Irish data commissioner launches GDPR probe into TikTok over its handling of children's data and the transfer of user information to China
Irish regulator adds to scrutiny of video app that has drawn national security concerns — The Irish data commissioner has launched investigations … Source: Data Protection Commission .
Context & Ripple Effects
This September 2021 probe is the origin point of the enforcement arc that followed: Ireland's Data Protection Commission opened parallel investigations into TikTok's handling of children's data and its transfers of user information to China, at a moment when the app was already drawing national-security scrutiny. The children's-data thread produced a €345M GDPR fine in 2023, with three months given to comply.
The China-transfer thread ran longer but landed harder — the DPC ultimately issued a €530M fine for illegally sending user data to China in May 2025, ordering a halt to EU data transfers within six months unless protections are guaranteed, after Bloomberg had reported the €500M-plus penalty was coming. What began as one regulator's probe has become the template case for how Europe polices cross-border data flows to China.
First-order effects
- TikTok must open both lines of inquiry — children's data practices and China transfer mechanisms — to the DPC while simultaneously managing US national-security pressure on the same underlying issue.
- The DPC, as TikTok's lead EU regulator under GDPR's one-stop-shop structure, gains jurisdictional leverage over every aspect of the app's European data operations.
Second-order effects
- Any platform routing EU user data through China-facing infrastructure now faces the same investigative playbook, since the DPC's eventual findings on transfer legality became enforceable precedent rather than a TikTok-specific ruling.
- TikTok's compliance costs compound across regulators: the 2023 children's-data compliance deadline and the 2025 six-month transfer-halt ultimatum force architectural changes to where EU data can be stored and processed at all.
Third-order effects
- If the pattern holds, GDPR enforcement escalates from corrective requests to fines large enough to dictate data architecture — effectively forcing a structural separation between European users' data and Chinese access paths, decided by regulators rather than by the companies.
- Children's data emerges as a distinct enforcement priority inside GDPR, with the 2021 probe showing regulators willing to run dual-track investigations that treat minors' protection and geopolitical data flows as separate breaches of the same law.
The trend: European data protection authorities are converting GDPR from a compliance framework into a geopolitical instrument, using escalating fines to force companies to sever data-transfer pathways to China.