TikTok Fined for Unlawful EEA-to-China Data Transfers Under GDPR
TikTok violated GDPR by transferring European Economic Area (EEA) user data to China without adequately demonstrating that Chinese law could not compel access to that data, even when stored outside China. The core failure was an inability to prove that supplementary technical measures (Project Clover) genuinely neutralised the risks posed by Chinese surveillance legislation such as the National Intelligence Law. This case highlights that geographic data storage alone is insufficient — organisations must conduct rigorous, documented legal and technical assessments of third-country data access risks. Regulators will scrutinise the substance of transfer safeguards, not merely their existence, making thorough Transfer Impact Assessments (TIAs) a critical compliance requirement for any cross-border data flows.
Tactical Insight
Immediate actions
- Commission a formal Transfer Impact Assessment (TIA) for every third-country data transfer, specifically evaluating whether foreign surveillance laws override contractual or technical protections.
- Document and retain evidence that supplementary technical measures (e.g., encryption, pseudonymisation, access controls) are operationally effective and independently verified.
Long-term improvements
- Establish a Data Transfer Governance programme that maps all cross-border data flows, assigns ownership, and schedules periodic legal reviews as foreign laws evolve.
- Engage external legal counsel in recipient countries to provide written opinions on whether local laws can compel data disclosure, updating these opinions annually.
- Build data minimisation and localisation into system architecture by default, reducing the volume of personal data that must transit high-risk jurisdictions.
Detection & Monitoring measures
- Implement continuous monitoring of data egress paths to detect unauthorised or undocumented transfers to third countries.
- Establish a regulatory change-monitoring process to flag updates to foreign intelligence or data access laws that could invalidate existing TIAs or Standard Contractual Clauses.