On 25 August 2026, Brazil's Official Gazette published the R$ 153.7 million fine that the ANPD, the country's data protection authority, imposed on ByteDance, owner of TikTok, for processing children's and teenagers' data without an adequate legal basis.
It is easy to read this as big-company news and move on. But the five violations the authority lists describe, almost point by point, what a small company does without thinking in the contact form on its own website. And the principle at stake is the one GDPR calls accountability.
What exactly was penalised
The decision cites articles 6 (items VIII and X) and 7 of Brazil's data protection law, and the five violations break down like this:
- Processing children's and teenagers' data without a valid legal basis in feed access without sign-up.
- Failing to adopt measures that would prevent that processing in the signed-out feed.
- Processing minors' data during account registration, again without a valid legal basis.
- Failing to adopt effective measures to prevent registration by that audience.
- Failing to demonstrate effective compliance measures, in either experience.
In the authority's own words: "the sanction applied corresponds to past conduct and to data processing carried out without a valid legal basis during the period analysed". The company has 10 business days to appeal, plus a deadline to delete the data and present a compliance plan.
Read the list again: two violations are about failing to prove
This is the part almost everyone skips. Of the five, two do not describe a wrong action — they describe an absence: not adopting the measure, and not being able to demonstrate that it was adopted.
Article 6, item X, calls this accountability — the same principle as article 5(2) of the GDPR. In practice it means being compliant is not enough: you have to be able to prove it. If your company does everything right and records none of it, from an audit's point of view the result looks a lot like not having done it.
It is the difference between "we don't sell customer data" and "here is the policy, the date it went live, who has access to the database, and how long we keep each item".
The other case, which almost nobody separated properly
Four days earlier, on 21 August, the ANPD notified 22 platforms and AI tools, giving them 10 business days to respond. The second group includes names your company probably uses: App Store, Google Play, ChatGPT, Claude, Gemini, Copilot, Meta AI, DeepSeek and Perplexity.
⚠️ The two are worth separating, because the press merged them: the TikTok fine is a data protection case; the notice to the 22 rests on Brazil's internet civil framework and its digital child statute, targeting criminal content and the protection of children, teenagers and women. It is not "the regulator auditing how companies use AI".
What the two cases say together is simpler: the Brazilian regulator has started acting, and the AI tools that entered companies' daily routine entered its field of view at the same time.
Your site collects data and you don't know whether it complies?
We audit what the site actually does before writing any policy.
The mistake I found on our own site
In August we rewrote this site's privacy policy. Before writing, we did what almost nobody does: audit what the site actually executes — which scripts load, which cookies get written, what goes where.
The result was embarrassing and useful. The old policy claimed we used analytics cookies. We did not. The site has no Google Analytics, no tag manager, no social pixel, no heatmap. The only cookies are one holding a menu state and the panel's session cookie. The only third party setting a cookie is the embedded YouTube video, and only if someone presses play.
In other words: we were declaring a collection that did not exist. Nobody was harmed, but the principle it breaks is exactly the one in article 6 — the policy did not describe reality. Had the inconsistency run the other way, that is the fine scenario.
📌 The lesson: a privacy policy is not copied from a template, it is written after looking at what the system does. Generic text usually lists things the company does not do and omits the one it does.
Five questions to answer today
1. What is the legal basis for each piece of data you collect? For every field in the form, one answer: consent, contract performance, legitimate interest, legal obligation. "Because we've always asked for it" is not a legal basis — and that is precisely what the authority called processing without a valid basis.
2. Do you collect any data you don't use? A phone number nobody calls, a tax ID that appears on no invoice, a birth date that serves no purpose. Every extra field is risk with no upside. The fastest way to reduce exposure is to delete fields from the form.
3. Can you prove what you claim? The date the policy went live, who has access to the database, how long each type of data is kept, what was done when someone asked for deletion. With no record, your answer to an audit is just your word.
4. Can a minor reach you? If your product touches teenagers — a school, a course, a game, a toy shop — that is the ground the regulator is looking at first, in both cases.
5. Where does the data go when you use AI? Pasting your customer list into a free chat means transferring third-party data outside the company. Responsibility towards the data subject remains yours. Before connecting any tool to what belongs to the customer, use the scale we wrote about in before you connect AI to your inbox.
What this text is not
It is not legal advice, and the distinction matters. We are a technology agency: we know how to audit what a site executes, organise what it collects and write a policy that describes reality. The legal reading of your case belongs to a lawyer, and for a company handling sensitive data or large volumes that reading is not optional.
It is also not a reason to panic. The fine landed on a global platform, for mass conduct involving minors. Nothing suggests a hunt for small businesses. What changed is the cost of having nothing organised, which is no longer zero.
The honest summary
Brazil's data law has existed since 2018 and became a footnote joke: a cookie bar nobody reads, copied from a competitor who copied it from someone else.
The 25 August decision shows the real standard, and it is simpler than the jargon suggests: have a legal reason for every piece of data, collect only what you use, and be able to show both. Whoever has that written down and dated gets through any audit with administrative work. Whoever only has the cookie bar gets through it rewriting everything in a hurry.
Sources
- ANPD — "ANPD multa TikTok em R$ 153,7 milhões por falhas na proteção de dados de crianças e adolescentes" (25 August 2026).
- ANPD — notice to 22 digital platforms and AI tools (21 August 2026).
- Law nº 13.709/2018 (LGPD), articles 6 and 7.
Frequently asked questions
Why did Brazil's regulator fine TikTok R$ 153.7 million?
For five violations related to processing children's and teenagers' data without a valid legal basis, both in feed access without sign-up and in account creation. The decision cites articles 6, items VIII and X, and 7 of Brazil's data protection law, and was published in the Official Gazette on 25 August 2026.
Does the TikTok fine affect small companies?
Not directly: the sanction targeted a global platform for mass conduct involving minors. What affects any company is the standard used. Two of the five violations do not describe a wrong action but absences: failing to adopt effective measures and failing to demonstrate that they were adopted.
What is a legal basis in practice?
It is the legal reason that allows you to process that data: consent, contract performance, legal obligation, legitimate interest. For every field your form collects there must be one of those answers. “Because we've always asked for it” is not a legal basis.
Is the regulator auditing how companies use AI?
That is not what happened. On 21 August 2026 the ANPD notified 22 platforms and AI tools, including ChatGPT, Claude, Gemini and Copilot, but on the basis of Brazil's internet civil framework and digital child statute, looking at criminal content and the protection of children, teenagers and women. The TikTok fine is a separate data protection case.
What do I need on record to prove compliance?
The legal basis for each piece of data collected, the date the policy went live, who has access to the database, the retention period for each type of information, and a record of what was done when someone requested deletion. Article 6, item X, calls this accountability: with no record, your answer to an audit is just your word.
Can I use a privacy policy template?
That is the most common mistake. A generic template usually declares practices the company does not have and omits the ones it does. When rewriting this site's policy we found that the previous text claimed to use analytics cookies that never existed here. A policy is written after auditing what the site actually executes.


