Search

06 Sept 2025

TikTok faces fresh European privacy investigation over China data transfers

TikTok faces fresh European privacy investigation over China data transfers

TikTok is facing a fresh European Union privacy investigation into user data sent to China, regulators said.

The Data Protection Commission (DPC) opened the inquiry as a follow-up to a previous investigation that ended earlier this year with a 530 million euro (£456 million) fine after it found the video sharing app put users at risk of spying by allowing remote access to their data from China.

The Irish national watchdog serves as TikTok’s lead data privacy regulator in the 27-nation EU because the company’s European headquarters is based in Dublin.

During an earlier investigation, TikTok initially told the regulator it did not store European user data in China, and that data was only accessed remotely by staff in China.

However, it later backtracked and said that some data had in fact been stored on Chinese servers.

The watchdog responded at the time by saying it would consider further regulatory action.

“As a result of that consideration, the DPC has now decided to open this new inquiry into TikTok,” the watchdog said.

“The purpose of the inquiry is to determine whether TikTok has complied with its relevant obligations under the GDPR in the context of the transfers now at issue, including the lawfulness of the transfers,” the regulator said, referring to the European Union’s strict privacy rules, known as the General Data Protection Regulation (GDPR).

TikTok, which is owned by China’s ByteDance, has been under scrutiny in Europe over how it handles personal user information amid concerns from Western officials that it poses a security risk.

TikTok noted that it was the one that notified the Data Protection Commission, after it embarked on a data localisation project called Project Clover that involved building three data centres in Europe to ease security concerns.

“Our teams proactively discovered this issue through the comprehensive monitoring TikTok implemented under Project Clover,” the company said in a statement.

“We promptly deleted this minimal amount of data from the servers and informed the DPC. Our proactive report to the DPC underscores our commitment to transparency and data security.”

Under the GDPR, European user data can only be transferred outside of the bloc if there are safeguards in place to ensure the same level of protection.

Only 15 countries or territories are deemed to have the same data privacy standards as the EU, but China is not one of them.

To continue reading this article,
please subscribe and support local journalism!


Subscribing will allow you access to all of our premium content and archived articles.

Subscribe

To continue reading this article for FREE,
please kindly register and/or log in.


Registration is absolutely 100% FREE and will help us personalise your experience on our sites. You can also sign up to our carefully curated newsletter(s) to keep up to date with your latest local news!

Register / Login

Buy the e-paper of the Donegal Democrat, Donegal People's Press, Donegal Post and Inish Times here for instant access to Donegal's premier news titles.

Keep up with the latest news from Donegal with our daily newsletter featuring the most important stories of the day delivered to your inbox every evening at 5pm.