Ireland Ireland DPC GDPR enforcement Big Tech HQ

Irish Court Forces DPC to Justify TikTok Data-Transfer Suspension, Not Just Assume It

The Irish High Court upheld TikTok's €530M GDPR fine but sent the China data-transfer suspension order back for want of reasoning on Project Clover.

TikTok's €530M Irish GDPR Fine, Broken Down People of Internet Research · Ireland €530M Total GDPR fine One of the largest fines ever issu… €485M Unlawful transfers fine For failing to verify safeguards o… €45M Transparency violations fine For inadequate disclosure of trans… peopleofinternet.com
TikTok's €530M Irish GDPR Fine, Broken… People of Internet Research · Ireland €530M Total GDPR fine €485M Unlawful transfers fine €45M Transparency violations fine peopleofinternet.com

Key Takeaways

Ireland's Data Protection Commission (DPC) is reconsidering one of the most consequential remedies in EU data-protection history: the order suspending TikTok's transfer of European user data to China. The reassessment follows a June 3, 2026 Irish High Court judgment that upheld the DPC's underlying GDPR findings and its €530 million fine against TikTok, but ruled that the regulator had failed to properly justify the suspension order itself, and sent that specific question back to the DPC (Irish Times).

What the court actually decided

The DPC's original May 2, 2025 decision found TikTok had breached Article 46(1) GDPR by failing to "verify, guarantee and demonstrate" that its Standard Contractual Clauses and supplementary safeguards gave EEA user data protection equivalent to EU standards once accessed by staff in China, and breached Article 13(1)(f) through inadequate transparency about those transfers between July 2020 and December 2022. The regulator imposed a combined €485 million and €45 million fine, and ordered TikTok to bring its processing into compliance within six months of the appeal period closing — or suspend the transfers entirely (DPC press release; EDPB).

TikTok appealed, and a stay kept the order frozen through a procedural detour to the Supreme Court over which national rules governed such stays — resolved in TikTok's favour in April 2026. The substantive High Court judgment then landed on June 3: the €530 million fine and the infringement findings stand, final and unappealed. But on the suspension order specifically, the court found the DPC had erred by not stating the basis on which it concluded that TikTok's Project Clover programme — a reported €12 billion European data-localisation and oversight initiative — didn't justify a less drastic remedy, and by declining to engage with a third expert opinion TikTok submitted on Chinese law. As the judgment put it, Project Clover measures are "clearly relevant to the question of whether a suspension order was necessitated in this case" (freevacy.com; privacy-daily.com).

The DPC has confirmed it will not appeal. Chair Des Hogan said the commission is "in the process of reading the judgment" and that reconsideration "will now happen over the coming period," with no fixed deadline given. Until that reassessment concludes, the suspension order remains stayed and TikTok's transfers continue uninterrupted.

Steelmanning the DPC's original approach

The DPC's instinct to treat cross-border access from China as presumptively high-risk isn't paranoia. China's 2017 National Intelligence Law obliges organisations operating there to cooperate with state intelligence work, and no contractual clause or pseudonymisation scheme can override a sovereign legal command to hand over data on request. A regulator responsible for enforcing Chapter V of the GDPR across the entire EU — because Dublin hosts the European headquarters of most major platforms — has to take that structural risk seriously, and a blanket suspension is the cleanest way to eliminate it rather than trust a corporate compliance programme to police a foreign government's own intelligence apparatus. Given how slow and Big-Tech-friendly the DPC's enforcement record has often been criticised as being, treating €530 million and a suspension order as a package deal was, on its face, a defensible show of teeth.

Why the court's correction matters more than the headline fine

But that's exactly what makes this ruling significant: the court didn't spare TikTok on substance. The infringement findings and the fine — among the largest ever issued under the GDPR — are final. What it corrected was process: a regulator cannot impose the single most disruptive remedy available under the GDPR without engaging, on the record, with the specific mitigation a company actually built. Project Clover is not a hypothetical; it's a concrete, multi-billion-euro architecture of European data storage, third-party monitoring and encryption designed precisely to address the risk the DPC identified. A suspension order that never explains why that architecture is insufficient isn't rigorous regulation — it's a categorical assumption dressed up as a finding.

That distinction matters far beyond this one case. If regulators can order the nuclear remedy — severing a platform's international data architecture — without having to reason through a company's actual safeguards, every multinational operating in the EU faces the same exposure regardless of what it invests in compliance. That would make transfer suspensions arbitrary rather than proportionate, chilling investment in exactly the kind of localisation and oversight infrastructure the GDPR is meant to incentivise. Requiring the DPC to show its work doesn't weaken GDPR enforcement; it makes the remedy defensible, appeal-proof and replicable — which is what durable enforcement actually requires. The fine stands as a serious deterrent. The correction to the suspension order is a proportionality check working exactly as intended, not a loophole for Big Tech.

Sources & Citations

  1. DPC press release: TikTok fined €530M
  2. EDPB news: Irish SA fines TikTok €530M
  3. Irish Times: DPC reconsidering TikTok transfer ban
  4. freevacy.com: High Court ruling on corrective measures
  5. privacy-daily.com: DPC won't appeal ruling