• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
tiktok slammed with €530 million gdpr fine for sending e.u.

TikTok Slammed With €530 Million GDPR Fine for Sending E.U. Data to China

You are here: Home / General Cyber Security News / TikTok Slammed With €530 Million GDPR Fine for Sending E.U. Data to China
May 2, 2025

Ireland’s Data Protection Commission (DPC) on Tuesday fined popular video-sharing platform TikTok €530 million ($601 million) for infringing data protection regulations in the region by transferring European users’ data to China.

“TikTok infringed the GDPR regarding its transfers of EEA [European Economic Area] User Data to China and its transparency requirements,” the DPC said in a statement. “The decision includes administrative fines totaling €530 million and an order requiring TikTok to bring its processing into compliance within 6 months.”

Cybersecurity

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


The order, in addition, requires the company to suspend data transfers to China within the time period.

The penalty is the result of an investigation that was launched in September 2021 that probed the company’s transfer of personal data to China and its compliance with stringent data protection laws regarding data transfers to third countries.

Commenting on the decision, DPC Deputy Commissioner Graham Doyle said TikTok’s personal data transfers to China went against Article 46(1) of the General Data Protection Regulation (GDPR) because it failed to verify and guarantee that the personal data of EEA users was given equivalent privacy protections to that afforded within the bloc.

Doyle further added that TikTok did not address concerns arising from potential access by Chinese authorities under anti-terrorism and counter-espionage laws in the country and which “materially” diverged from European Union standards.

The DPC also faulted TikTok for providing erroneous information during the inquiry to the effect that it did not store EEA users’ data in Chinese servers, only to disclose to the watchdog last month that it identified an issue in its systems in February 2025, as a result of which limited EEA data had indeed been stored on servers in China.

Cybersecurity

“Whilst TikTok has informed the DPC that the data has now been deleted, we are considering what further regulatory action may be warranted, in consultation with our peer EU Data Protection Authorities,” Doyle said.

Christine Grahn, TikTok’s head of public policy and government relations for Europe, said the decision failed to take into account Project Clover, a data security initiative aimed at protecting European user data, and that the ruling does not reflect the current safeguards put in place.

“The DPC itself recorded in its report what TikTok has consistently said: it has never received a request for European user data from the Chinese authorities, and has never provided European user data to them,” Grahn said.

This is the second fine levied by the DPC against the ByteDance-owned company. In September 2023, TikTok was handed a €345 million (then about $368 million) fine for violating GDPR laws in relation to its handling of children’s data.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «how to automate cve and vulnerability advisory response with tines How to Automate CVE and Vulnerability Advisory Response with Tines
Next Post: U.S. Charges Yemeni Hacker Behind Black Kingdom Ransomware Targeting 1,500 Systems u.s. charges yemeni hacker behind black kingdom ransomware targeting 1,500»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • New HTTPBot Botnet Launches 200+ Precision DDoS Attacks on Gaming and Tech Sectors
  • Top 10 Best Practices for Effective Data Protection
  • Researchers Expose New Intel CPU Flaws Enabling Memory Leaks and Spectre v2 Attacks
  • Fileless Remcos RAT Delivered via LNK Files and MSHTA in PowerShell-Based Attacks
  • [Webinar] From Code to Cloud to SOC: Learn a Smarter Way to Defend Modern Applications
  • Meta to Train AI on E.U. User Data From May 27 Without Consent; Noyb Threatens Lawsuit
  • Coinbase Agents Bribed, Data of ~1% Users Leaked; $20M Extortion Attempt Fails
  • Pen Testing for Compliance Only? It’s Time to Change Your Approach
  • 5 BCDR Essentials for Effective Ransomware Defense
  • Russia-Linked APT28 Exploited MDaemon Zero-Day to Hack Government Webmail Servers

Copyright © TheCyberSecurity.News, All Rights Reserved.