Brazil's data protection authority set out five separate breaches of the country's data protection law by ByteDance Brasil Tecnologia Ltda in an investigation report signed on August 24, 2026, recommending simple fines totalling R$ 153,769,671.33 and the deletion of personal data collected from adolescents registered on TikTok without valid parental representation.

The document, Investigation Report (PUB) No. 2/2026/CGS/SFI, closes the evidentiary phase of Administrative Sanctioning Proceeding No. 00261.006648/2024-02, a case that began with a single complaint filed against TikTok on March 23, 2021. Five years and two technical notes later, the ANPD has produced what amounts to a detailed dissection of how a recommendation engine handles users it has never identified.

For advertisers, the substance sits below the headline number. The report does not treat the absence of a login as a mitigating factor. It treats it as an aggravating one.

Five findings, three articles

The report separates the conduct into five counts, each carrying its own fine calculated under Resolution CD/ANPD No. 4 of February 24, 2023, the regulation governing penalty dosimetry.

Conduct 1 concerns the processing of personal data belonging to under-18s in the "feed without registration" without a valid legal basis, a breach of Article 7 of the LGPD, assessed at R$ 35,760,388.68. Conduct 2 covers the failure to prevent that processing in the first place, a breach of Article 6, VIII, assessed at the same amount. Conduct 3 addresses registration itself, where the report finds no valid contract existed to support processing under Article 7, at R$ 27,416,297.99. Conduct 4 covers the failure to prevent under-13s from registering, again under Article 6, VIII, at R$ 27,416,297.99. Conduct 5 concerns the failure to demonstrate that any of the measures adopted actually worked, a breach of the accountability principle in Article 6, X, at R$ 27,416,297.99.

Grouped by provision, Article 7 accounts for R$ 63,176,686.67, Article 6, VIII for the same figure, and Article 6, X for R$ 27,416,297.99.

Each count was classified as serious under Article 8, paragraph 3, item I of the dosimetry regulation, on three grounds applied consistently across all five: large-scale processing, economic advantage obtained or intended, and the processing of children's and adolescents' data. No aggravating circumstances were found. No mitigating circumstances were granted either, despite ByteDance requesting three of them.

The company's argument for mitigation rested on the compliance plan it filed during the parallel inspection proceeding. The report rejects that reasoning on procedural grounds, noting that Article 13, paragraph 3 of the dosimetry regulation places the burden of proof on the violator, and that a plan awaiting approval, implementation and certification does not meet the legal test for a reduction.

The base revenue figures used in the calculation are redacted throughout under tax confidentiality provisions of Article 198 of Law No. 5,172 of 1966. What survives is the arithmetic result and the statutory ceiling: 2 percent of Brazilian revenue excluding taxes, capped at R$ 50,000,000.00 per infraction. The report confirms each individual fine sits below that ceiling and above the R$ 12,000.00 floor.

The feed nobody had to log into

The centre of the case is a product feature rather than a policy document. TikTok's "feed without registration" allowed anyone to open the application and scroll indefinitely without creating an account. According to the report, that design choice functioned as "a pathway actively facilitated and offered by the company, representing a conscious structural design choice that enabled broad and unrestricted access to the platform."

ByteDance defended the feature as a deliberately limited experience. Its submissions describe data collection restricted to the device level, without profile creation, without behavioural logs, and without personalised advertising. The recommendation mechanism, the company argued, operates on generic numerical criteria unconnected to individual identification.

The ANPD tested that claim by tabulating the two experiences side by side. The comparison, reproduced as Table 1 in the report, is the analytical core of the decision.

In the registered feed, TikTok processes videos the user likes, shares and comments on. In the unregistered feed, it processes videos the user attempts to like, share or comment on. Registered users have accounts they follow; unregistered users have accounts they attempt to follow. Both experiences capture videos watched in full or skipped, captions, audio, hashtags, view counts, the country where a video was posted, device settings, language preference, country, time zone, day and device type.

Two differences emerge. Account settings are absent, because no account exists. And the unregistered feed adds a metric the registered feed does not list separately: time spent watching a specific video.

The report's conclusion on that table is blunt. The comparison "indisputably refutes the respondent's claim that the processing of personal data is limited in the 'feed without registration' mode compared to the 'feed with registration' mode."

Why a blocked click is still a signal

The reasoning that follows has consequences well beyond one platform. The ANPD argues that for a recommendation algorithm, "the predictive value of the data lies in the impulse and interest expressed by the user when clicking the button." Capturing the attempt therefore delivers the same technical capability to track, map and build predictive profiles as capturing the completed action would.

