On 25 August 2026, Brazil’s data protection authority fined TikTok’s owner, ByteDance, nearly US$30 million — a stark reminder of what data protection failures cost companies operating globally. This was not a vague procedural penalty: the regulator found that TikTok collected and processed the personal data of children and teenagers without a valid legal basis or adequate safeguards, across both logged-in accounts and guest browsing sessions.
The regulator estimated data from at least 8 million children was processed, and singled out the “logged-out feed” — available in Brazil but not in the US or Europe — for letting minors use the platform while bypassing age verification. TikTok was ordered to erase the unlawfully obtained data and build a comprehensive youth-protection framework.
For businesses, the implications are far-reaching. Children’s data is where regulators worldwide are most willing to act, and the standards converge: under the EU and UK GDPR, processing a child’s data demands a lawful basis that actually holds, age checks that actually work, and safeguards that are designed in rather than bolted on. A control that exists in one market but is switched off in another — as Brazil found with the logged-out feed — is precisely the kind of inconsistency an investigation surfaces first.
The case also illustrates the financial and reputational stakes. A penalty of this size affects the bottom line, but the lasting damage is to trust — and in a market where consumer trust is the product, businesses cannot afford to treat data protection obligations as optional overhead.
To mitigate these risks, companies should audit their data processing activities regularly, be transparent about what is collected and why, and put strong security measures around personal data — with special care wherever minors can reach the service, intentionally or not. Age-verification mechanisms deserve the same engineering seriousness as payment flows.
Accountability and governance matter just as much. Organisations need clear ownership of data protection, staff who know the rules that apply to their work, and — for businesses operating across multiple jurisdictions — someone whose job it is to keep the whole picture honest. That may mean appointing a data protection officer, or a local representative in the jurisdictions that require one.
The TikTok fine is a wake-up call worth hearing before a regulator makes the appointment for you. If you are unsure where your organisation stands, our Article 37 readiness review checks whether you need a DPO and whether your arrangements would stand up to examination — and our EU and UK representative services cover the local-contact obligations for businesses outside those markets.
Source: Al Jazeera — Brazil fines TikTok $30m for child data privacy violations (25 August 2026).

