Ireland Ireland DPC GDPR enforcement Big Tech HQ

Irish High Court Upholds TikTok's €530M Fine, But Tells the DPC to Actually Weigh Its Own Evidence

Ireland's High Court keeps TikTok's €530M GDPR fine intact but faults the DPC's dismissal of Project Clover evidence, forcing a corrective-order do-over.

The TikTok Ruling, by the Numbers People of Internet Research · Ireland €530M Total GDPR fine upheld €485M for unlawful China transfers… €12B Project Clover investment TikTok's decade-long EU data-local… 6 months Original compliance deadline Time the DPC gave TikTok to end Ch… 2 of 3 Dublin data centres built Two of Project Clover's three EU d… peopleofinternet.com
The TikTok Ruling, by the Numbers People of Internet Research · Ireland €530M Total GDPR fine upheld €12B Project Clover investment 6 months Original compliance deadl… 2 of 3 Dublin data centres built peopleofinternet.com

Key Takeaways

The Irish High Court's June 3, 2026 ruling in TikTok Technology Ltd v Data Protection Commission delivers a split verdict that should reassure both sides of the GDPR enforcement debate — and unsettle both a little too. The court upheld the Data Protection Commission's finding that TikTok breached Articles 46 and 13 of the GDPR by transferring EEA user data to China without adequate safeguards, and it left the €530 million fine intact. But it also ruled that the DPC botched the process behind its most consequential remedy: the order suspending TikTok's transfers to China altogether.

What the DPC Found, and What It Ordered

The DPC's original decision, dated May 2, 2025, fined TikTok €485 million for unlawfully transferring EEA user data to China without demonstrating protections equivalent to EU law, plus €45 million for failing to properly disclose those transfers in its privacy policy — a combined €530 million, the largest single GDPR penalty the DPC has ever issued. Alongside the fine, the DPC ordered TikTok to suspend transfers to China within six months unless it brought its data flows into compliance with GDPR Chapter V.

Steelmanning the DPC's Approach

The DPC's underlying theory is not unreasonable. Article 46 GDPR requires that any transfer of personal data to a country without an EU adequacy decision be backed by "appropriate safeguards" and "enforceable data subject rights and effective legal remedies." China has neither an adequacy decision nor a legal framework that meaningfully constrains state access to data held by firms operating there. A regulator whose job is to protect 450 million EU residents' data has good reason to treat remote access from Chinese soil as a live risk, regardless of how the data is technically labelled, and to be skeptical of a company's self-designed remediation program marketed under a friendly name like "Project Clover." Employees in Beijing accessing pseudonymised EU user records is still a transfer that needs a lawful basis, and dismissing that concern as merely theoretical would be an abdication, not restraint.

Where the DPC Overreached

But process matters as much as principle, and this is where the DPC came up short. The court found that the Commission erred by refusing to consider a third expert opinion TikTok submitted on Chinese law, and — more damagingly — that it concluded, without stating its reasoning, that TikTok's Project Clover pseudonymisation and privacy measures did not justify a different corrective approach than an outright transfer ban. The court held the DPC should have asked not merely whether data could in theory relate to an identifiable person, but whether data subjects could in fact be identified given the safeguards TikTok had actually built. Because the DPC's corrective-order reasoning may have been distorted by that gap, the court vacated the transfer-suspension order and remitted the question of what corrective measures are appropriate back to the regulator.

That is a meaningful check, not a technicality. Project Clover is a real €12 billion, decade-long commitment — two of its three EU data centres are already operational in Dublin, with a third in Norway, audited on an ongoing basis by the independent security firm NCC Group. A regulator that brushes past €12 billion of verifiable engineering without explaining why it doesn't move the needle isn't just risking reversal on appeal; it's setting a precedent where compliance investment carries no evidentiary weight, which is exactly the wrong incentive to send to every other platform sizing up whether remediation is worth the capital outlay.

Why the Politics of This Cut Both Ways

The DPC has said it will not appeal the June 3 ruling — Deputy Commissioner Graham Doyle confirmed the Commission accepts the judgment — and is now reassessing what corrective order to issue in its place. That restraint is itself notable. Ireland's DPC has issued roughly €4 billion in cumulative GDPR fines against Big Tech over six years, the overwhelming majority still tied up in appeals and uncollected. A regulator that keeps losing procedural fights on the way to defending eye-catching headline fines isn't demonstrating rigor; it's inviting years of relitigation that helps no one — not the companies seeking legal certainty, not the users whose data is the actual subject of the dispute.

The Proportionality Case

None of this excuses TikTok's underlying conduct, and the €530 million fine standing is the correct outcome: real deficiencies in transparency and transfer safeguards were found and should be penalized. But GDPR enforcement's credibility depends on regulators applying the same evidentiary discipline to their own remedies that they demand of the companies they investigate. A one-stop-shop system that lets Dublin set data-transfer policy for the whole EU only works if its reasoning survives judicial scrutiny — otherwise every major enforcement action becomes a multi-year court fight, which serves neither innovation nor privacy. The DPC now has a chance to write a corrective order that actually grapples with what TikTok built. It should take it.

Sources & Citations

  1. EDPB: DPC fines TikTok €530M
  2. GDPR Article 46 text
  3. Irish Times: DPC reconsidering transfer ban
  4. Arthur Cox: the TikTok decision explained
  5. Silicon Republic: Project Clover investment
  6. Privacy Daily: DPC won't appeal ruling