operating in Brazil is less the amount than the trajectory: ANPD, an agency that was still issuing advisory recommendations a few weeks earlier, moved against Discord on child-safety grounds within the same three-week window as the TikTok fine, per TNW's reporting. An agency graduating quickly from guidance to fines, without settled precedent on how far a "lawful basis" theory extends to anonymous or logged-out activity, creates exactly the kind of compliance uncertainty that a maturing regulator should be trying to avoid — companies can't build reliable guest-mode data practices around a legal test that hasn't been tested in appeal yet.
Why this ruling will get cited outside Brazil
ANPD's guest-session theory matters beyond Brazil because it sidesteps the hardest problem in child-safety regulation: age verification for people who never gave you an age. The EU's Digital Services Act investigation into TikTok remains open with no fine yet issued; the UK, Australia, and others have leaned on curfews, bans, or parental-linking mandates that all still assume an identified minor on the other end. ANPD's approach doesn't need one — it asks what data was collected and whether the platform had a right to collect it, full stop. That is a cleaner legal hook for regulators elsewhere to borrow, and platforms should expect it to travel long before the 12-hour screen-time mechanics do. ByteDance has ten business days from publication to appeal to ANPD's board (Migalhas), and that appeal — not the fine amount — is where the guest-session theory will actually be tested.