TikTok to Appeal €530 Million Fine Over European Data Transfers to China

The decision followed a draft ruling submitted to other EU data regulators earlier this year, none of whom raised objections.

1 min read
TikTok CEO Shou Zi Chew

TikTok has confirmed it will appeal a €530 million fine imposed by Ireland’s Data Protection Commission (DPC), following a major ruling that found the Chinese-owned video-sharing app violated European data privacy laws by transferring personal data of users in the European Economic Area (EEA) to China.

The DPC announced the fine on Friday, citing TikTok’s failure to ensure that European user data accessed by staff in China received protections equivalent to those guaranteed under the EU’s General Data Protection Regulation (GDPR). The decision also requires TikTok to bring its data processing practices into compliance within six months—or risk a suspension of data transfers to China.

The case marks one of the most significant GDPR enforcement actions to date and could have wide-ranging implications for cross-border data flows and tech regulation in the EU.

TikTok had long insisted it did not store EEA user data on servers in China. However, the company disclosed in April 2025 that it had discovered an incident in February where a limited amount of such data had in fact been stored in China—contradicting previous assurances to regulators. The DPC said it viewed this as the provision of inaccurate information during the investigation, which began in 2021.

TikTok’s Head of Public Policy and Government Relations in Europe, Christine Grahn, said the company “disagrees with the decision and plans to appeal it in full,” reiterating that TikTok has never received, nor complied with, any request for European user data from Chinese authorities.

The DPC’s ruling also found that TikTok did not sufficiently assess or address the potential access by Chinese authorities under Chinese national security laws, including those related to counterterrorism and counter-espionage, which the company itself acknowledged diverge significantly from EU privacy protections.

While TikTok has since deleted the European data that was stored in China, the DPC is evaluating whether further regulatory action is warranted in consultation with other EU data protection authorities.

The company emphasized its ongoing efforts to bolster data security through “Project Clover,” a €1.2 billion initiative launched in 2023 that includes storing European user data at three centers—two in Dublin and one in Norway—under strict oversight by UK-based cybersecurity firm NCC Group.

Despite acknowledging the steps taken under Project Clover, the DPC concluded that suspending data transfers remains “appropriate, necessary and proportionate” unless TikTok complies with GDPR Chapter V obligations within the designated timeframe.

Sri Lanka Guardian

The Sri Lanka Guardian is an online web portal founded in August 2007 by a group of concerned Sri Lankan citizens including journalists, activists, academics and retired civil servants. We are independent and non-profit. Email: editor@slguardian.org

Leave a Reply

Your email address will not be published.

Latest from Blog