A few days ago, the National Data Protection Agency (ANPD) imposed fines totaling R$ 153.7 million on ByteDance Brasil, the operator of TikTok.

The number does not surprise those who have been following the actions of the ANPD, since in the first fine imposed on the company Telekall, in the amount of R$ 14,400, the agency made it clear that the fine would be individualized in relation to each violation of the General Data Protection Law (LGPD).

With TikTok’s decision, it is clear that the R$50 million ceiling for simple fines, which can be set at up to 2% of gross revenue, applies to each infraction committed by data controllers. Anyone familiar with the number of obligations arising from the LGPD (Brazilian General Data Protection Law) knows that we are talking about no small matter.

In the case of TikTok, the ANPD (Brazilian National Data Protection Authority) identified five independent actions related to the improper handling of children’s and adolescents’ data on the platform. In short, here is the structure of the decision:

Two actions relate to feeds without registration . Action 1 (processing data of children and adolescents without a valid legal basis) violates Article 7 of the LGPD (Brazilian General Data Protection Law) and resulted in a fine of R$ 35,760,388.68. Action 2 (failure to adopt preventive measures to prevent the processing of data of children under 13 years of age) violates Article 6, VIII (principle of prevention) and resulted in another fine of the same value.

Two other violations relate to the feed with registration . Conduct 3 (processing data of minors under 18 years of age for registration on the platform without a valid contract) again violates Article 7 and resulted in a fine of R$ 27,416,297.99. The fine was combined with the sanction of deleting the personal data of adolescents between 13 and 18 years of age whose registrations are not regularized by legal assistance or representation within 60 working days, under penalty of a daily fine of R$ 137,081.49. Conduct 4 (failure to implement effective mechanisms to prevent the registration of minors under 13 years of age) violates Article 6, VIII and generated a new fine of R$ 27,416,297.99.

Conduct 5 (failure to demonstrate effective measures capable of proving compliance with data protection regulations) violates Article 6, X (principle of accountability and transparency) and resulted in a fine of R$ 27,416,297.99. The sum of all these fines for each violated article resulted in the figure of R$ 153,769,671.33.

The mathematics corresponds to the dosimetry mechanism approved by Resolution CD/ANPD No. 4/2023, which provides for the sanctioning of each conduct . The wording of item II of article 52 of the LGPD itself left no doubt: the limit is per infraction . In the TikTok case, there were also aggravating circumstances that classified the infractions as serious because, in addition to significantly affecting fundamental rights (medium infraction criterion), they carried out large-scale processing (Dosimetry Regulation, article 8, §3, I, subparagraph “a”), with economic advantage (subparagraph “b”) and processing of data of children and adolescents (subparagraph “d”).

Decision Order No. 27/2026 consolidates the five offenses into three categories per violated provision: two of them, resulting from the sum of two offenses each, total R$ 63,176,686.67; the third, resulting from a single offense, totals R$ 27,416,297.99. This is unequivocal proof that the ceiling is determined by offense, not by article, and also a predictable appeal argument: if the limit is R$ 50 million per infraction , the defendant will only need to argue that the infraction, for the purpose of the ceiling, is per violated provision, and not each violating offense , reducing the fine to R$ 127.4 million.

Beyond the monetary value, the rationale justifying the imposition of three of the five fines is also noteworthy. The violations did not stem from rules with specific commands in the LGPD (Brazilian General Data Protection Law), but directly from two principles of Article 6 of the law: prevention and accountability. The ANPD (National Data Protection Authority) understood that these principles, more than interpretative guidelines, constitute autonomous sources of obligations that, if the controller is unaware of them, they should be aware of. Although the principle of prevention does not explicitly state which technological barrier to adopt, the agency’s decision considers that it imposes on the controller the duty to implement some effective measure before the damage occurs. Which measure and how effective it is, is something to be decided by the controller when carrying out data processing operations, subject to control by the ANPD ex post facto .

What is even more striking is what was left out: the technical note also alleged a violation of article 14, caput , and article 6, I, and none of these are included in the final decision. There was a specific rule at hand, including article 14, §5, sensitive to the state of the art, but even so, the direct application of the principle was preferred.

