TikTok is once again transferring the personal data of European users to China.

  • TikTok has resumed transferring user data from the EEA to China following the temporary suspension of the Irish sanction.
  • The €530 million fine from the Irish data protection authority remains in effect, but is under appeal and judicial review.
  • The Spanish Data Protection Agency (AEPD) and other European regulators consider that these transfers do not comply with the GDPR and issue a special warning to minors.
  • Authorities recommend reviewing privacy settings, limiting permissions, and considering whether to continue using TikTok while sending data to China.

TikTok transfers personal data to China

In recent weeks, millions of European users have begun seeing a warning on TikTok about the transfer of personal data to China . The message, which has raised concerns among daily users of the social network, directly references an investigation opened by data protection authorities in Ireland.

The text superimposed on the app is not a hoax: the notification is official and has been confirmed by the platform itself . In it, TikTok reports that it is appealing a multimillion-dollar fine imposed by the Irish regulator for sending user data from the European Economic Area (EEA) to China via remote access, while explaining that, for the time being, it can continue to do so.

Ireland's €530 million fine and the role of the GDPR

The conflict originated in April 2025, when the Irish Data Protection Commission (DPC) , the main authority that oversees TikTok in Europe because its EU headquarters are in Dublin, concluded a wide-ranging investigation into the platform's international data flows.

Following this joint analysis with other European regulators, the DPC determined that TikTok had not complied with the requirements of the General Data Protection Regulation (GDPR) by allowing remote access from China to EEA user information between 2020 and 2023, without guaranteeing a level of protection equivalent to that required within the European Union.

The Irish regulator imposed a €530 million fine and ordered corrective measures, including halting data transfers to China within six months if the company did not fully comply with the GDPR. The ruling was accompanied by a warning that, without robust safeguards, access from China would remain incompatible with European regulations.

The message that now appears in the app, under the title "Transfer of EEA user data to China via remote access", summarizes precisely that procedure: Ireland's decision, the order to stop the shipments and the appeal filed by TikTok in the country's courts.

TikTok's notice about personal data and China

TikTok's appeal and the temporary suspension of the block

After receiving the Irish ruling, TikTok decided to appeal it to the High Court of Ireland . This legal step has completely changed the short-term scenario: the court agreed to temporarily suspend the DPC's decision while the appeal is being processed.

In practice, this means that, although the financial penalty and the regulator's legal assessment remain in effect, the order to block data transfers to China is temporarily suspended . Until there is a final ruling, the company can continue with its international data processing model.

The platform itself explains this in the notification displayed within the app. This text indicates that, as of November 14, 2025, and as a direct consequence of the Irish court's decision , data transfers of EEA users to China may continue while the legal proceedings are underway.

This temporary lifting of the ban is contingent upon TikTok fulfilling certain additional transparency obligations. Therefore, the company has begun to more visibly inform European users about how it handles their data, what type of information may be accessible from China, and the status of its litigation with the Irish regulator.

TikTok insists it “totally disagrees” with Ireland’s decision and that, in its view, the measures it has implemented offer sufficient safeguards. However, the legality of these transfers remains under judicial review , and the debate with European authorities is far from over.

What data can be sent to China and why is this a concern for Europe?

The underlying problem is not so much the existence of remote access from China itself, but the legal framework under which that access occurs . The GDPR requires that, when personal data is sent outside the EU or EEA, the destination country guarantees a level of protection essentially equivalent to that of Europe.

In the case of China, European data protection authorities believe that national security, anti-terrorism, and counter-espionage laws allow local authorities to demand from technology companies any information they process in the interest of the state. This makes it very difficult to ensure that a European user's data cannot end up in the hands of the government or the People's Liberation Army.

During the Irish investigation, TikTok initially claimed it did not store EEA user data on servers located in China. However, as the proceedings progressed, the company had to admit that a limited amount of information had indeed reached Chinese systems due to an internal error, fueling regulators' concerns.

European authorities have not presented evidence of any specific access by the Chinese government to TikTok's databases. However, they emphasize that the Chinese legal framework would permit such access , a point that directly contradicts GDPR requirements for international data transfers.

For the average user, all this legal mess translates into something quite simple: if you use TikTok in Europe, some of your data may be accessible from China while the legal challenge is ongoing and the suspension of the block remains in effect.

The reaction of the Spanish Data Protection Agency (AEPD) and the other European regulators

The Spanish Data Protection Agency (AEPD) has addressed concerns and reiterated that, despite the temporary suspension of the blocking order, the European authorities' assessment remains unchanged . According to a recently released statement, TikTok continues to transfer the personal data of European users to third countries, including the People's Republic of China, under conditions that do not comply with the GDPR.

The Spanish Data Protection Agency (AEPD), which participated in the coordinated procedure through the European Data Protection Board, emphasizes that the Irish Data Protection Commission's decision is the result of a joint analysis by several national authorities. The shared conclusion is that the safeguards offered by TikTok are insufficient to offset the risks arising from Chinese legislation.

