Brazil Hit TikTok With a $30 Million Fine for Collecting Children's Data
Key Takeaways
- Brazil's National Data Protection Authority (ANPD) fined ByteDance approximately $30 million for collecting and processing children's and teenagers' personal data without a valid legal basis or adequate safeguards, affecting an estimated 8 million minors.
- The ruling specifically targets TikTok's "logged-out feed" — a feature allowing users to browse content without creating an account — which the regulator says enables minors to use the platform while bypassing age-verification checks. This feature is available in Brazil but not in the US or EU.
- ByteDance has been ordered to erase all illegally collected data and must develop a comprehensive youth-protection framework. The company has 10 days to appeal.
- The fine arrives as Brazil is simultaneously pursuing constitutional challenges to ECA Digital, its broader child online safety framework — part of a week of intersecting stories about how regulators are approaching child data protection globally.
Brazil's National Data Protection Authority fined ByteDance approximately $30 million for breaching data privacy laws in its handling of children's and teenagers' personal data, according to reporting by Al Jazeera.
The regulator found that TikTok had collected and processed young users' personal information without a valid legal basis or adequate safeguards, across both logged-in accounts and guest browsing sessions. The fine includes an order to erase all data amassed illegally and a mandate to develop a comprehensive youth-protection framework.
The regulator estimated that TikTok may have processed data from at least 8M children in Brazil. ByteDance has 10 days to appeal.
The specific enforcement action that stands out is the targeting of TikTok's "logged-out feed" — a feature that allows users to browse content without creating an account. The ANPD found that this feature enables widespread use of the platform by minors while bypassing age-verification checks.
Notably, the logged-out feed is available in Brazil but is not offered in the United States or Europe, where access is limited to registered users.
A Feature Available in Brazil but Not in the US or EU
That geographic discrepancy is worth sitting with. TikTok applies stricter access controls in jurisdictions where regulatory enforcement pressure is highest (the US and EU) and maintains a more permissive version of the product in markets where that pressure has historically been lower.
The ANPD's fine is part of a broader pattern of regulators in the Global South pushing back against the assumption that different rules apply to them.
Brazil has been active in this space. Earlier this month, the ANPD ordered Discord to suspend its livestreaming feature following a 13-year-old girl's death by suicide after a livestream in which authorities say she was encouraged to harm herself.
The government and Supreme Court have been attempting to regulate internet use by minors — the constitutional challenge to ECA Digital's biometric age verification requirements that we covered earlier is part of the same cluster of activity.
The $30M fine is meaningful in its specificity: it targets a feature TikTok chose to make available in Brazil that it doesn't offer in markets with stronger regulatory infrastructure. That's not a technical accident. It's a product decision, and the ANPD is treating it as one.
What Enforcement-First Regulation Looks Like
The Brazil TikTok fine is a different kind of intervention from the age verification mandates we've covered across this series. It doesn't require biometric data collection from every user. It doesn't ban minors from the platform.
It identifies specific conduct — collecting children's data without a legal basis — and applies a financial penalty with a data deletion order attached.
That's the approach the Meta trial in California is also pursuing: hold platforms accountable for what they built and what they knew, rather than building verification infrastructure around the edges of it. The states suing Meta are arguing that liability for design decisions is a more targeted instrument than blanket age verification or platform bans.
Brazil's ANPD fine for the logged-out feed is enforcement-first regulation at the product level — targeting the specific feature that enabled the specific harm, rather than requiring new data collection infrastructure to prevent a hypothetical one.
Both approaches are imperfect. Fines are only as deterrent as the regulator's ability to impose them consistently, and $30 million is a manageable sum for a company of ByteDance's size.
But the principle that platforms making deliberate product decisions that harm children should face specific consequences for those decisions is more proportionate than the alternatives currently being deployed in most jurisdictions.
Be part of the resistance, quietly.
Get Mysterium VPN

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats in editorial pieces. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.