The principle of accountability, in line with the decision, requires the data controller to prove, with concrete and auditable records, that its practices truly protect data subjects. The agency rejected generic arguments regarding the existence of a compliance program and demanded proof of the program’s effectiveness, which had failed to protect minors. Thus, it is evident that the principle of accountability deals with the burden of proof and implies the duty to maintain adequate and auditable documentation regarding all measures and precautions adopted for the compliance of personal data processing with the LGPD (Brazilian General Data Protection Law). The requirement is concrete: a detailed report, audit records, and a declaration signed by the data protection officer, under penalty of external audit.

We need to recognize that this construction does not come without a cost to legal certainty. Legal principles, by definition, do not precisely define what should or should not be done, limiting themselves to setting an end to be pursued, or a point of arrival, without indicating exactly which paths lead to it. In the area of ​​technology, where standards of conduct change at a speed that contrasts with the pace of regulation, this openness generates a concrete problem: a company that adopts a certain available strategy today may discover tomorrow that it no longer satisfies the regulator.

The present case provides an example of age verification through self-declaration ( age gate ), which was a globally widespread practice for accessing websites and games when TikTok implemented it as a means of accessing the platform; now, the ANPD (Brazilian National Data Protection Authority) has deemed it insufficient, asserting that “the claim of adopting practices aligned with the ‘industry standard’ does not hold up as a valid justification. The legislation requires compliance with legal principles, not conformity to the average market behavior” (section 7.86 of the instruction report).
The question is not whether the agency is right — and it probably is.

The issue is that, without specific regulations on which mechanisms fulfill the duty of prevention, the controller is forced to hit a moving target, risking hefty fines of up to 2% of revenue for each infraction. This contrast between the openness of the principles and the predictability that regulation should provide seems to be the most delicate point of the decision and the one that will require the most attention from personal data processing agents in future cases.

It must be acknowledged, however, that in the case of the age gate, the target will soon cease to move, as the Digital ECA (Law No. 15.211/2025), in force since March 2026, removed self-declaration from the list of acceptable mechanisms, and the ANPD, responsible for overseeing it, has already published preliminary guidelines and a schedule for age verification. In the same edition of the Official Gazette, the Board of Directors approved ByteDance’s compliance plan, noting these deadlines. The criticism shifts from the structural to the temporal: conduct from 2021 to 2024 judged by a parameter consolidated in 2026. If the legislator deemed it necessary to grant six months of vacatio legis and the agency a staggered schedule to require reliable age verification, it is at least uncomfortable to sanction as a failure of prevention the period in which none of this existed.

The requirement for predictability is grounded in the principle of legal certainty and in the Introductory Law to the Brazilian Civil Code (LINDB), which imposes on the authority the duty to act to increase legal certainty, through instruments that bind the very body that issues them (article 30), and requires a transitional regime when the decision establishes a new interpretation of a rule with indeterminate content, imposing a new duty (article 23). Predictability is, therefore, a duty of the regulator, beyond the aspirations of the regulated entity.

The decision against TikTok is not only the largest ever issued by the ANPD (Brazilian National Data Protection Authority). It confirms a logic that was already evident in the first sanctioning process that led to the first fine imposed on Telekall: each violated provision of the LGPD (Brazilian General Data Protection Law) can generate an independent fine, and the principles of the law have the same sanctioning weight as its rules. For data controllers who still treat compliance with the LGPD as a bureaucratic formality, the message is direct: omission is not a loophole to be filled when convenient, it is a set of infractions in formation that can be costly. It is hoped, however, that the message reaches all recipients: the market, with proof that the educational phase is over; and the agency itself, with the reminder that a precedent of this magnitude demands from the author the rigor that it demands.

Ana Paula Ávila
She is a lawyer, coordinator of the Compliance area at Silveiro Advogados and vice-president of the Special Commission on Data Protection and Privacy of the OAB-RS (Brazilian Bar Association – Rio Grande do Sul chapter), holds a master’s and doctorate in Law from UFRGS (Federal University of Rio Grande do Sul), a master’s degree in Global Rule of Law from the University of Genoa (Italy), and has completed programs in Crisis Management and Cybersecurity for Executives at MIT (USA).

Martha Leal
She is a lawyer specializing in Digital Law, data protection, and artificial intelligence regulation, a certified data protection officer from Maastricht University, holds a master’s degree and is a doctoral candidate in Law from Unisinos, and is the president of the National Institute for Data Protection (INPD).

Source / related link: https://dcadvogados.com.br/o-recado-de-r-153-milhoes-da-anpd-ao-mercado/

← Back to Insights