In this context, the Spanish agency points out that, although the implementation of certain corrective measures is currently suspended by court order, the legality of the transfers remains in question and continues to be reviewed. In other words, the sanction has not been annulled; it is simply pending the final decision of the Irish courts.

The Spanish Data Protection Agency (AEPD) also emphasizes that TikTok has designated Ireland as its main establishment in Europe . This means that the Irish Data Protection Commission (DPC) acts as the lead supervisory authority, but always in coordination with the other European agencies, which are closely monitoring the case and participating in the cooperation mechanisms provided for by the GDPR.

The AEPD's public complaint had a clear objective: to warn European users that the risk situation has not disappeared , despite the reassuring messages issued by the company.

TikTok's discourse: Project Clover and security promises

In response to criticism from regulators, TikTok has issued a firm message: it asserts that it takes the privacy and data protection of its European users very seriously. As part of this defensive strategy, the company has focused on its initiative known as Project Clover.

According to the platform, this is an investment plan of around €12.000 billion aimed at strengthening data security in Europe. The company maintains that, thanks to this project, EEA user information is now stored by default in data centers , including one in Brazil, located in Ireland, Norway, and the United States, with strict access controls and independent third-party audits.

The company also states that employees based in China cannot access certain sensitive data , such as phone numbers or IP addresses, and that some of the information used globally is pseudonymized or subject to additional security measures to limit risks.

According to TikTok, these investments offer “unparalleled guarantees” for European users and demonstrate that its model can comply with the GDPR. The company maintains that it has used existing EU legal mechanisms to allow limited and highly controlled remote access for technical support, moderation, and service maintenance purposes.

However, data protection authorities are maintaining a cautious stance. They believe that, while the data localization project and additional controls are steps in the right direction, they are not enough to completely neutralize the risks associated with Chinese legislation and the potential access of European authorities to user information.

User warnings: review permissions and consider whether to continue using the app

Beyond the legal battle with TikTok, the Spanish Data Protection Agency (AEPD) has taken advantage of the case's visibility to launch a series of recommendations aimed at users of digital services , with special emphasis on young people, who spend the most time on these types of applications.

The Spanish regulator emphasizes the importance of carefully reading the notifications and privacy policies that appear when using social networks, games, and other apps, even though they may seem somewhat dense. Understanding what data is collected, for what purposes, and which countries you can travel to is key to making informed decisions.

It also advises reviewing the privacy settings and permissions granted to each app, checking whether it's truly necessary to grant access to the microphone, camera, contacts, or location at all times. In the case of TikTok, many users accept these permissions without question, even though limiting them can reduce the amount of information sent to the company's servers.

Another guideline shared by the AEPD is to act with caution regarding the information shared on social networks, avoiding publishing or sending particularly sensitive data, such as health information, details about sexual orientation, financial data or personal documents.

Finally, the agency goes a step further and suggests that users consider whether they want to continue using services that send data to countries without a level of protection equivalent to that of Europe . In other words, it encourages users to seriously consider stopping using platforms like TikTok if they are uncomfortable with the possibility that some of their information might end up under more intrusive jurisdictions.

A case that weighs heavily on the European debate on international transfers

The TikTok controversy comes at a time when the European Union has been grappling for years with data transfers to countries with vastly different legal systems . The most well-known example is the United States: the EU Court of Justice has twice struck down data-sharing agreements with that country, deeming them insufficient in terms of privacy.

The current EU-US data transfer framework is also under scrutiny in the courts, driven by lawsuits from the same lawyer who successfully challenged the two previous agreements. This climate of widespread distrust toward foreign jurisdictions places the TikTok-China case at the heart of the European debate on the extent to which personal data can be outsourced.

In this scenario, regulators point out that once personal information is stored or made accessible from countries outside the European Union , it becomes subject to local laws. In the Chinese case, this could imply, at least on paper, very broad access by authorities to the systems of technology companies.

Doubts about what really happens to data aren't limited to TikTok's internal workings. Several privacy advocacy groups in Europe have pointed to potential additional risks related to advertising and cross-app tracking , adding another layer of concern about how information is being exploited beyond the video app itself.

Meanwhile, many Western governments have tightened their scrutiny of the platform, including a possible ban in the US , making any decision about its data model a matter of political and social significance.

The TikTok case illustrates the extent to which the management of personal data has become a point of contention between global platforms, European regulators, and countries with vastly different legal frameworks. While Ireland debates in court whether the fine and restrictions on data transfers will be upheld, the social network continues to operate normally in Europe and send information to China . Meanwhile, the Spanish Data Protection Agency (AEPD) and other authorities remind citizens that they are not mere spectators: they have the power to adjust their privacy settings, limit permissions, and decide whether it is worthwhile to continue using a service whose data processing model remains under scrutiny.

TikTok transfers European data
Related article:
TikTok under European scrutiny for transferring user data to China

Add as preferred source in Google