TikTok has been fined €530 million ($600 million) by European Union privacy regulators for illegally transferring European users' personal data to China and failing to demonstrate that this information was adequately protected from potential access by Chinese authorities, as reported by the Irish Data Protection Commission, writes ABC News.

Chinese Authority Access Concerns

The investigation revealed that TikTok failed to address the risks associated with Chinese authorities potentially accessing Europeans' personal data under China's anti-terrorism, counter-espionage, and national security laws-frameworks that TikTok itself acknowledged "materially diverge" from EU standards. Despite TikTok's assertions that it "has never received a request for European user data from the Chinese authorities, and has never provided European user data to them", regulators remained unconvinced by these assurances. The company's failure to conduct necessary assessments regarding these risks formed a central part of the EU's decision.

During the investigation, TikTok initially denied storing European user data on servers in China, but later admitted in April 2025 that it had discovered "limited EEA User Data" had in fact been stored on Chinese servers, contradicting its previous statements to regulators. This revelation of providing "inaccurate information" further damaged TikTok's credibility and highlighted the concerns that have kept the Chinese-owned platform "in the crosshairs of Western governments for years over fears personal data could be used by China for espionage or propaganda purposes".

Project Clover Data Centers

TikTok's Project Clover represents a €12 billion investment to enhance data security for its 150 million European users by establishing dedicated data centers within Europe. The initiative includes three strategic locations: two in Ireland and one in Norway, with the Norwegian facility in Hamar being the largest of its kind in Europe once completed. The first Irish data center went live in September 2023, while the Norwegian facility began operations in late 2024, with all three buildings at the Norwegian site now fully operational as of April 2025.

The data centers form a "European enclave" where user data is stored by default, with strict security measures in place. These facilities run on renewable energy and employ approximately 200 people including IT engineers and cooling specialists. Independent cybersecurity firm NCC Group provides continuous monitoring of TikTok's security gateways, ensuring that restricted data like phone numbers and IP addresses cannot be accessed by employees in China. This level of transparency and oversight is described as "unmatched amongst online platforms" and sets a new industry standard for data protection.

EU GDPR Compliance Violations

The Irish Data Protection Commission found that TikTok violated key provisions of the EU's General Data Protection Regulation (GDPR) in two significant ways. First, TikTok failed to "verify, guarantee and demonstrate" that European users' data accessed by staff in China received protection equivalent to EU standards. This violation resulted in a €485 million fine. Second, TikTok breached transparency requirements between 2020 and 2022 by not properly informing users about data transfers to China, leading to an additional €45 million penalty.

The investigation also uncovered that TikTok provided inaccurate information during the inquiry, initially claiming it didn't store European user data on Chinese servers. However, in April 2025, TikTok admitted discovering in February that "limited EEA user data" had been stored in China, contradicting its previous statements. The DPC has ordered TikTok to bring its data processing into compliance within six months or face suspension of all data transfers to China.