Elizabeth Finn
05th January 2026
05th January 2026
26th November 2025
21st November 2025
11th November 2025
07th November 2025
17th October 2025
16th October 2025
15th October 2025
On 30 April 2025, the Irish Data Protection Commission (the ‘DPC’) adopted a final decision in an own-volition statutory inquiry, concerning TikTok Technology Limited’s (‘TikTok’) transfers of EEA User Data to China. The inquiry was carried out in accordance with the Data Protection Act 2018 and Article 60 of the EU General Data Protection Regulation (GDPR). The DPC was competent to act as lead supervisory authority for the processing at issue, pursuant to Article 56 GDPR. Prior to its adoption, the DPC submitted a draft of its decision to the Concerned Supervisory Authorities in February 2025, as required under Article 60(3) of the GDPR. The Concerned Supervisory Authorities did not raise any objections (for the purpose of Article 60(4) GDPR) to the draft decision.
The transfers of personal data considered in the Decision consisted of TikTok’s transfers of EEA User Data to China by way of remote access to that personal data by personnel of the ByteDance group of companies in China. The Decision considered whether those transfers complied with Chapter V of the GDPR. The Decision also considered whether TikTok’s provision of information to users in relation to such transfers met TikTok’s transparency requirements as required by the GDPR.
The decision concluded that:
Having considered the infringements of the GDPR as set out above, the DPC decided to exercise the following corrective powers, in accordance with Article 58(2) GDPR:
In respect of TikTok’s infringement of Article 46(1) GDPR, a fine of €485million.
In respect of TikTok’s infringement of Article 13(1)(f) GDPR, a fine of €45million.
For more information, you can download:
06th October 2025