PrivacySignal
Enforcement

Brazil fines TikTok owner ByteDance for unlawful processing of teenagers' data

Reuters · · International · Enforcement

Brazil's data protection authority has fined ByteDance, the company behind TikTok, for illegally processing personal data belonging to teenagers. The penalty reflects regulatory action under Brazilian law governing how platforms handle minors' information.

Why this matters: Teenagers do not get to negotiate their privacy. They sign up for an app, and the platform decides what to do with their data. Brazil is saying that choice belongs to the law, not to ByteDance. This fine matters beyond Brazil because TikTok has hundreds of millions of young users worldwide, and regulators in multiple countries are watching how the company handles minors' data. If a major economy is willing to impose real penalties, other jurisdictions have cover to follow.

Who should care: Lawyers · Privacy officers · Compliance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Deep Signal · Part I of III

The Algorithm Said So

Federal rulemakers are deciding what to do when artificial intelligence produces the kind of conclusion that once required an expert. They disagree about how to regulate it. They also disagree about whether the problem has arrived.

· 10 min read Read →

Related stories

Enforcement
EDPB · · EU

Italian DPA fines BBVA EUR 5 508 000 for failing to respect a customer’s objection to direct marketing

Italy's data protection authority fined BBVA's Italian branch over 5.5 million euros after the bank continued direct marketing to a customer who had formally objected to it. The decision cites violations of GDPR principles covering data processing, transparency, the right to object, and controller accountability.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · General readers · Policy

#enforcement#gdpr#regulation#privacy Read original →
Enforcement
EDPB · · EU

Italian DPA fines security company EUR 39 000 for violations concerning employees’ data

Italy's data protection authority fined security firm La Patria S.p.A. €39,000 following an employee complaint. The violations involved failures to provide transparent privacy information and blocking workers from accessing their own personal data.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · General readers · Policy

#enforcement#gdpr#privacy Read original →
Enforcement
EDPB · · EU

Italian DPA fines IQVIA EUR 7 000 000 for unlawful processing of patients’ health data

Italy's data protection authority fined IQVIA Solutions Italy €7 million following a finding that the company processed patients' health data without a lawful basis. The decision cited violations across multiple GDPR provisions, including rules on sensitive data, transparency, data protection by design, and impact assessments.

Who should care: Lawyers · Privacy officers · Compliance · Healthcare professionals · AI governance · General readers · Policy

#enforcement#healthcare#gdpr#privacy Read original →
Enforcement
EDPB · · EU

Italian DPA fines Emirates EUR 180 000 for infringements concerning passengers’ health data

Italy's data protection authority fined Emirates €180,000 following an investigation into how the airline handled passengers' health data. The ruling cited violations of GDPR principles on lawful processing, transparent communication, and disclosure obligations at the point of data collection.

Who should care: Lawyers · Privacy officers · Compliance · Healthcare professionals · AI governance · General readers · Policy

#enforcement#healthcare#gdpr#regulation#privacy Read original →
Enforcement
The Record · · International

ASOS: Hackers tricked way into employee account before sending rogue push notification

ASOS confirmed a breach in which attackers used social engineering to access an employee account, then sent unauthorized push notifications. The incident exposed some customer personal information, including names and contact details, along with non-personal account data.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Enforcement
EDPB · · EU

Swedish DPA fines Miljödata i Karlskrona approximately EUR 160 000 for insufficient technical and organisational measures to ensure information security

Sweden's data protection authority fined IT service provider Miljödata i Karlskrona roughly EUR 160,000 after a 2025 cyberattack exposed personal data belonging to 2.2 million individuals, with the stolen data later published on the darknet. The fine was issued under Article 32 of the GDPR for inadequate technical and organisational security measures.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · General readers · Policy

#enforcement#gdpr#privacy Read original →