Site icon Araújo e Policastro Advogados

ANPD imposes the largest fine in its history: what changes for those who process children’s and adolescents’ data

The National Data Protection Authority was established in 2018 by Provisional Measure No. 869, which was converted into Law No. 13,853 in July 2019. The LGPD took effect in September 2020, but administrative sanctions did not take effect until August 1, 2021.

After just over five years of enforcement activity, the Agency imposed, on August 25, 2026, the largest monetary fine in its history: R$ 153,769,671.33, imposed on a widely known, large-scale digital platform for failures in the processing of children’s and adolescents’ personal data.

Until then, the only monetary fine ever imposed on the private sector had been R$ 14,400.00, relating to a case from 2023. The new amount represents a jump of more than ten thousand times and confirms that the Agency’s purely advisory phase is now definitively behind it.

What the decision ruled

The administrative enforcement proceeding was initiated in November 2024 and examined the processing of data from underage users through two methods of accessing the platform: one that did not require registration and another linked to a registered profile. In both cases, the investigation concluded that there was no valid legal basis for the processing of this data, among a total of five violations identified.

The fine was divided into three installments, imposed collectively for violations of different provisions of the LGPD, which caused the total amount to exceed the R$50 million cap set for each individual violation. In addition to the monetary penalty, the company must delete the data of adolescents whose registration does not have proper legal representation, notify third parties who received this data so that they may also delete it, and provide technical proof of compliance with these measures. An appeal may still be filed with the Agency’s Board of Directors.

LEGAL BASISVALUEREASON
Article 7 of the LGPDR$ 63,176,686.67Data processing without a valid legal basis
Article 6, subparagraph VIIIR$ 63,176,686.67Lack of preventive measures
Article 6, subparagraph XR$ 27,416,297.99Lack of proof of compliance

The Leap in Numbers

The chart below compares the first monetary fine ever imposed on the private sector, the statutory cap for a single violation, and the total amount of the most recent penalty. The difference in scale is the main message of the decision for companies that still view the LGPD as a distant risk.

Three points to keep in mind

1. From the purely advisory phase to cumulative fines

Prior to the most recent fine, the Agency’s enforcement activities focused primarily on public agencies, against which the law prohibits the imposition of monetary fines. In such cases, non-monetary sanctions were imposed, such as warnings, orders to correct violations, and public disclosure of the infractions—typically for failures such as delayed reporting of security incidents, failure to submit a data protection impact assessment, and noncompliance with requests made during inspections. These were signs that the Agency had already been testing its enforcement tools, even without direct financial repercussions.

When the same conduct violates more than one provision of the LGPD, the ANPD may impose a penalty for each violation, and the R$50 million cap applies per violation, not to the entire proceeding. It was this mechanism that caused the total amount, in the most recent case, to exceed R$ 150 million.

It is also worth noting that the simple fine coexists with another mechanism—the daily fine—which is used to enforce compliance with a specific order until the violation is corrected. It is a separate amount, charged only in the event of noncompliance, which can continuously increase the financial risk.

2. Why Data on Children and Adolescents Requires Extra Care

From its inception, the LGPD has provided for a special regime for this group. Article 14 establishes that the processing of data pertaining to children and adolescents must always be in their best interest, in accordance with the age groups defined in the Statute of the Child and Adolescent: children are defined as persons under 12 years of age, and adolescents as those between 12 and 18 years of age. For the processing of children’s data, paragraph 1 of the same article requires specific and prominently displayed consent from at least one parent or legal guardian, making this provision one of the strictest in the entire law.

This framework gained a second layer with the Digital Statute for Children and Adolescents (Digital ECA), enacted in September 2025 and in effect since March 17, 2026. The new law does not replace the LGPD; rather, it supplements it and introduces its own obligations, such as the elimination of self-declared age, the requirement for reliable technical age-verification mechanisms, the requirement that accounts for minors under 16 be linked to a legal guardian, with tools to monitor usage time, spending, and contacts, and semiannual reports for platforms with more than one million users. Failure to comply with these specific obligations may result in a fine of up to R$ 10.00 per registered user, also capped at R$ 50 million per violation, pursuant to subsection II of Article 35 of the Digital ECA, and thus under a penalty regime distinct from that provided for in the LGPD.

The ANPD enforces both laws simultaneously, which means that a single investigation involving minors’ data could result in cumulative penalties under both laws. Companies with products, apps, or services accessed by this demographic can no longer treat this issue as a footnote in their privacy policy.

3. The fine is only part of the cost

In addition to the monetary penalty, the deletion of data, and notification to third parties who received such data, the decision mandated public disclosure of the violation and the possibility of an independent external audit if the documentation submitted is deemed insufficient. Each of these measures has its own implementation and monitoring costs, which are not typically factored into a company’s assessment of regulatory risk.

There is also a civil action, which proceeds in parallel with and independently of the administrative proceeding. Article 42 of the LGPD provides that the data controller is liable for pecuniary and non-pecuniary damages caused to the data subject as a result of processing that violates the law, which may give rise to individual and class-action lawsuits, including claims for non-pecuniary damages. The Public Prosecutor’s Office and consumer protection agencies may also take action on the same case, based on their own grounds and with sanctions that are in addition to—not in lieu of—the ANPD’s actions.

Finally, there is the reputational cost, which is difficult to quantify but very real. The very act of publicizing the violation is intended to bring the case to the public’s attention, which tends to undermine the trust of users, business partners, and investors long after the administrative sanction has expired.

Key Considerations for Businesses

Given this situation, it is recommended that companies:

should verify whether the processing of data pertaining to children and adolescents has a valid and documented legal basis, especially in digital products, apps, and social media platforms accessed by this audience;

should implement age verification mechanisms and more restrictive privacy settings for accounts held by minors, in accordance with the timeline set forth in the Digital Statute for Children and Adolescents;

update the personal data protection impact assessment whenever data from vulnerable groups is processed;

review contracts with suppliers and partners who also process this data, ensuring that deletion and portability are technically feasible;

develop an incident response and regulatory compliance plan, thereby reducing the risk of aggravating factors in the calculation of any potential fine.

The Data Protection Team at the law firm Araújo e Policastro Advogados is available to answer any questions.

Authors:

Ana Lúcia Pinke Ribeiro de Paiva – apinke@araujopolicastro.com.br

Marcos Rafael Carneiro – mcarneiro@araujopolicastro.com.br

Exit mobile version