ByteDance maintained throughout that it does not classify unregistered users and does not create behavioural profiles of them, only performing numerical calculations to recommend content. The report treats the terminology as beside the point, holding that the concrete effects of personalisation based on inferred characteristics are materially equivalent to profiling regardless of what the practice is called. Whether a dataset is keyed to a name or to an internal identification number "does not alter the essential fact."

That framing matters for anyone operating identity-light or cookieless targeting infrastructure. The regulator's test is not whether a natural person has been named. It is whether the relationship between a device, its interaction patterns and the content served allows the platform to influence the behaviour of the person behind the screen.

The report also draws on the company's own impact assessment. Content personalisation, ByteDance stated in its Personal Data Protection Impact Report, is "central to the Platform" and serves to build and retain an engaged user base while "ensuring the Platform's commercial viability (since the Platform's popularity is a factor in attracting business partners)." The ANPD uses that sentence to establish economic advantage under the dosimetry regulation, including for the unregistered feed, where advertisements were displayed even if not personalised.

A contract with a party who cannot sign

The Article 7 findings turn on Brazilian civil law rather than data protection doctrine. ByteDance relied on contract performance as its legal basis, pointing to a pop-up requesting acceptance of the Terms of Use.

Article 104, I of the Civil Code requires a capable agent for a valid contract. Under Brazilian law, children under 12 and adolescents up to 16 are absolutely incapable, and those between 16 and 18 relatively so. The report concludes that acceptance of terms by a minor without parental assistance or representation lacks legal validity, which in turn removes the foundation for the legal basis invoked.

ByteDance argued that Brazilian law prescribes no specific form for parental assistance, that clicks in a digital environment suffice, and that the "theory of socially typical behaviour" validates everyday acts by minors such as buying snacks or riding public transport. The ANPD rejects the parallel, distinguishing a one-off purchase from a relationship that "endures over time, generating a continuous and massive flow of data collection, behavioral profiling, and targeted personalized advertising."

A separate finding addresses what users actually saw at registration. Technical Note No. 6/2023 established that the full message on representation and assistance was not displayed during signup. What appeared instead was the standard line about agreeing to the Terms of Use and confirming the Privacy Policy had been read. A footnote cites 2023 TIC Kids data indicating that reading the privacy policies of WhatsApp, Snapchat, Twitter, TikTok and Instagram would take three hours and six minutes at adult reading speed.

Late in the proceeding, ByteDance told the authority it had concluded internally that legitimate interest would be the more appropriate legal basis for the unregistered feed. The report declines to assess whether that would work, holding that a change of legal basis after a sanctioning proceeding opens "does not absolve the respondent of liability for past conduct."

The advertising layer the report examines directly

Buried in the Conduct 4 analysis is material that speaks directly to media buyers. Document SEI No. 0230320 records ByteDance's position that it does not serve personalised advertisements to adolescent users in Brazil, and does not show teenage users non-personalised advertisements for products inappropriate to their age group, listing energy drinks and video games or media rated above 13 as examples. The same document states that the recommendation algorithm is identical for teenagers and adults, with additional policies and technology layered on top.

The ANPD turns that architecture into a finding. If protections depend on correct age classification, then correct age classification becomes a prerequisite for the lawfulness of everything downstream. According to the report, "if the algorithm classifies a teenager who has managed to bypass the age gate as an adult, all personal data processing operations will disregard the user's vulnerable status," which renders the platform's privacy tools "ineffective formalities."

A second finding, under Conduct 5, concerns the data-sharing chain. Asked about any policy for notifying business partners of the need to delete data, the company stated it would not share the data in the future. The report describes that answer as incomplete and evasive, noting the absence of "a structured policy to require advertisers and business partners to delete personal data of children and adolescents under 13 years of age." Deletion obligations, on this reading, do not stop at the platform boundary.

Deletion, audit logs and a daily penalty

Conduct 3 carries a sanction beyond money. ByteDance must delete personal data collected from adolescents aged 13 and over but under 18 in the registered feed, unless legal representation or supervision is regularised within 60 business days of notification of the decision. The report frames the window as an opportunity to remedy a structural flaw in the database rather than a grace period.

The obligation extends outward. The company must notify third parties with whom it shared data belonging to non-compliant adolescent accounts of their obligation to delete that data from their own databases.

Within five business days of the deadline expiring, ByteDance must submit a detailed technical report accompanied by system audit logs and a formal statement signed by its Data Protection Officer, plus a list of the third parties notified and proof of notification. The ANPD reserves the right to commission an independent external audit if the documentation proves insufficient.

