The platform is accused of illegally transferring users’ personal data outside Europe, in breach of GDPR
The Irish Data Protection Commission (DPC) has hit TikTok with a staggering €530 million fine, ranking it as the third-largest sanction ever issued under the General Data Protection Regulation (GDPR). Only Amazon (€746 million) and Meta-Facebook (€1.2 billion) have received higher penalties.
At the core of the issue is the unauthorized transfer of EU users’ personal data to China, where parent company ByteDance is headquartered. The DPC determined that TikTok failed to comply with privacy obligations, exposing European data to significant risks.
Under the GDPR, any non-EU company with its European base in a member state is subject to that country’s data authority. In TikTok’s case, its European headquarters in Ireland makes the DPC responsible for investigations and enforcement.
The fine follows a lengthy investigation, which found that TikTok did not offer sufficient safeguards to protect data transferred outside the EU, putting users’ rights at risk.
TikTok strongly disagrees with the DPC’s decision and has announced plans to file an appeal. The platform argues that it has already updated its data practices to comply with European standards and called the fine disproportionate.
Regardless of the outcome, the case sends a powerful message to big tech companies: if you operate in Europe, you must respect data protection laws — no matter where your servers are.
The General Data Protection Regulation (GDPR) restricts the transfer of personal data to countries outside the European Economic Area (EEA) unless those countries ensure an adequate level of data protection. In the absence of an adequacy decision by the European Commission, transfers can still occur if specific safeguards are in place, such as:
In the TikTok case, the Irish Data Protection Commission found that the company transferred European users’ data to China without sufficient safeguards, breaching Articles 44 to 49 of the GDPR. Since China is not covered by an EU adequacy decision, companies transferring data there must take extra precautions.
This record-high fine underscores how European data protection authorities are ramping up GDPR enforcement, particularly in cases involving:
To remain compliant, companies should:
We will send you periodical important communications and news about the digital world. You can unsubscribe at any time by clicking the appropriate link at the bottom of the newsletter.
The ChatGPT Agent Mode is one of the most exciting innovations introduced by OpenAI. It’s not just…
With AI Max, artificial intelligence personalizes Google Search ads by focusing on user intent rather…
The other day, my eight-year-old son looked at me seriously and said, “When I grow…
Google tests a new experiment that reorganizes search results with AI to help you find…
Between broken promises, manipulative ads and increasingly disillusioned consumers: is ethics in marketing still possible, or just…
How digital marketing is changing with artificial intelligence: insights from Google’s GTM team on Search,…