Question of the Day
One question per day to look beyond the headlines.
Why does Brazil’s TikTok minors penalty pair a data-deletion deadline with a mandated compliance plan?
Take-away Regulators pair deletion with a compliance plan because purging illegal data stops the harm now, while process controls (defaults, age gates) prevent re-collection.
Brazil’s data regulator imposed a fine on ByteDance due to the improper collection and processing of minors' data on TikTok, with insufficient safeguards or legal basis [1], [3]. As part of enforcing data protection, the regulator ordered the deletion of unlawfully collected data within a set timeframe and required ByteDance to develop a compliance plan aimed at enhancing youth protection through measures like stricter privacy settings for under-16 accounts [2], [4]. This dual requirement ensures immediate cessation of past data privacy violations and mandates the implementation of systems and policies to prevent such infractions in the future [2], [4].
- Brazil fines TikTok $30m for child data privacy violations ranked.news (opens in new tab)
- Brazil fined TikTok over data from users who never logged in - Briefly briefly.co (opens in new tab)
- Brazil fines TikTok $30m for child data privacy violations | Internet News | Al Jazeera aljazeera.com (opens in new tab)
- Unlawful data processing: Multi-million fine for TikTok in Brazil | heise online heise.de (opens in new tab)