Non-compliance with any of those four obligations triggers a daily fine of R$ 137,081.49, calculated as 0.5 percent of the base fine for that conduct, under Article 52, III of the LGPD.

Numbers the report does surface

The revenue figures are redacted, but other quantities are not. ByteDance removed more than 7.75 million children's accounts in Brazil between October 2022 and September 2023, a figure drawn from its own submissions. The report treats that volume as evidence the company knew children were on the platform at scale, and notes it says nothing about how long those accounts were active, how their interaction data was handled, or whether the resulting datasets were actually deleted.

The continuous processing period is anchored to August 1, 2021, when the LGPD's sanctioning provisions took effect, TikTok having launched in Brazil in 2018. That places the conduct at nearly five years by the report's reckoning.

Harm was graded at level 3 for both unregistered-feed counts, on grounds of irreversibility, and at level 2 for the three counts involving the registered feed, where the report acknowledges that some form of age verification exists, however flawed, and that detected under-13 accounts were deleted.

ByteDance's defence leaned repeatedly on the argument that its age gate matches what other platforms do, and that no universal, effective and proportionate age verification technology exists. Requiring documents, biometrics or facial recognition, the company argued, would mean excessive collection of personal data including sensitive data, with exclusionary effects on vulnerable groups.

The report does not dispute the technical difficulty. It disputes the relevance. "The law requires compliance with legal principles, not conformity with average market behavior," it states, adding that where processing involves children the standard of protection must be higher than the market average.

The sharper point concerns internal consistency. The ANPD observes that no age verification mechanism existed in the unregistered feed at all, and that this absence "does not stem from a technical limitation" given that the same environment simultaneously processed behavioural data in real time for personalisation. The company demonstrated the capability, the report argues, and chose not to apply it to exclusion.

On the registered feed, the finding is one of persistence. Technical Note No. 6/2023 warned the company to revise its age verification mechanisms. More than a year later, Technical Note No. 50/2024 recorded the same deficiency.

Where this sits in Brazilian enforcement

The case predates the statutory framework now shaping platform obligations in Brazil. Lei 15.211/2025, the Estatuto Digital da Criança e do Adolescente, was signed in September 2025, and Brazil's data watchdog added child protection to its enforcement agenda on December 22, 2025, committing 30 inspection and enforcement actions to privacy-by-default configurations and age verification for the 2026-2027 period. Article 22 of that law bans profiling techniques for directing commercial advertising to minors.

The ANPD subsequently released a draft guide on age verification mechanisms for public consultation in May 2026, and ordered Discord to halt its Go Live feature for all Brazilian users within three business days earlier in August 2026. The agency had previously taken action against Meta over AI chatbots simulating child profiles in August 2025.

Internationally, TikTok has drawn parallel scrutiny of the same mechanics from different angles. The Irish Data Protection Commission imposed a 530 million euro fine over transfers of European user data to China in May 2025. The European Commission preliminarily found TikTok and Meta in breach of DSA transparency obligations in October 2025, and in February 2026 charged TikTok over addictive design features including infinite scroll, autoplay, push notifications and highly personalised recommender systems.

The Brazilian report cites some of that international material as context, including the Italian Garante's order restricting processing where age could not be established with certainty, a European Commission Joint Research Centre study finding minors can encounter self-harm content within 2.6 minutes of browsing, and a July 2026 European Parliament research study on algorithmic inference of vulnerability from viewing patterns.

Procedure from here

The report goes to the Superintendent of Inspection for a first-instance decision, which is published in the Official Gazette. ByteDance has 10 business days from notification to appeal to the agency's Conselho Diretor. Payment falls due within 20 business days of notification, and Article 18 of the dosimetry regulation offers a 25 percent reduction for an express waiver of the right to appeal, provided payment lands within that window.

A Conduct Adjustment Agreement is not available. ByteDance proposed negotiating one on January 16, 2025; the request was rejected because the ANPD has not yet issued the specific regulation that Article 44 of the inspection regulation requires for the mechanism to operate.

The Alana Institute, admitted as an interested third party on April 10, 2025, filed comments that prompted the agency to invite an amendment to ByteDance's final arguments, submitted on December 2, 2025.

What advertisers take from the file

Three elements of this decision travel beyond Brazil and beyond TikTok.

The first is the treatment of attempted interactions as behavioural signal. A blocked like is not a null event in the eyes of this regulator. It is intent, captured and used.

