Ireland’s Data Protection Commission (DPC) has imposed a €530 million ($601 million) fine on TikTok for violating European data protection regulations by transferring user data to China.
“TikTok infringed the GDPR regarding its transfers of EEA [European Economic Area] User Data to China and its transparency requirements,” the DPC stated. The ruling requires TikTok to bring its processing into compliance and suspend all data transfers to China within six months.
The penalty stems from an investigation launched in September 2021 that examined TikTok’s data transfer practices and compliance with EU regulations regarding third-country data transfers.
DPC Deputy Commissioner Graham Doyle explained that TikTok violated Article 46(1) of GDPR by failing to ensure equivalent privacy protections for European users’ data when transferred to China. The company also did not adequately address concerns about potential access by Chinese authorities under local anti-terrorism and counter-espionage laws that significantly differ from EU standards.
Further complicating matters, TikTok initially claimed it did not store European user data on Chinese servers, only to later reveal that “limited EEA data” had indeed been stored in China due to a system issue discovered in February 2025. The DPC is now considering additional regulatory action regarding this discrepancy.
TikTok’s head of public policy for Europe, Christine Grahn, contested the decision, arguing it fails to acknowledge the company’s “Project Clover” data security initiative designed to protect European user data. Grahn emphasized that TikTok “has never received a request for European user data from the Chinese authorities, and has never provided European user data to them.”
This marks TikTok’s second major GDPR fine, following a €345 million penalty in September 2023 for violations related to children’s data handling.
