Cyber Security

TikTok fined €530 M over unlawful data transfers to China

0

The Irish Data Protection Commission (DPC) has imposed a hefty €530 million (approximately $601 million) fine on TikTok for unlawfully transferring the personal data of users in the European Economic Area (EEA) to China, breaching the European Union’s General Data Protection Regulation (GDPR).

The total fine includes €485 million for violating Article 46(1) of the GDPR, which requires that personal data transferred outside the EU be afforded an equivalent level of protection. An additional €45 million was levied for breaching Article 13(1)(f), concerning transparency obligations.

TikTok has been given six months to bring its data processing practices into full compliance. If it fails to do so, the DPC has stated it will suspend all data transfers to China. Officials emphasized that the concern isn’t just about server location but also the risk of access by Chinese authorities under domestic laws related to national security—laws that diverge significantly from EU standards.

“TikTok’s data transfers to China breached GDPR because the company did not verify, ensure, or demonstrate that European users’ data—remotely accessed by staff in China—received protections equivalent to those required in the EU,” said Deputy Commissioner Graham Doyle.

Doyle added that TikTok failed to conduct necessary risk assessments and did not sufficiently address the possibility of Chinese government access under laws related to anti-terrorism and counter-espionage—regulations TikTok itself acknowledged as conflicting with EU protections.

Although TikTok previously stated that no EEA user data was stored on servers in China, the company disclosed in April 2025 that it had discovered in February that some data had, in fact, been stored there. TikTok said the data has since been deleted, but the DPC is now evaluating whether additional regulatory actions are needed.

TikTok Plans to Appeal

Christine Grahn, TikTok’s Head of Public Policy & Government Relations for Europe, confirmed that the company will appeal the decision, arguing that it does not account for the recent implementation of Project Clover—TikTok’s new data security framework.

“Through Project Clover, TikTok has adopted advanced privacy-enhancing technologies, including encryption-on-access and differential privacy, to ensure any data accessed by staff in China is de-identified,” Grahn explained. She also noted that independent cybersecurity firm NCC Group has verified the effectiveness of these measures.

This fine ranks as the third-largest penalty ever issued by the DPC, following sanctions against Amazon (€746 million) for its advertising practices and Meta/Facebook (€1.2 billion) for data transfers to the U.S.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Hertz Data Breach: Driver’s Licenses and Financial Details at Risk

Previous article

U.S. indicts Black Kingdom Ransomware Operator for Microsoft Exchange Attacks

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *