
The Irish Data Protection Commission (DPC) has launched a new investigation into TikTok over concerns that the company may have transferred European users’ personal data to servers in China, in potential violation of the General Data Protection Regulation (GDPR).
The move follows an earlier decision by the DPC on April 30, 2025, in which TikTok was fined €530 million for failing to demonstrate that personal data belonging to users in the European Economic Area received protections equivalent to those required by EU law. That inquiry also found that some European users’ data had been remotely accessed by TikTok employees based in China, a practice that triggered widespread regulatory concern.
The latest probe will examine whether TikTok, owned by Chinese tech giant ByteDance, complied with transparency and data transfer obligations under the GDPR. Specifically, the DPC will assess the legality of TikTok’s data transfers to third countries and whether the company provided accurate and complete information regarding where and how user data was processed.
TikTok previously maintained that no data from European users was stored on servers in China. However, the company later acknowledged that some user information had, in fact, been stored there. The DPC said TikTok may have submitted inaccurate or misleading information during its earlier inquiry and is now “considering what further regulatory action may be warranted,” in coordination with its counterparts in other EU member states.
The Irish regulator, which leads privacy oversight for many major tech platforms operating in the EU, underscored the importance of transparency in cross-border data transfers and accountability under the GDPR. Under the regulation, companies are required to be clear about the locations where personal data is stored and must cooperate fully with regulatory investigations.
TikTok has appealed the previous €530 million fine, claiming that the decision related to historical practices that have since been discontinued. The company cited “Project Clover”, a €12 billion initiative to construct multiple data centers across the EU, as evidence of its commitment to localizing user data and enhancing compliance with European privacy standards.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543