TikTok, fined 530 million euros for transferring personal data from Europe to China

TikTok has expressed its rejection, explaining that this decision "represents a severe blow to the competitiveness of the European Union."
May 5, 2025

The Irish Data Protection Commission (DPC) has announced a million-dollar fine against TikTok for transferring personal data of users from the European Economic Area to China without the appropriate safeguards. This regulator, which acts as the main control authority in the digital domain within the European Union, concluded that the company significantly violated the General Data Protection Regulation (GDPR) by allowing remote access to European users’ personal data from China, without verifying that these data were protected with a level equivalent to that guaranteed by the GDPR.

According to a spokesperson from the Commission, Graham Doyle, “The GDPR requires that the high level of protection offered in the European Union be maintained when personal data is transferred to other countries. TikTok’s personal data transfers to China breached the GDPR because TikTok did not verify, guarantee, or demonstrate that the personal data of EEA users, accessed remotely by its personnel in China, had an essentially equivalent level of protection to that guaranteed in the EU.

As a consequence of TikTok not performing the necessary assessments, it did not address the potential access of Chinese authorities to personal data of the EEA under Chinese anti-terrorism, counter-espionage, and other laws that TikTok identified as substantially different from EU norms.”

Lack of informational transparency

The second infringement point relates to the lack of transparency towards European users. TikTok’s 2021 Privacy Policy did not name the data recipient countries, such as China, nor specify that personnel from that country had remote access to data stored on servers in the U.S. and Singapore.

Although TikTok updated its policy in December 2022 to include these details, the DPC considered that during the period from July 29, 2020, to December 1, 2022, the company failed to comply with its transparency obligations, which is why it has been fined an additional $49.5 million.

According to the commission, during the process, TikTok explained that it did not store data from EEA users on Chinese servers. However, in April 2025, the company reported an internal incident for which some data was indeed stored in China, contradicting the information provided during the investigation. Although TikTok claims that these data have already been deleted, the DPC is evaluating possible additional actions regarding this matter.

TikTok’s response

In response to this ruling, the Chinese company quickly issued a strong response statement, expressing its rejection of the decision. TikTok argues that the decision is based on past practices, before the implementation of its 2023 Clover Project, a €12 billion initiative designed to reinforce the security of European users’ data. TikTok states that it has never received nor provided data to Chinese authorities and that the remote access is limited and supervised by the European cybersecurity firm NCC Group.

Through Clover, the data of European TikTok users is stored by default in a specific European data enclave, hosted in data centers in Norway, Ireland, and the United States.

The company criticizes the DPC for not adequately considering these measures, which include default European storage, privacy-enhancing technologies, and 24/7 independent control. TikTok asserts that it followed the same legal frameworks as other multinationals (such as standard contractual clauses) and describes the decision as a detrimental precedent for companies operating globally from the EU:

“This decision risks setting a precedent with far-reaching consequences for companies and entire industries across Europe that operate on a global scale. It represents a severe blow to the competitiveness of the European Union.”

Therefore, TikTok will appeal the sanction and urges the EU to support solutions like Clover, which allow for privacy protection without blocking the global flow of data and innovation.

A new fine for big tech companies

Of course, this is neither the first (nor will it be the last) of the large multimillion-dollar fines that the European Union, through its various regulatory bodies, imposes on big tech companies. Whether for breaching GDPR provisions, the DSA, or the DMA, European authorities have embarked on numerous legal battles in recent years, seeking to ensure the protection of their consumers.

For instance, the same Irish Data Protection Commission that just fined TikTok, imposed in 2024 a sanction of $100.1 million on Meta for having compromised the security of several users by storing their passwords without cryptographic or encryption protection. Furthermore, in December 2024, it imposed a new fine on the company of Mark Zuckerberg worth $251 million, after concluding that it had violated data protection regulations, compromising the security of its users.

Regarding the GDPR, in 2024, the European Commission fined LinkedIn $341 million after determining that the social network, owned by Microsoft, had not appropriately processed data for behavior analysis and targeted advertising. Finally, this year we have learned that Apple will have to pay $500 million and Meta $200 million, following a historic decision by the European Commission for violating provisions of the Digital Markets Act (DMA).

Image: Flux Schnell

Other articles related to

Published by

Content manager in Marketing4eCommerce

Stay up to date!

Únete a nuestro canal de Telegram

All you need to know!

Sign up for our newsletter and receive our best articles on eCommerce and digital marketing in your email for free.