Don’t do SECURITY. Do business SECURELY.

TikTok fined EUR 530m over transfers of European user data to China

Ireland's Data Protection Commission fines TikTok EUR 530 million over transfers of EEA users' data to China and a lack of transparency.

Ireland’s Data Protection Commission (DPC) fined TikTok EUR 530 million after finding that its transfers of European users’ personal data to China, including remote access by staff there, breached the GDPR.

What happened

  • The DPC found that TikTok had failed to verify, guarantee, and demonstrate that data accessed from China received protection essentially equivalent to that in the EU, and fined it EUR 485 million for this.
  • A further EUR 45 million was imposed because TikTok’s 2021 privacy notice had not named China or explained the remote access.
  • TikTok was ordered to bring its processing into compliance within six months, or have transfers to China suspended.
  • TikTok said it disagreed with the decision and would appeal, and the DPC said it was considering further action after TikTok revealed that some EEA data had in fact been stored on servers in China.

Why it mattered

It was one of the largest GDPR fines to date and put international transfer assessments under the spotlight. It confirmed that remote access from another country counts as a transfer, even when the data is stored in Europe.

Lessons for organisations

Map where personal data is stored and accessed from, including remote support by overseas staff or suppliers. Transfer risk assessments should be completed and kept up to date, not treated as a one-off exercise.

Sources: Data Protection Commission, The Record

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights