TikTok Fined €530 Million for GDPR Breaches

TikTok logo graphic

TikTok has been fined €530 million by Ireland’s Data Protection Commission (DPC) following a significant investigation into the platform’s handling of European user data. The DPC, which serves as the lead supervisory authority for TikTok under the EU’s General Data Protection Regulation (GDPR), found the company had failed to implement adequate safeguards around the transfer of personal data to China. The investigation revealed that TikTok had not ensured that data accessed by staff in China received protection consistent with EU standards. Moreover, the platform was found to have misled regulators by initially denying that any European user data was stored or accessed in China, before later admitting that “limited” data was indeed involved.

In response to the ruling, TikTok has announced plans to appeal and pointed to the implementation of its 2023 “Project Clover” initiative as evidence of its commitment to data protection compliance. However, the DPC has ordered the company to suspend any such data transfers within six months unless it can demonstrate full compliance with GDPR requirements. The decision also criticised the platform’s historical lack of transparency, noting that its privacy policies were only updated in 2022 to reflect the possibility of data access from China. This case marks one of the largest GDPR-related fines to date and underscores the increasing regulatory scrutiny facing tech companies operating across international data boundaries.

Is your business GDPR-compliant?

While enforcement actions often target major tech platforms, small and medium-sized businesses are by no means immune. Any organisation holding data on EU citizens, regardless of size or location, must regularly review its GDPR compliance to avoid significant financial and reputational risks. Crucially, it is a legal requirement under Article 27 of the GDPR for non-EU businesses processing EU personal data to appoint an EU-based representative. If your organisation has not yet done so, it’s essential to take action. You can schedule a free consultation with EU Business Partners to understand your obligations and next steps.

James Hubbard

James Hubbard is the Content Marketing Manager for EU Business Partners and McCarthy + Co Solicitors in Ireland. James has extensive experience in delivering digital content campaigns in the legal sector. He has worked alongside Flor McCarthy and the team behind EU Business Partners for over 5 years. James has an interest in cybersecurity issues and covers stories relating to data breaches, GDPR fines and non-compliance.

0 Comments

You May Also Be Interested In