All news
Case law April 30, 2026 6 min

TikTok vs Irish DPC: Supreme Court suspends 530 million euro fine

April 30, 2026: the fine stay remains in place. The case redefines GDPR enforcement timelines

TL;DR for the DPO

On April 30, 2026, the Irish Supreme Court confirmed the stay of the 530M EUR fine that the DPC had imposed on TikTok on May 1, 2025 for unlawful transfer of EEA data to China. The fine remains suspended until the High Court's merit decision. For DPOs: anyone transferring extra-EU data must document Transfer Impact Assessments (TIAs) - missing documentation is the center of enforcement.

The case in 3 minutes

On May 1, 2025, the Irish Data Protection Commission (DPC) fined TikTok Technology Limited 530M EUR for violation of Art. 46(1) GDPR: transfer of personal data of EEA users to China (via remote access by ByteDance personnel) without adequate safeguards.

TikTok challenged the decision before the Irish High Court. On November 14, 2025, the High Court granted a stay on the fine and the transfer suspension order, pending the merit decision of the appeal. The DPC appealed the granting of the stay to the Supreme Court.

On April 30, 2026, the Supreme Court rejected the DPC's appeal, confirming the stay. The fine remains unenforced. The merits will be decided by the High Court on timelines measured in years.

530MEUR
DPC fine
6
Months compliance deadline
175M
TikTok EEA users

What the DPC charged in the original decision

  • TikTok allowed remote access to EEA data by personnel located in China, without verifying that the level of protection was 'substantially equivalent' to that guaranteed in the EU (Schrems II)
  • TikTok used Standard Contractual Clauses (SCCs) but had not conducted a Transfer Impact Assessment adequate to the specifics of the Chinese legal context
  • TikTok's privacy policy did not adequately inform users of transfers to China
  • During the investigation TikTok stated it had never stored EEA data in China; in April 2025 it revealed that some data had in fact been stored on Chinese servers, contradicting previous statements

Practical implications for Italian DPOs

Even for Italian SMEs, any transfer of extra-EU data - including those to US cloud providers like AWS or Azure - requires: (1) appropriate legal basis (SCC, BCR, adequacy decision), (2) documented Transfer Impact Assessment, (3) supplementary technical measures if necessary (encryption, pseudonymization).

The structural effect: enforcement that lasts years

The TikTok case highlights a systemic problem with the GDPR: big tech headquartered in Ireland can obtain suspension of DPC decisions for years of litigation, delaying execution of fines and corrective orders.

This dynamic applies to Meta, Google, LinkedIn, Apple and other companies headquartered in Ireland. A DPC decision today does not translate to immediate compliance: it translates to a judicial path of 3-5 years.

What changes for your average client

  • The legal principle remains: extra-EU transfers must be protected as within the EU (Schrems II)
  • Standard good practices remain valid: SCC + documented TIA + supplementary measures where necessary
  • You cannot say 'TikTok got away with it, we can too': your client does not have the resources for years of litigation in Irish courts
  • Italian DPA fines for unlawful transfers are much faster to execute

The 6-step Transfer Impact Assessment

  • 1. Identify categories of data transferred and extra-EU recipients
  • 2. Check adequacy decision for the recipient country (updated EU list)
  • 3. If no adequacy, choose the instrument: SCC, BCR, or approved code of conduct
  • 4. Assess the recipient country's legal framework: government access powers to data, available remedies for data subjects
  • 5. Determine if supplementary measures are needed (end-to-end encryption, pseudonymization, access controls)
  • 6. Document everything: the documented TIA is the difference between fine and case closure in case of inspection

In DPO Workspace

For clients using extra-EU cloud providers, we suggest creating a dedicated processing activity in Art. 30 with the following fields: recipient country, transfer legal basis, link to TIA, supplementary measures, next review date. This way you have documentation ready in case of inspection.

Comparison with other data transfer cases

  • Meta vs DPC (May 2023): 1.2 billion EUR for US transfers after Schrems II - still in litigation
  • TikTok vs DPC (May 2025): 530M EUR for China transfers - suspended until 2027-2028 estimated
  • Schrems II (July 2020): invalidation of US Privacy Shield - immediate regulatory change
  • EU-US Data Privacy Framework (July 2023): new framework, already challenged (Schrems III imminent)
Official source:Compliance Hub: TikTok vs DPC Supreme Court Ruling

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Case law
200 €for the loss of control

Real employee data inside the test system: what loss of control is worth

Testing a new HR system with real data is not forbidden: transferring more fields than the test needs is. The German Federal Labour Court ordered an employer to pay two hundred euro because it had uploaded salary, home address, tax ID and marital status although it had agreed a list of nine fields with the works council. And it confirmed that a delayed answer to an access request is not, in itself, a damage.

Aug 21, 2026New 5 min
Case law
7i criteri di bilanciamento CEDU

You don't delete the article, you delete the name

On 5 August 2026 the CNIL clarified the boundaries of a right that is often exercised and widely misunderstood. Against a press organisation, objection and erasure remain available; access and rectification do not. And a refusal must be reasoned concretely: six generic formulas are named as inadmissible.

Aug 05, 2026New 4 min
Case law
3condizioni cumulative del test

Legitimate interest is not the fallback legal basis

In Case C-621/22 the Court of Justice held that a commercial interest can constitute a legitimate interest under Article 6(1)(f). Many people read only that line. The rest of the judgment recalls that the conditions remain three and cumulative, and that the third - the balancing against the data subject's reasonable expectations - is where the case at hand was lost. For the DPO the consequence is practical: legitimate interest exists only if it is written down somewhere.

Aug 12, 2026New 6 min