ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

TikTok faces fresh EU scrutiny over data transfers to China

The Irish Data Protection Commission (DPC) has launched a new investigation into TikTok over concerns that the company may have transferred European users’ personal data to servers in China, in potential violation of the General Data Protection Regulation (GDPR).


The move follows an earlier decision by the DPC on April 30, 2025, in which TikTok was fined €530 million for failing to demonstrate that personal data belonging to users in the European Economic Area received protections equivalent to those required by EU law. That inquiry also found that some European users’ data had been remotely accessed by TikTok employees based in China, a practice that triggered widespread regulatory concern.


The latest probe will examine whether TikTok, owned by Chinese tech giant ByteDance, complied with transparency and data transfer obligations under the GDPR. Specifically, the DPC will assess the legality of TikTok’s data transfers to third countries and whether the company provided accurate and complete information regarding where and how user data was processed.


TikTok previously maintained that no data from European users was stored on servers in China. However, the company later acknowledged that some user information had, in fact, been stored there. The DPC said TikTok may have submitted inaccurate or misleading information during its earlier inquiry and is now “considering what further regulatory action may be warranted,” in coordination with its counterparts in other EU member states.


The Irish regulator, which leads privacy oversight for many major tech platforms operating in the EU, underscored the importance of transparency in cross-border data transfers and accountability under the GDPR. Under the regulation, companies are required to be clear about the locations where personal data is stored and must cooperate fully with regulatory investigations.


TikTok has appealed the previous €530 million fine, claiming that the decision related to historical practices that have since been discontinued. The company cited “Project Clover”, a €12 billion initiative to construct multiple data centers across the EU, as evidence of its commitment to localizing user data and enhancing compliance with European privacy standards.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543