HomeSecurityIreland: TikTok fined for GDPR violation

Ireland: TikTok fined for GDPR violation

TikTok has been fined €530 million by the Irish Data Protection Authority (DPC) for violating GDPRby sending user data to China.

TikTok GDPR fine Ireland

The regulator has ordered TikTok to bring its data processing practices into line with the regulations within six months, warning that if it fails to comply within the stipulated period, it will suspend data transfers to China.

DPC Deputy Commissioner Graham Doylesaid TikTok's transfers of personal data to China breached the GDPR because the company failed to demonstrate, ensure or confirm that user data, which was accessed remotely by staff in China, was protected in a way that meets European standards.

Furthermore, he stressed that TikTok did not make the necessary assessments regarding the possibility that Chinese authorities would have access to the data in question.

See also: TikTok Shop comes to France, Germany and Italy

The Irish Data Protection Commission (DPC) also revealed that TikTok provided misleading information during its investigation when it claimed it did not store European user on Chinese servers. However, according to a recent update to the DPC, TikTok admitted that it had identified a problem in February where limited user data was indeed stored on servers in China – contradicting the company’s previous assurances.

Graham Doyle said the DPC is taking the issue very seriously and is considering additional regulatory measures. These may be taken in cooperation with other European data protection, as this is a wider compliance issue within the EU.

For its part, TikTok expressed its opposition to the Irish regulator's decision and intends to challenge it legally through a full appeal.

In a blog post , Christine Grahn , TikTok's head of institutional relations and public policy in Europe, argued that the decision ignored important developments, such as " Project Clover " — a €12 billion investment aimed at strengthening the protection of European users' personal data.

See also: USA: TikTok brings Amber Alert notifications to For You feeds

Grahn stressed that the decision focuses on an earlier time period, before the launch of the Clover program in 2023, and therefore does not reflect data protection policies TikTok's

He also pointed out that even the Irish regulator itself acknowledged in its report that TikTok had consistently stated that it has never received a request for European user data from the Chinese authorities, nor has it shared such data with them.

On the other hand, the company had previously admitted that employees in China and other countries, such as Brazil, Canada and Israel, could have access to user data. It had mentioned this in a related update to its privacy policy in 2022, explaining that this is done to ensure a uniform, positive and safe experience for users.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Ireland: TikTok fined for GDPR violation
Ireland: TikTok fined for GDPR violation

However, there is ongoing concern among Western regulators and politicians that user data flowing through the platform could end up in Beijing's hands and be used for spying purposes. Chinese law allows the government to demand access to user data from technology companies.

For its part, TikTok has repeatedly assured that it has never shared user data with the Chinese government. The company's CEO, Shou Zi Chew, testified in writing to the US Congress in 2023 that there has never been a sharing or request for sharing of user data from the US to Chinese authorities.

See also: TikTok lets parents see teens' followers

GDPR

The GDPR sets out requirements for the collection, storage and management of personal data by businesses and organisations. The requirements apply to organisations based in Europe that process personal data of individuals in the EU, as well as to organisations outside the EU that target European citizens.

EU data protection rules are among the strictest privacy rules in the world , and violating them can lead to fines of up to 4% of an organization's annual turnover.

Source: www.cnbc.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS