TikTok Fined €530 Million for Sending EU Users' Data to China
The Irish DPC fined TikTok €530 million — the second-largest GDPR penalty ever — for illegally transferring EEA users' data to China and letting staff there access it without equivalent legal protection. Here's what the ruling actually said.
The Fine The Irish Data Protection Commission (DPC) — the lead regulator for most of Big Tech's European operations — announced the €530 million fine on May 2, 2025. It breaks down as: €485 million for violating Article 46(1) of the GDPR, which requires legally recognized safeguards for transferring personal data outside the EU/EEA.
€45 million for failing to meet Article 13(1)(f) transparency obligations — specifically, giving users misleading information about where their data was stored and processed. For comparison: the previous record GDPR penalty was the €1.2 billion fine against Meta in 2023 for the same kind of unlawful US data transfers. TikTok's fine is the second largest in GDPR history. What TikTok Did Wrong The DPC's investigation found that TikTok transferred and granted remote access to the personal data of EEA users to staff in China — where the company's parent, ByteDance, is headquartered — without putting in place protections that are essentially equivalent to those guaranteed by EU law. That's the legal crux. EU law doesn't ban international data transfers outright. What it demands is that data sent outside the EU travels under an adequate protection framework — because once data leaves the EU, European enforcement stops at the border, while local law (in this case, China's national security and intelligence legal regime) can compel access without the user's knowledge or consent. The DPC also found TikTok had provided erroneous information about where data was stored during the investigation — the transparency violation that earned the separate €45 million. Why This Matters to You If you're an EU user, this ruling is the regulatory equivalent of the Google Android data-harvest settlement and the Kochava location-data enforcement in the US: proof that where your data goes is a question of law, not just policy. When a service says "your data is safe," the real question is safe from whom, and enforceable by whom? For a social platform, "where your data goes" is not abstract. It determines which governments can legally compel access to your messages, your viewing history, your location, and your contacts — the same concerns that drove the EU's earlier battles over data transfers and the FTC's strategic privacy enforcement push. What Happens Next TikTok was ordered to bring its data-processing into compliance — a process the DPC will supervise. TikTok has said it plans to appeal. Meanwhile, the fine sends a signal to every company that routes EU user data through jurisdictions with weaker protections: the era of claiming "we never transfer data" while staff abroad access it remotely is over. The Pattern The €530 million fine is part of a broader pattern: regulators are finally enforcing the destination of data, not just its collection. Whether it's Google's shared-links mishap, the Android data-harvest settlement, or TikTok's €530 million penalty, the lesson is the same — data protection law is now extraterritorial, and "we're based somewhere else" is no longer a defense. If you want to reduce your own data footprint, our guide to de-Googling and the 2026 privacy guide cover the practical steps.