The second is the rejection of formal identification as the boundary of profiling. The report holds that a device identifier, an internal ID and a pattern of usage are sufficient to constitute personal data processing with profiling effects, whether or not the platform assigns categories or names.

The third is the downstream deletion obligation. Where a platform has shared data derived from unlawfully processed accounts, the report requires it to push deletion instructions through its partner chain and to document that it did so. For measurement vendors, demand-side platforms and any partner receiving audience signal from a platform with a known minor population, that is an operational exposure with an audit trail attached to it.

The report is explicit that its classifications bind nothing beyond this case. The reasoning, however, is now on the record of a regulator that has named child protection as a two-year enforcement priority.

Timeline

  • March 23, 2021 - A complaint against TikTok reaches the ANPD's General Coordination of Enforcement, opening Enforcement Proceeding No. 00261.000297/2021-75
  • August 1, 2021 - The LGPD's sanctioning provisions take effect, the date the report adopts as the start of continuous and repeated processing
  • May 3, 2022 - The ANPD sends Official Letter No. 124/2022 to ByteDance Brasil requesting explanations on TikTok's data processing
  • May 30, 2022 - ByteDance responds with information drawn largely from its Privacy Policy and Terms of Service
  • October 2022 to September 2023 - ByteDance removes more than 7.75 million children's accounts in Brazil, according to its own submission
  • 2023 - Technical Note No. 6/2023 warns the company to revise its age verification mechanisms
  • November 29, 2023 - Official Letter No. 50/2023 requests evidence on account removals, contract performance, the unregistered feed, data sharing and advertising
  • February 5, 2024 - ByteDance files updated impact reports and a revised table of legal bases
  • November 1, 2024 - Decision No. 2/2024/CGF orders full suspension of the unregistered feed and a compliance plan, and directs the opening of a sanctioning proceeding
  • November 4, 2024 - Notice of Violation No. 1/2024/FIS/CGF is issued against ByteDance Brasil
  • November 26, 2024 - ByteDance files its defence
  • January 16, 2025 - The company proposes a Conduct Adjustment Agreement; the request is later rejected
  • April 10, 2025 - The Alana Institute is admitted as an interested third party
  • June 3, 2025 - ByteDance files final arguments with an initial and a new compliance plan
  • December 2, 2025 - The company files an addendum to its final arguments
  • December 22, 2025 - The ANPD approves 2026-2027 enforcement priorities, placing child protection at the centre with 30 planned actions
  • March 18, 2026 - Decree No. 12,881 restructures the ANPD, followed by Resolution CD/ANPD No. 33 on April 6, 2026
  • May 23, 2026 - The ANPD opens a public consultation on a draft age verification guide
  • August 2026 - The ANPD orders Discord to halt Go Live for all Brazilian users within three business days
  • August 24, 2026 - Investigation Report (PUB) No. 2/2026/CGS/SFI is signed, recommending R$ 153,769,671.33 in fines and a data deletion sanction

Summary

Who: Brazil's Autoridade Nacional de Proteção de Dados, through its Superintendence of Inspection and General Coordination of Sanctions, acting against ByteDance Brasil Tecnologia Ltda as data controller for TikTok in Brazil. The report was drafted by Samira Borelli Satriano with Reinaldo Sena Junior, and signed off by Coordinator Mariana Gomes de Barros Fernandes Távora and General Coordinator Amanda Muniz Oliveira. The Alana Institute participated as an interested third party.

What: Investigation Report (PUB) No. 2/2026/CGS/SFI finds five breaches of the LGPD covering processing without a valid legal basis under Article 7, failure to prevent harm under Article 6, VIII, and failure to demonstrate effective measures under Article 6, X. Recommended simple fines total R$ 153,769,671.33, alongside an order to delete data collected from adolescents aged 13 to 17 in the registered feed absent valid parental representation, backed by a daily fine of R$ 137,081.49.

When: The report was signed on August 24, 2026, closing a proceeding opened on November 4, 2024 and an inspection that began with a complaint on March 23, 2021. Deletion must be completed within 60 business days of notification, with documentation due five business days later. Appeal to the Conselho Diretor runs for 10 business days.

Where: Brazil, covering TikTok's operations nationally in both the registered and unregistered feed experiences.

Why: The ANPD found that TikTok's unregistered feed collected behavioural and technical data substantially equivalent to the logged-in experience, including attempted likes, shares, comments and follows, without any age verification barrier, and that acceptance of standard-form terms by legally incapable minors could not support contract performance as a legal basis. The agency also found the company unable to demonstrate the effectiveness of its removal measures or to show any structured policy requiring advertisers and business partners to delete data belonging to under-13s.