Irish data commissioner launches GDPR probe into TikTok's handling of children's data and the transfer of user information to China
Hannah Murphy / Financial Times : Source: Data Protection Commission .
Context & Ripple Effects
This probe, opened by Ireland's Data Protection Commission in September 2021, turned out to be the root of TikTok's entire GDPR enforcement saga: the regulator split its inquiry into two strands — how the app handles children's data, and whether transferring European users' information to China breaches GDPR. As lead EU supervisor for TikTok, the DPC had jurisdiction over both.
The children's-data strand resolved first, with a €345 million fine in September 2023 and three months given to comply; the China-transfer strand ran longer and ended far heavier, with a €530 million penalty in May 2025 that also ordered a halt to EU-to-China data flows within six months absent guaranteed protections. Reading the 2021 launch against those outcomes shows the probe was never routine housekeeping — it set the legal architecture for both penalties.
First-order effects
- TikTok immediately comes under formal investigation by its lead European regulator on two fronts at once — children's data handling and user-data transfers to China — requiring detailed responses to DPC information requests across both files.
- The dual mandate effectively freezes the status quo: any change TikTok makes to where European user data is processed or how minors' accounts are treated now happens under active regulatory examination.
Second-order effects
- The probe's findings compound into escalating financial exposure: the children's-data strand alone produces a €345M fine with a compliance deadline, and the transfer strand produces a €530M fine plus an operational order to stop sending EU users' data to China unless safeguards are proven — a constraint on TikTok's engineering and infrastructure decisions, not just its balance sheet.
- A halt order on EU-China transfers forces TikTok toward re-architecting data flows for its largest non-US market, with costs and timelines dictated by the DPC's six-month window rather than product roadmaps.
Third-order effects
- If the pattern holds, the DPC's two-strand approach becomes a template for enforcing GDPR against platforms whose data practices span jurisdictions regulators consider high-risk: first establish the transfer breach, then price it, then attach behavioral orders — fines functioning as leverage over infrastructure, not just punishment.
- Children's data emerges as a standing enforcement priority in Europe independent of the geopolitics: TikTok's €345M penalty signals that minors' privacy breaches draw their own investigations and deadlines even when the headline concern is cross-border transfers.
The trend: GDPR enforcement is shifting from one-off privacy fines to multi-year investigations that end in penalties paired with orders reshaping where platforms physically process user data.