TL;DR for the DPO
On April 30, 2026, the Irish Supreme Court confirmed the stay of the 530M EUR fine that the DPC had imposed on TikTok on May 1, 2025 for unlawful transfer of EEA data to China. The fine remains suspended until the High Court's merit decision. For DPOs: anyone transferring extra-EU data must document Transfer Impact Assessments (TIAs) - missing documentation is the center of enforcement.
The case in 3 minutes
On May 1, 2025, the Irish Data Protection Commission (DPC) fined TikTok Technology Limited 530M EUR for violation of Art. 46(1) GDPR: transfer of personal data of EEA users to China (via remote access by ByteDance personnel) without adequate safeguards.
TikTok challenged the decision before the Irish High Court. On November 14, 2025, the High Court granted a stay on the fine and the transfer suspension order, pending the merit decision of the appeal. The DPC appealed the granting of the stay to the Supreme Court.
On April 30, 2026, the Supreme Court rejected the DPC's appeal, confirming the stay. The fine remains unenforced. The merits will be decided by the High Court on timelines measured in years.
What the DPC charged in the original decision
- TikTok allowed remote access to EEA data by personnel located in China, without verifying that the level of protection was 'substantially equivalent' to that guaranteed in the EU (Schrems II)
- TikTok used Standard Contractual Clauses (SCCs) but had not conducted a Transfer Impact Assessment adequate to the specifics of the Chinese legal context
- TikTok's privacy policy did not adequately inform users of transfers to China
- During the investigation TikTok stated it had never stored EEA data in China; in April 2025 it revealed that some data had in fact been stored on Chinese servers, contradicting previous statements
Practical implications for Italian DPOs
Even for Italian SMEs, any transfer of extra-EU data - including those to US cloud providers like AWS or Azure - requires: (1) appropriate legal basis (SCC, BCR, adequacy decision), (2) documented Transfer Impact Assessment, (3) supplementary technical measures if necessary (encryption, pseudonymization).
The structural effect: enforcement that lasts years
The TikTok case highlights a systemic problem with the GDPR: big tech headquartered in Ireland can obtain suspension of DPC decisions for years of litigation, delaying execution of fines and corrective orders.
This dynamic applies to Meta, Google, LinkedIn, Apple and other companies headquartered in Ireland. A DPC decision today does not translate to immediate compliance: it translates to a judicial path of 3-5 years.
What changes for your average client
- The legal principle remains: extra-EU transfers must be protected as within the EU (Schrems II)
- Standard good practices remain valid: SCC + documented TIA + supplementary measures where necessary
- You cannot say 'TikTok got away with it, we can too': your client does not have the resources for years of litigation in Irish courts
- Italian DPA fines for unlawful transfers are much faster to execute
The 6-step Transfer Impact Assessment
- 1. Identify categories of data transferred and extra-EU recipients
- 2. Check adequacy decision for the recipient country (updated EU list)
- 3. If no adequacy, choose the instrument: SCC, BCR, or approved code of conduct
- 4. Assess the recipient country's legal framework: government access powers to data, available remedies for data subjects
- 5. Determine if supplementary measures are needed (end-to-end encryption, pseudonymization, access controls)
- 6. Document everything: the documented TIA is the difference between fine and case closure in case of inspection
In DPO Workspace
For clients using extra-EU cloud providers, we suggest creating a dedicated processing activity in Art. 30 with the following fields: recipient country, transfer legal basis, link to TIA, supplementary measures, next review date. This way you have documentation ready in case of inspection.
Comparison with other data transfer cases
- Meta vs DPC (May 2023): 1.2 billion EUR for US transfers after Schrems II - still in litigation
- TikTok vs DPC (May 2025): 530M EUR for China transfers - suspended until 2027-2028 estimated
- Schrems II (July 2020): invalidation of US Privacy Shield - immediate regulatory change
- EU-US Data Privacy Framework (July 2023): new framework, already challenged (Schrems III imminent)
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free