The Irish High Court's June 3, 2026 ruling in TikTok Technology Ltd v Data Protection Commission delivers a split verdict that should reassure both sides of the GDPR enforcement debate — and unsettle both a little too. The court upheld the Data Protection Commission's finding that TikTok breached Articles 46 and 13 of the GDPR by transferring EEA user data to China without adequate safeguards, and it left the €530 million fine intact. But it also ruled that the DPC botched the process behind its most consequential remedy: the order suspending TikTok's transfers to China altogether.
What the DPC Found, and What It Ordered
The DPC's original decision, dated May 2, 2025, fined TikTok €485 million for unlawfully transferring EEA user data to China without demonstrating protections equivalent to EU law, plus €45 million for failing to properly disclose those transfers in its privacy policy — a combined €530 million, the largest single GDPR penalty the DPC has ever issued. Alongside the fine, the DPC ordered TikTok to suspend transfers to China within six months unless it brought its data flows into compliance with GDPR Chapter V.
Steelmanning the DPC's Approach
The DPC's underlying theory is not unreasonable. Article 46 GDPR requires that any transfer of personal data to a country without an EU adequacy decision be backed by "appropriate safeguards" and "enforceable data subject rights and effective legal remedies." China has neither an adequacy decision nor a legal framework that meaningfully constrains state access to data held by firms operating there. A regulator whose job is to protect 450 million EU residents' data has good reason to treat remote access from Chinese soil as a live risk, regardless of how the data is technically labelled, and to be skeptical of a company's self-designed remediation program marketed under a friendly name like "Project Clover." Employees in Beijing accessing pseudonymised EU user records is still a transfer that needs a lawful basis, and dismissing that concern as merely theoretical would be an abdication, not restraint.
Where the DPC Overreached
But process matters as much as principle, and this is where the DPC came up short. The court found that the Commission erred by refusing to consider a third expert opinion TikTok submitted on Chinese law, and — more damagingly — that it concluded, without stating its reasoning, that TikTok's Project Clover pseudonymisation and privacy measures did not justify a different corrective approach than an outright transfer ban. The court held the DPC should have asked not merely whether data could in theory relate to an identifiable person, but whether data subjects could in fact be identified given the safeguards TikTok had actually built. Because the DPC's corrective-order reasoning may have been distorted by that gap, the court vacated the transfer-suspension order and remitted the question of what corrective measures are appropriate back to the regulator.
That is a meaningful check, not a technicality. Project Clover is a real €12 billion, decade-long commitment — two of its three EU data centres are already operational in Dublin, with a third in Norway, audited on an ongoing basis by the independent security firm NCC Group. A regulator that brushes past €12 billion of verifiable engineering without explaining why it doesn't move the needle isn't just risking reversal on appeal; it's setting a precedent where compliance investment carries no evidentiary weight, which is exactly the wrong incentive to send to every other platform sizing up whether remediation is worth the capital outlay.
Why the Politics of This Cut Both Ways
The DPC has said it will not appeal the June 3 ruling — Deputy Commissioner Graham Doyle confirmed the Commission accepts the judgment — and is now reassessing what corrective order to issue in its place. That restraint is itself notable. Ireland's DPC has issued roughly €4 billion in cumulative GDPR fines against Big Tech over six years, the overwhelming majority still tied up in appeals and uncollected. A regulator that keeps losing procedural fights on the way to defending eye-catching headline fines isn't demonstrating rigor; it's inviting years of relitigation that helps no one — not the companies seeking legal certainty, not the users whose data is the actual subject of the dispute.
The Proportionality Case
None of this excuses TikTok's underlying conduct, and the €530 million fine standing is the correct outcome: real deficiencies in transparency and transfer safeguards were found and should be penalized. But GDPR enforcement's credibility depends on regulators applying the same evidentiary discipline to their own remedies that they demand of the companies they investigate. A one-stop-shop system that lets Dublin set data-transfer policy for the whole EU only works if its reasoning survives judicial scrutiny — otherwise every major enforcement action becomes a multi-year court fight, which serves neither innovation nor privacy. The DPC now has a chance to write a corrective order that actually grapples with what TikTok built. It should take it.