Recommended Free Tools
Ireland’s Data Protection Commission (DPC), TikTok’s lead privacy regulator in the EU, imposed a €530 million fine on the company in April 2025 over how it protected and explained access to European data from China. The original case concerned remote access to data stored in Singapore and the United States—not a finding that all European users’ data was stored on Chinese servers or that Chinese authorities had accessed it. A separate DPC inquiry followed after TikTok disclosed that a limited amount of EEA user data had been stored on servers in China.
The fine has been challenged in court. Irish court rulings followed in 2026, but the DPC’s fines register lists the penalty as “Pending Appeal”; the available official records do not establish that the €530 million has been paid or collected. DPC fines register
What Ireland’s DPC fined TikTok for
The DPC adopted its decision on 30 April 2025 and announced it on 2 May. It acted as TikTok’s lead EU supervisory authority under the GDPR’s One-Stop-Shop system; the fine was not imposed by the European Commission. The DPC says it circulated its draft decision to the other concerned supervisory authorities, and no objections were raised through the GDPR cooperation procedure. DPC decision summary
The €530 million total comprised two penalties for different GDPR infringements:
#1 Best Overall
| Fine | GDPR provision | What the DPC found |
|---|---|---|
| €485 million | Article 46(1) | TikTok failed to verify, guarantee and demonstrate that EEA user data remotely accessed from China received protection essentially equivalent to that required in the EU. |
| €45 million | Article 13(1)(f) | TikTok did not adequately tell users about transfers to third countries and remote access from China. |
The decision also ordered TikTok to bring the processing into GDPR compliance and to suspend the relevant transfers if it did not do so within the prescribed period. It required the company to ensure that EEA data located in China through the remote-access system ceased being processed there once the order took effect. DPC decision summary
What “sending data to China” meant in the original case
The phrase can give the wrong impression if it is taken to mean that TikTok routinely stored all European users’ data in China. The original decision concerned EEA user data stored on servers in Singapore and the United States that personnel of ByteDance-group companies in China could access remotely. The DPC treated that access as an international transfer subject to GDPR rules.
- Physical storage is the country where the server holding data is located.
- Remote access is the ability of staff in another country to view, use or otherwise process that data.
- Transfer compliance asks whether the company can demonstrate that the data remains protected to an essentially equivalent standard in the destination country.
That last question matters even when the data stays on a server outside the destination country: storage location alone does not settle whether an international transfer has occurred or whether it is adequately protected. DPC decision summary
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
Why the DPC found TikTok’s safeguards inadequate
GDPR transfers to countries outside the EEA are not automatically prohibited. They require an appropriate legal basis and safeguards. The DPC found that TikTok had not shown that its Standard Contractual Clauses and supplementary safeguards provided essentially equivalent protection in China.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsThe regulator considered Chinese laws including the Anti-Terrorism Law, Counter-Espionage Law, Cybersecurity Law and National Intelligence Law. It said TikTok’s own assessment identified material differences between those legal regimes and EU standards, but the company did not adequately address the resulting risks in its transfer assessment. DPC announcement of the decision
This was a finding about GDPR compliance and the safeguards TikTok could demonstrate—not a finding that Chinese authorities actually obtained the affected data. TikTok said it had never received a request from Chinese authorities for European user data and had never provided such data to them. That is the company’s account, not proof that the regulator found the data had been accessed by authorities. TikTok’s response
Rank #3
What users were told—and when
The DPC found that TikTok’s October 2021 EEA privacy policy did not name China and other third countries receiving data, or explain that personnel in China could remotely access data stored in Singapore and the United States. It found the relevant disclosures in the December 2022 policy compliant, limiting this transparency infringement to 29 July 2020 through 1 December 2022. DPC announcement of the decision
TikTok’s response and Project Clover
TikTok said it disagreed with the DPC’s decision and intended to appeal it in full. It argued that Project Clover, rolled out from 2023, changed its data architecture and safeguards. The company has described measures including data localization, security gateways, encryption on access and differential privacy as part of its approach. Those are TikTok’s claims about its safeguards; they should not be confused with the DPC’s findings about the earlier processing period. TikTok’s response
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →The DPC’s decision considered the relevant transfer practices and corrective measures, but its findings and orders do not amount to a general endorsement of Project Clover or a conclusion that later safeguards resolved every issue. DPC announcement of the decision
Rank #4
Why there is a separate inquiry into data stored in China
In February 2025, TikTok discovered that a limited amount of EEA user data had been stored on servers in China; it notified the DPC in April. The regulator said that disclosure contradicted evidence given in the earlier inquiry, which described China-related processing as remote access to data stored outside China. In July 2025, the DPC opened a separate inquiry. DPC announcement of the separate inquiry
The new inquiry is not the proceeding that produced the €530 million fine. It examines potential issues involving accountability under Article 5(2), transfer information under Article 13(1)(f), cooperation with the regulator under Article 31 and GDPR rules on international transfers in Chapter V. The announcement establishes that the inquiry was opened; it does not establish a final finding or penalty in that proceeding. DPC announcement of the separate inquiry
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Where the court proceedings stand
The penalty has been challenged, and the official records give more than one part of the procedural picture. The Irish Supreme Court record shows a judgment in TikTok Technology Limited v DPC delivered on 30 April 2026 and uploaded on 5 May, with the result recorded as “Dismissed.” The High Court issued judgments on 3 June and 30 June 2026; the later judgment says the court had already concluded that TikTok infringed Articles 46 and 13(1)(f), while remaining issues concerned interpretation and calculation of the fines. Supreme Court record · High Court judgment of 30 June 2026
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
The DPC’s public fines register still labels TikTok’s €530 million penalty “Pending Appeal” and says fines do not become payable until confirmed in court. Accordingly, the available records support neither saying the fine was overturned nor saying it has been paid or collected. DPC fines register
What this means for TikTok users and other companies
The fine does not require users to delete TikTok, and it does not establish that every user’s full profile was copied to China. It does show that a company cannot answer international-transfer questions just by identifying where its servers sit: remote access by staff abroad can matter, and the company must assess legal and practical risks and explain relevant transfers to users.
For an EEA user concerned about their own information, the decision does not prescribe a special action. People can review TikTok’s current EEA privacy policy and use applicable GDPR rights, including requests for access or deletion, through the company’s current channels. The same lesson applies to organizations using overseas support, engineering, analytics or moderation teams: assess who can access personal data, from where, under what legal safeguards, and what users have been told.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




