TikTok Technology Limited – Court Ruling (Ireland, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
TikTok faced scrutiny over how it transferred personal data of users in Europe to China. The Irish data protection authority found that TikTok didn't show it was protecting user data adequately during these transfers. This ruling is crucial for companies that handle data across borders, as it stresses the need for strong data protection measures.
What happened
TikTok was investigated for transferring personal data of European users to China without adequate protection.
Who was affected
European users of TikTok whose personal data was transferred to China.
What the authority found
The data protection authority determined that TikTok failed to prove that user data received sufficient protection during transfers to China, violating GDPR requirements.
Why this matters
This ruling highlights the importance of ensuring strong data protection when transferring personal data internationally. Companies must review their data transfer practices to comply with privacy laws.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
TikTok Technology Limited, the controller, and TikTok Information Technologies UK Limited appealed a decision of the Data Protection Commission, the DPA, before the High Court. The DPA had opened an own-volition inquiry into transfers of personal data of EEA users of the TikTok platform to China. The controller operated the TikTok platform in the EEA and allowed personnel of China-based group entities to remotely access certain EEA user data. The controller accepted that the data included personal data and that the remote access constituted a transfer under Chapter V GDPR. The controller relied on standard contractual clauses and supplementary measures. It argued that the personal data was stored outside China and only remotely accessed from China. On this basis, the controller claimed that Chinese public authorities could not compel access to the data because, under the territoriality principle in Chinese law, Chinese authorities had no power to access data stored outside China. The DPA considered that the controller had not sufficiently demonstrated that the relevant Chinese laws would not apply to the personal data while it was being processed by personnel in China. The DPA also considered that the controller had failed to properly assess whether the transferred data received a level of protection essentially equivalent to that guaranteed in the EEA. During the inquiry, the controller also introduced Project Clover. This was a set of measures intended to localise EEA user data in Europe, restrict access by China-based personnel and reduce the data flows still accessible from China. Under Project Clover, certain data would remain accessible by China-based personnel, but the controller argued that this data would be subject to additional privacy-enhancing measures, including pseudonymisation and differential privacy. The DPA found that the controller infringed Article 46(1) GDPR between 29 July 2020 and 17 May 2023. It also found that the controller infringed Artic
Outcome
Court Ruling
A ruling by a national court on a data-protection matter.
Related Cases (1)
Other cases involving TikTok Technology Limited in IE
Details
About this data
Cite as: Cookie Fines. TikTok Technology Limited - Ireland (2026). Retrieved from cookiefines.eu
Last updated: