Social Network

TikTok in trouble: €530 million fine for sending EU data to China

The platform is accused of illegally transferring users’ personal data outside Europe, in breach of GDPR

The third-largest GDPR fine in history

The Irish Data Protection Commission (DPC) has hit TikTok with a staggering €530 million fine, ranking it as the third-largest sanction ever issued under the General Data Protection Regulation (GDPR). Only Amazon (€746 million) and Meta-Facebook (€1.2 billion) have received higher penalties.

At the core of the issue is the unauthorized transfer of EU users’ personal data to China, where parent company ByteDance is headquartered. The DPC determined that TikTok failed to comply with privacy obligations, exposing European data to significant risks.

Why Ireland decides for all of Europe

Under the GDPR, any non-EU company with its European base in a member state is subject to that country’s data authority. In TikTok’s case, its European headquarters in Ireland makes the DPC responsible for investigations and enforcement.

The fine follows a lengthy investigation, which found that TikTok did not offer sufficient safeguards to protect data transferred outside the EU, putting users’ rights at risk.

TikTok fights back: “We’ll appeal”

TikTok strongly disagrees with the DPC’s decision and has announced plans to file an appeal. The platform argues that it has already updated its data practices to comply with European standards and called the fine disproportionate.

Regardless of the outcome, the case sends a powerful message to big tech companies: if you operate in Europe, you must respect data protection laws — no matter where your servers are.

Transferring Data Outside the EU: What the GDPR Says

The General Data Protection Regulation (GDPR) restricts the transfer of personal data to countries outside the European Economic Area (EEA) unless those countries ensure an adequate level of data protection. In the absence of an adequacy decision by the European Commission, transfers can still occur if specific safeguards are in place, such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Binding Corporate Rules (BCRs) for intra-group data transfers
  • Data Protection Impact Assessments (DPIAs) to assess and mitigate risks
  • Participation in recognized data transfer frameworks, such as the EU-U.S. Data Privacy Framework

In the TikTok case, the Irish Data Protection Commission found that the company transferred European users’ data to China without sufficient safeguards, breaching Articles 44 to 49 of the GDPR. Since China is not covered by an EU adequacy decision, companies transferring data there must take extra precautions.

Implications for Businesses

This record-high fine underscores how European data protection authorities are ramping up GDPR enforcement, particularly in cases involving:

  • Transparency in data processing
  • Protection of minors
  • Data security and localization

To remain compliant, companies should:

  1. Map international data flows and identify high-risk transfers
  2. Assess the legal basis for each transfer and apply necessary safeguards
  3. Review contracts with vendors and partners outside the EEA
  4. Implement encryption, anonymization, and privacy-by-design measures

Sign up for the newsletter. Stay updated!

We will send you periodical important communications and news about the digital world. You can unsubscribe at any time by clicking the appropriate link at the bottom of the newsletter.

Dopstart

Dopstart è il sito di Paolino Donato ma anche il suo Nickname su Internet. Dopstart è un consulente SEO. Si occupa di posizionamento nei motori di ricerca fin dal 1998. Dal 2010 ha collaborato con Google in qualità di TC per Google News italiano e Google Noticias per i Paesi di Lingua spagnola e dal 2018 come Product Expert vedi curriculum

Share
Published by
Dopstart

Recent Posts

Digital usability and websites

Designing for usability means designing for people. Whether you're creating an e-commerce platform or a municipal website,…

11 hours ago

User Experience: the key to digital design

User Experience (UX) is one of the most crucial concepts in the modern digital world. Often…

2 days ago

DolphinGemma: Google’s AI could let us talk to dolphins

An interspecies communication breakthrough: Google develops an AI to decode dolphin vocalizations A voice from…

2 weeks ago

Add PHP Code to WordPress

Adding PHP code to WordPress pages can unlock advanced customization, integrate third-party tools, or display dynamic content.…

2 weeks ago

Disable AdSense on WordPress Pages

While Google AdSense is a widely used tool for monetizing websites, there are times when…

2 weeks ago

Competitor analysis in digital marketing

Understanding your rivals is key. This article explores the importance of competitor analysis in digital…

3 weeks ago