Pillaraxis Cyber law, privacy & security — read plainly
Vol. 2 · 2026
Kochi, India
Brief No. 010
GDPR & Privacy

TikTok's €530 Million Lesson: Why Cross-Border Transfers Are GDPR's Real Fault Line

The Irish DPC's penalty against TikTok confirms that moving European data to China, or anywhere outside the bloc, is now the single most expensive mistake a platform can make.

When people picture a GDPR fine, they usually picture consent: a cookie banner nobody read, a checkbox that was pre-ticked, a privacy notice buried three clicks deep. The numbers tell a different story. Look at the ten largest GDPR fines ever issued and the pattern is not consent design, it is geography — where the data physically ends up, and under whose laws it sits once it gets there.

In May 2025, Ireland's Data Protection Commission fined TikTok €530 million for transferring the personal data of European users to China, where the DPC found the company could not guarantee that data would be shielded from access by Chinese authorities. It is the third-largest GDPR fine on record, behind only Meta's €1.2 billion penalty for EU-US transfers and Amazon's since-annulled €746 million fine for ad targeting. Two of the three largest fines in GDPR history, in other words, were not about what data companies collected — they were about where it went afterward.

Two of the three largest GDPR fines in history were not about what data was collected — they were about where it went afterward.

This is the doctrine that traces back to the Court of Justice's Schrems II ruling: an adequate legal basis to collect data is not the same as an adequate legal basis to move it across a border into a jurisdiction with weaker protections. The mechanism GDPR uses to bridge that gap — Standard Contractual Clauses, supplementary technical measures, transfer impact assessments — sounds like paperwork. In TikTok's case, and in Meta's, regulators decided the paperwork could not actually deliver on its promise, because no contractual clause can stop a foreign intelligence law from compelling disclosure.

TikTok has appealed, and the Irish High Court granted a stay in November 2025 allowing transfers to continue while the case is heard — a reminder that a headline fine is rarely the end of the story. But the direction of travel is unmistakable. As AI training pipelines, customer support outsourcing, and cloud infrastructure increasingly route data through subsidiaries and subprocessors outside the EU, transfer mapping is no longer a compliance afterthought. It is the primary exposure.

← OlderGDPR Meets the AI Act: Two Regulations, One Compliance Headache