Brazil's National Data Protection Authority has levied a 153.8 million reais fine on ByteDance's Brazilian subsidiary for violations of the country's General Data Protection Law. The sanction, recorded in the official gazette on Tuesday, stems from the regulator's finding that the company processed personal data belonging to teenagers aged 13 to 18 without the required legal authorization.
The agency's decision compels the company to erase personal data tied to teenagers for whom legal representation or assistance was not properly documented. ByteDance Brasil is required to complete the deletions within 60 business days. The regulator also instructed the company to notify any third parties that received the improperly processed data about the breach.
To demonstrate compliance, ByteDance must provide a technical report signed by its data protection officer and produce system audit logs showing that it fulfilled the deletion, reporting and notification requirements. That documentation must be delivered within five business days after the close of the 60-business-day remediation window.
The authority has established a coercive daily fine of 137,081.49 reais that will accrue if ByteDance fails to meet the deletion, reporting or notification obligations. In addition to this daily penalty mechanism, the regulator noted a reduction provision: the total fine can be cut by 25% if the company refrains from appealing within 10 business days and pays the penalty within 20 business days.
Regulatory scrutiny of how online platforms protect minors has heightened in Brazil. In a related recent action this month, the same authority ordered Discord to suspend livestreaming features over concerns that children and teenagers could be exposed to harmful content. That move illustrates an elevated enforcement posture toward platform safeguards for young users.
ByteDance Brasil has not provided a public response to requests for comment regarding the fine or the compliance requirements outlined by the authority.
Compliance timeline and consequences
- Delete improperly collected teen data within 60 business days.
- Inform third-party recipients of the data breach.
- Deliver a technical report and system audit logs within five business days after the 60-business-day period.
- Face a daily fine of 137,081.49 reais for missed obligations.
- Potential 25% reduction in the total fine if no appeal is filed within 10 business days and payment is made within 20 business days.
This enforcement action underscores the procedural requirements platforms must satisfy when personal data of minors is involved, and it signals continued regulatory vigilance in Brazil with practical penalties tied to both remediation and timeliness of response.