TikTok Facing New Privacy Investigation From Europe Over China Data Transfers
Popular social media app TikTok is facing a new privacy investigation from the European Union due to user data being sent to China, regulators stated this week.
The Data Protection Commission opened up the inquiry as a follow up to a previous investigation that ended earlier this year with a 530 million euro ($620 million) fine. The fine was enforced after it was found that TikTok put its user’s data at risk of being exposed and spied on by allowing remote access from China.
TikTok’s European headquarters are based in Dublin, Ireland, so the Irish national watchdog will be serving as TikTok’s lead data privacy regulator in the 27-nation EU.
During a previous investigation, TikTok told the regulator that they didn’t store European user data in China, and the data itself was remotely accessible by staff in China.
Later on, it backtracked and stated that some data had been stored on Chinese servers, and the watchdog responded by stating they would consider regulatory action, according to the Associated Press.
“As a result of that consideration, the DPC has now decided to open this new inquiry into TikTok,” the watchdog stated.
“The purpose of the inquiry is to determine whether TikTok has complied with its relevant obligations under the GDPR in the context of the transfers now at issue, including the lawfulness of the transfers,” the regulator said, referencing the General Data Protection Regulation which is the European Union’s privacy rules.
TikTok is owned by China’s ByteDance, and has been under scrutiny from multiple nations over how they handle personal user information and data. Western officials specifically believe that the app poses a security risk which the EU has also cited.
“Our teams proactively discovered this issue through the comprehensive monitoring TikTok implemented under Project Clover,” the company said in a statement.
“We promptly deleted this minimal amount of data from the servers and informed the DPC. Our proactive report to the DPC underscores our commitment to transparency and data security.”
Under the GDPR, European user data can only be transferred outside of the bloc if there are safeguards in place. These safeguards ensure a certain level of protection, and only 15 countries or territories are deemed to have an equal data privacy obligation as the EU.
Eric Mastrota is a Contributing Editor at The National Digest based in New York. A graduate of SUNY New Paltz, he reports on world news, culture, and lifestyle. You can reach him at eric.mastrota@thenationaldigest.com.



