The encyclopedia · Legal & Compliance · Legal decision · 2020–2025
TikTok let staff in China access EEA user data — €530M GDPR fine
Ireland's DPC fined TikTok €530M because staff in China accessed EEA users' data — and gave six months to comply or stop the transfers.
TikTok · 2025-05-02
What happened
In May 2025 Ireland's Data Protection Commission, TikTok's lead regulator in the EU, fined the platform €530 million for infringing the GDPR over transfers of European users' personal data to China. It was one of the largest data-protection fines ever issued in the European Union.
The DPC found TikTok could not verify, guarantee or demonstrate that personal data of EEA users, remotely accessed by staff in China, was given a level of protection essentially equivalent to that guaranteed in the EU. The regulator also said TikTok did not address the potential access by Chinese authorities to EEA data under Chinese anti-terrorism, counter-espionage and other laws that diverge materially from EU standards.
The DPC ordered TikTok to bring its processing into compliance within six months and warned it would suspend transfers to China if the platform did not. It also found TikTok had given inaccurate information during the inquiry: TikTok had claimed it did not store European users' data on servers in China, then told the regulator it had discovered in February that limited EU data had in fact been stored on Chinese servers, contrary to its earlier statements.
TikTok disagreed with the decision and said it would appeal in full, pointing to Project Clover, a €12 billion data-security programme it introduced in 2023, and noting the decision focused on a period before that programme. It said the DPC itself had recorded that TikTok had never handed European user data to Chinese authorities.
Why it happened
- A platform whose parent runs its operations staff overseas cannot assume those staff are bound by the EU's data-protection rules just because the platform is subject to them.
- Claiming data is not stored somewhere without verifying where it actually lands turns a compliance assertion into a fresh, separate breach when the truth surfaces.
- The regulator's threat to suspend the transfers made the fine the cheaper half of the decision — losing access to the whole EU market was the real lever.
The lesson
A data-transfer regime is only as safe as what you verify, not assert away. If staff in a third country can reach the data, prove the destination guarantees EU-level protection — or pay the gap.
Aftermath
TikTok said it would appeal the fine in full. It continued to argue that Project Clover, its €12 billion data-security programme, already protects European user data, and that it had never received a request for — or handed over — European user data to Chinese authorities. The case was cited as a landmark on cross-border data transfers between the EU and China.
Sources
- Irish Data Protection Commission fines TikTok €530 million and orders corrective measures — Irish Data Protection Commission
- Ireland fines TikTok 530 million euros for sending EU user data to China — CNBC
spotted an error? The club wants to know.
More like this
Google stacked its ad exchange against rivals — €2.95B EU fine
Netflix fined €4.75M for not telling customers what it does with their data
Meta's 2018 breach exposed 29M accounts — a €251M fine six years later
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.