Chinese Companies Overseas Compliance Alert: Brazil’s Hard Line on TikTok Highlights Cross-Border Children’s Data Risks

I. Background

Brazil’s data protection authority, the ANPD, announced on August 25 that it was fining ByteDance, the owner of TikTok, 153.7 million reais, close to thirty million dollars, over how the platform handled the personal data of children and adolescents.

It is the first time the regulator has sanctioned a major global technology platform for violating Brazil’s data protection law, and it lands at a moment when Brazilian authorities across the board, from data protection regulators to the Supreme Court, have been moving aggressively to police how digital platforms treat young users. For a company whose growth in Latin America has been a genuine bright spot, the fine is a reminder that success in Brazil now comes with real regulatory weight attached.

TikTok has built a large and loyal audience in Brazil in a short span of years, the kind of scale that makes the country attractive to any consumer platform looking for growth outside its home market, and exactly why a fine calibrated to local revenue carries real financial weight rather than symbolic sting. The case is worth understanding in full, both for what it says about how the ANPD builds a file and for what it signals to any company, Chinese or otherwise, that treats Brazil as a serious long term market.

The investigation traces back to 2021, when a report by Vice Italy showed that TikTok was collecting substantial user data even from people who never created an account. Brazilian regulators pulled that thread for years, and the findings were eventually laid out in ANPD Technical Note number 50 of 2024.

What investigators found was that TikTok processed personal data belonging to children and adolescents without a valid legal basis in both of its access modes, the standard registered account and the logged out feed that lets anyone browse without signing up, and that the company could not demonstrate it had adequate safeguards in place to prevent that from happening.

TikTok itself told regulators that it removed 7.75 million child accounts in Brazil between October 2022 and September 2023, and the ANPD calculated that around one in five Brazilian children had their data improperly collected at some point. The fine was issued under Brazil’s general data protection law, the LGPD, together with the newer ECA Digital, a statute purpose built to protect children and adolescents online that took effect in March 2026.

Regulators identified five separate violations spanning those two access modes, registered and logged out, treating the failure to establish a valid legal basis and the failure to build adequate preventive safeguards as distinct problems rather than one combined issue. An ANPD director framed the years long process as having already produced results, saying the regulatory action had led to concrete changes in the design of the service.

TikTok, for its part, said child safety was an absolute priority and argued that the fine did not reflect the actions already laid out in its own compliance plan.

II. The Compliance Checklist

The fine came bundled with a detailed compliance plan rather than just a bill. TikTok must delete personal data that was collected unlawfully, switch privacy settings for users under 16 to restrictive by default, require parental authorization before those settings can be loosened, strengthen parental supervision tools and expand its content filters for younger users. The logged out, unregistered mode gets the sharpest restrictions.

Read together, the list amounts to a rebuild of how anonymous access works on the platform inside one country, not a fine that can be paid and forgotten. A twelve hour cap on logged out sessions, a full stop on advertising to unregistered Brazilian users and a ban on posting, commenting or messaging without an account are product level changes that touch engineering, advertising operations and legal all at once, which is presumably why the ANPD packaged them as a compliance plan with a timeline rather than a one line order.

It would be easy to read this as a Chinese platform being singled out, and the timeline argues against that reading. Earlier in August, before the TikTok fine was even announced, the ANPD ordered Discord, a platform with no Chinese ownership at all, to suspend certain live streaming features after regulators found its safety systems had failed to properly flag a serious risk to a young user.

The two cases are different in kind, one about a specific safety failure and one about systemic data handling, but together they show a regulator, and a broader Brazilian government under President Lula together with an assertive Supreme Court, treating the online safety of minors as a live enforcement priority across every major platform operating in the country, regardless of where that platform is headquartered.

Brazil is hardly alone in this. Australia, Canada and Indonesia have all been moving on similar ground recently, and companies operating across these markets are increasingly facing the same basic question wherever they go, whether their product was actually built with a young audience in mind or simply defaults to treating every user as an adult until proven otherwise.

What stands out about the Brazilian approach specifically is how procedural it is. Rather than reaching for a headline grabbing gesture, the ANPD built a formal technical record over several years, gave the company a chance to respond, and paired its final penalty with a granular list of product changes rather than a vague instruction to do better.

That pattern, patient investigation followed by a detailed compliance plan, is a reasonable template for how the same regulator is likely to treat the next platform that draws its attention, Chinese owned or not.

III. A Playbook for Chinese Enterprises

For Chinese companies with any footprint in Brazil, or any ambition to build one, the case is worth studying closely rather than dismissing as a TikTok specific problem. The LGPD applies extraterritorially on fairly broad terms, reaching any company whose processing of personal data happens inside Brazil or is carried out for the purpose of offering goods or services to people located there, regardless of whether that company has a Brazilian subsidiary, local servers or even a local office.

A Chinese app with Brazilian users downloading it directly from an international app store can fall squarely inside that scope. Fines under the LGPD are calculated with reference to a company’s own revenue, which means the exposure grows precisely as a Chinese company’s business succeeds, an unusual dynamic that flips the usual assumption that smaller or newer entrants face lower risk.

In practice this means a Chinese app with a modest Brazilian user base today, one that might reasonably deprioritize local compliance spending while it is still small, is building future fine exposure that will scale automatically as it grows, with no guarantee that compliance investment will keep pace unless it is planned for deliberately rather than left until the business is large enough to attract regulatory attention on its own.

The ECA Digital layer adds obligations that go beyond what a compliance program built primarily around China’s own data protection law or Europe’s GDPR is likely to already cover, particularly default privacy settings for minors, restrictions on unregistered or anonymous access, and active age assurance rather than a simple checkbox.

The long run up to this fine, roughly three years from the original media report to a finalized technical note, is also instructive. Brazilian enforcement can take years to mature, and a complaint or investigation that appears to have gone quiet should not be assumed to have been dropped, a pattern that regulators in other emerging consumer markets Chinese platforms are entering tend to share as well.

Chinese companies operating consumer facing products anywhere outside their home market, Brazil very much included, would do well to treat several things as routine practice rather than optional extras.

That means documenting a clear legal basis for every category of data collected from users who may be minors, testing whether default settings for anyone who cannot be confirmed as an adult are genuinely restrictive rather than merely labeled that way, building an internal process that can respond within days rather than weeks given how short ANPD’s own appeal windows tend to be, and treating any public compliance plan as a binding commitment likely to be measured against future enforcement, exactly as happened here.

None of these habits are specific to Brazilian law, and companies that build them into how they launch in any new jurisdiction will generally find themselves better positioned than those that treat local compliance as an afterthought to be handled once regulators come calling.

Two access modes were treated separately in this case, and that detail carries a broader lesson. Any Chinese product that lets people browse, sample or use core features before creating an account cannot assume that the absence of a formal account somehow places it outside data protection law, since the ANPD treated the logged out experience as fully in scope and arguably as the more troubling of the two.

Companies that built their compliance programs primarily around China’s own Personal Information Protection Law or Europe’s GDPR should not assume that framework travels cleanly to Brazil. The ECA Digital in particular is a newer, more specific layer that GDPR trained legal teams may not think to check for by default, and its requirements around age assurance and default settings for minors go further in some respects than either of those better known regimes.

IV. Conclusions

ByteDance’s appeal will test how much room the ANPD’s governing board is willing to give a company that says it has already been acting on the concerns raised against it. The board could reduce the fine, uphold it in full, or adjust elements of the compliance plan, and the outcome will itself become a reference point for how the regulator treats a large platform’s own self reported remediation efforts going forward. Whatever the outcome, the broader message for platforms with a foothold in Brazil is already clear.

Regulators there are prepared to build patient, multi year cases against major platforms regardless of nationality, to calculate penalties that scale with genuine commercial success, and to pair fines with concrete product changes rather than symbolic gestures.

Companies that treat Brazilian child safety and data protection rules as a standing compliance priority, rather than something to address only after a technical note arrives, will be in a far stronger position than TikTok finds itself in today, and that lesson applies just as much to the next Chinese consumer app eyeing Brazil as it does to the platforms already operating there.

Sources

1. Brazil’s National Data Protection Authority (ANPD), “ANPD multa TikTok em R$ 153,7 milhões por falhas na proteção de dados de crianças e adolescentes,” August 25, 2026, https://www.gov.br/anpd/pt-br/assuntos/noticias/anpd-multa-tiktok-em-r-153-7-milhoes-por-falhas-na-protecao-de-dados-de-criancas-e-adolescentes

2. Tech Policy Press, “Understanding Brazil’s $29.7 Million TikTok Fine Over Children’s Data,” https://www.techpolicy.press/understanding-brazils-297-million-tiktok-fine-over-childrens-data/

3. Al Jazeera, “Brazil fines TikTok $30m for child data privacy violations,” August 25, 2026, https://www.aljazeera.com/news/2026/8/25/brazil-fines-tiktok-30m-for-child-data-privacy-violations

4. UPI, “Brazil fines TikTok $29.8 million over processing minors’ data,” August 25, 2026, https://www.upi.com/Top_News/World-News/2026/08/25/latam-brazil-tiktok-fined-children-data/7131787672622/

5. IAPP, “An overview of Brazil’s LGPD,” https://iapp.org/news/a/an-overview-of-brazils-lgpd

6. Metropoles, “Após sancionar Discord, ANPD aplica multa contra TikTok. Entenda casos,” https://www.metropoles.com/sao-paulo/discord-tiktok-anpd-entenda-casos

*Aris Xie *Aris Xie

*Aris Xie

Aris Xie is the Counsel at D’ Andrea & Partners Legal Counsel, located in Shanghai.

Contact us for a
first consultation

CONTACT US FOR A FREE CONSULTATION

This field is for validation purposes and should be left unchanged.