The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →On January 16, 2025, Austrian privacy organisation NOYB filed six GDPR complaints against TikTok, Xiaomi, Shein, AliExpress, Temu and WeChat. The complaints, lodged in five European countries, allege that the companies’ arrangements for transferring or accessing European users’ personal data in China or other third countries may not provide protection equivalent to that required in the EU.
These are allegations, not final regulatory findings. No complaint by itself proves that a company unlawfully transferred a particular user’s data, that Chinese authorities accessed it, or that any of the services will be banned.
The six complaints at a glance
| Company or service | Complaint country | Transfer issue described by NOYB |
|---|---|---|
| TikTok | Greece | Its privacy policy reportedly says personal data may be transferred to China. |
| Xiaomi | Greece | Its privacy policy reportedly says personal data may be transferred to China. |
| Shein | Italy | Its privacy policy reportedly says personal data may be transferred to China. |
| AliExpress | Belgium | Its privacy policy reportedly says personal data may be transferred to China. |
| Netherlands | Its policy referred to “third countries”; NOYB inferred that China could be included. | |
| Temu | Austria | Its policy referred to “third countries”; NOYB inferred that China could be included. |
NOYB said AliExpress, Shein, TikTok and Xiaomi openly acknowledged possible transfers to China. Temu and WeChat used broader third-country wording, so the China connection in those complaints was more inferential. The organisation described the action as its first GDPR campaign directed at Chinese companies. Its announcement is available at NOYB’s complaint notice.
What NOYB alleged
NOYB argued that sending European users’ data to China may fail the GDPR requirement that protection in a destination country be “essentially equivalent” to protection in the EU. It contended that companies could not reliably shield transferred data from potential access by Chinese authorities and that users have limited practical ability to challenge such access.
Recommended Free Tools
#1 Best Overall
The complaints cited Articles 44 and 46 of the GDPR, which govern transfers to countries outside the European Economic Area, and Article 58(2)(j), which allows a supervisory authority to suspend data flows to a third-country recipient. The official regulation is available at EUR-Lex.
NOYB also referred to Xiaomi transparency reports as evidence of extensive requests from Chinese authorities and frequent company compliance. That is NOYB’s argument and interpretation, not a final finding by a regulator in these cases.
Why a contract does not automatically make a China transfer lawful
A company must meet two separate requirements: it needs a lawful basis to process personal data, and it needs a valid GDPR mechanism for transferring that data outside the EEA.
- Choose a lawful basis. Processing may rely on consent, contract, legal obligation or another basis recognised by the GDPR.
- Use a transfer mechanism. If no European Commission adequacy decision applies, a company may use safeguards such as Standard Contractual Clauses (SCCs).
- Assess the destination country. The exporter must examine local law and practice, including government-access powers, to determine whether the SCC protections work in reality.
- Add safeguards or stop. Encryption, access controls and data minimisation may reduce risk. If the remaining risk cannot be addressed, the transfer may have to be suspended even where SCCs were signed.
That framework does not mean every transfer to China is automatically illegal. It means the company must demonstrate a lawful mechanism and protection that works in practice.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →What data was involved?
The public complaint announcement does not provide a complete, company-by-company inventory of data sent to China. It refers generally to European users’ personal data and to privacy-policy disclosures, as well as companies’ responses or alleged failures to respond adequately to Article 15 access requests.
It therefore does not establish that every service transferred passwords, private messages, payment details, precise location or biometric information. A policy may describe possible transfers without proving that every listed category actually moved, while vague “third-country” language may be legally important without proving that China was the destination.
Storage, processing and access are different questions
- Storage location: where a database or backup is physically held.
- Processing location: where data is analysed or otherwise used.
- Remote access: whether staff or contractors in another country can access a European-hosted system.
- Legal recipient: the corporate entity, affiliate, subprocesser or service provider receiving the data.
- Government-access exposure: whether local law could compel an entity to provide data.
A Chinese-founded company may store some information in Europe, and a European data centre does not by itself rule out access by an affiliate or service provider in China. Conversely, a corporate headquarters in China does not prove that all user data is stored there.
What NOYB asked regulators to do
NOYB asked the competent authorities to:
- immediately suspend the challenged data transfers;
- order the companies to bring their processing into compliance with the GDPR; and
- impose administrative fines.
The GDPR ceiling cited by NOYB is up to 4% of worldwide annual turnover or €20 million, whichever is higher, subject to the regulation and the authority’s assessment. NOYB gave illustrative calculations of about €147 million for AliExpress and €1.35 billion for Temu using revenues it cited. Those figures are advocacy-group estimates, not announced or expected penalties.
Best Value
- No more exposed information in unprotected notary journals. This product shields clients' confidential information from prying eyes. It allows the Notary Public to keep the journal open during the transaction, as NO prior client information is viewable.
- Shields clients' AND Notary Publics' confidential information
- GLBA and HIPAA require non-disclosure policies and procedures. Notary Privacy Guard is a compliance tool for the professional Notary Public.
- Decreases Notary Public's liability from exposing client information
- Journal column headers are printed on the Notary Privacy Guard, no having to peek underneath to complete the journal entry. Becomes part of the journal and also acts as a place marker.
What the complaints prove—and what they do not
| Established by the filing | Not established by the filing alone |
|---|---|
| Six complaints were filed on January 16, 2025, in five countries. | That any company has been finally found to violate the GDPR. |
| Specific transfer and transparency practices were challenged. | That Chinese authorities accessed a named user’s data. |
| NOYB sought suspension, compliance orders and fines. | That all six companies transfer data to China, or that every data category moves there. |
| The complaints raise questions about Chinese-law government-access risks. | That the services have been banned or that a fine is inevitable. |
What happens after a complaint?
A complaint starts a supervisory process rather than ending it. Authorities may first assess jurisdiction and competence, then request information from NOYB and the companies. They can examine privacy notices, data maps, contracts, SCCs, transfer-impact assessments, technical controls and the identities of recipients or subprocessors.
Depending on the evidence, an authority could order changes, suspend a flow, impose a fine, reject some claims or close the matter without the remedies requested. The six cases were filed with different national authorities, so procedure and timing may differ. The available announcement does not establish a later final decision, suspension or policy change.
What European users can reasonably do
- Read the current privacy notice. Look for China, named third countries, international-transfer sections and the legal entities receiving data.
- Limit optional collection. Disable non-essential personalisation, targeted advertising, analytics or cloud synchronisation where the service offers those controls.
- Use GDPR rights. You can request access to your data and information about recipients or third-country transfers, and request deletion where applicable.
- Minimise sensitive information. Avoid entering information that the service does not clearly explain, especially where the account is not necessary for the transaction.
- Separate device and online services. A Xiaomi phone can be used without every Xiaomi account, cloud or analytics feature. Review those services individually.
- Keep expectations realistic. Uninstalling an app, using a VPN or choosing a European data centre may reduce some exposure, but none independently proves that previously collected data was deleted or that all international access has stopped.
Why the cases matter beyond these six brands
The dispute is not simply a question of whether an app is Chinese. It tests how the EU’s international-transfer rules apply when a company, affiliate or service provider may be subject to laws that permit government access. The same analysis can arise for any destination country: what data leaves the EEA, who can access it, which safeguards apply and whether those safeguards remain effective in practice.
TikTok is the most politically visible name, but the complaints cover social media, smartphones, online marketplaces, fashion retail and messaging. For users, the practical issue is the service’s actual data flow rather than its headquarters alone.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




