High Court - TikTok Technology Limited v Data Protection Commission (2026) IEHC 347
| High Court - TikTok Technology Limited v Data Protection Commission (2026) IEHC 347 | |
|---|---|
| Court: | High Court (Ireland) |
| Jurisdiction: | Ireland |
| Relevant Law: | Article 13(1)(f) GDPR Article 46(1) GDPR Article 83(2)(b) GDPR |
| Decided: | 03.06.2026 |
| Published: | 03.06.2026 |
| Parties: | TikTok Technology Limited TikTok Information Technologies UK Limited Data Protection Commission |
| National Case Number/Name: | TikTok Technology Limited v Data Protection Commission (2026) IEHC 347 |
| European Case Law Identifier: | |
| Appeal from: | DPC (Ireland) IN-21-9-2 |
| Appeal to: | Unknown |
| Original Language(s): | English |
| Original Source: | Bailii (in English) |
| Initial Contributor: | bms |
A court upheld the DPC’s finding that TikTok unlawfully transferred EEA user data to China. However, it revoked the transfer ban because the DPC failed to properly assess TikTok’s technical changes.
English Summary
Facts
TikTok Technology Limited, the controller, and TikTok Information Technologies UK Limited appealed a decision of the Data Protection Commission, the DPA, before the High Court.
The DPA had opened an own-volition inquiry into transfers of personal data of EEA users of the TikTok platform to China. The controller operated the TikTok platform in the EEA and allowed personnel of China-based group entities to remotely access certain EEA user data. The controller accepted that the data included personal data and that the remote access constituted a transfer under Chapter V GDPR.
The controller relied on standard contractual clauses and supplementary measures. It argued that the personal data was stored outside China and only remotely accessed from China. On this basis, the controller claimed that Chinese public authorities could not compel access to the data because, under the territoriality principle in Chinese law, Chinese authorities had no power to access data stored outside China.
The DPA considered that the controller had not sufficiently demonstrated that the relevant Chinese laws would not apply to the personal data while it was being processed by personnel in China. The DPA also considered that the controller had failed to properly assess whether the transferred data received a level of protection essentially equivalent to that guaranteed in the EEA.
During the inquiry, the controller also introduced Project Clover. This was a set of measures intended to localise EEA user data in Europe, restrict access by China-based personnel and reduce the data flows still accessible from China. Under Project Clover, certain data would remain accessible by China-based personnel, but the controller argued that this data would be subject to additional privacy-enhancing measures, including pseudonymisation and differential privacy.
The DPA found that the controller infringed Article 46(1) GDPR between 29 July 2020 and 17 May 2023. It also found that the controller infringed Article 13(1)(f) GDPR between 29 July 2020 and 1 December 2022, because its 2021 privacy policy did not identify the third countries to which personal data was transferred and did not properly explain the nature of the processing.
The DPA imposed administrative fines totalling €530 million. It also ordered the controller to suspend the transfers and to bring its processing into compliance with the GDPR. The controller appealed the infringement findings, the fines and the corrective orders.
Holding
The Court largely dismissed the appeal.
Unlawful international transfers to China
First, the Court upheld the finding that the controller infringed Article 46(1) GDPR. The Court held that Chapter V GDPR requires a controller transferring personal data to a third country to verify that the data receives a level of protection essentially equivalent to that guaranteed in the EEA. The controller must also be able to demonstrate that assessment, in line with the accountability principle under Articles 5(2) and 24 GDPR.
The Court rejected the controller’s argument that the DPA had reversed the burden of proof. The DPA did not have to prove that Chinese authorities would in fact access the personal data. Rather, the relevant question was whether the controller had adequately verified and demonstrated that the transferred personal data received the required level of protection. The Court also rejected the controller’s argument that the DPA had misinterpreted Schrems II. According to the Court, the DPA was entitled to assess whether the controller’s verification of the third-country legal framework and supplementary measures was adequate. Since the controller had not properly assessed the position of personal data processed by personnel in China, the DPA was entitled to find an infringement.
Transparency obligations (Article 13(1)(f) GDPR)
Second, the Court upheld the finding that the controller infringed Article 13(1)(f) GDPR. The Court held that the controller’s privacy policy should have identified the third countries to which personal data was transferred, including China. It should also have explained the nature of the processing. The Court considered that the 2021 privacy policy fell short of the GDPR’s transparency requirements.
Negligence and entitlement to impose fines (Article 83 GDPR)
Third, the Court upheld the DPA’s conclusion that the infringements were negligent under Article 83(2)(b) GDPR. The controller failed to comply with an obvious obligation under Article 46(1) GDPR and did not justify its misunderstanding of its obligations under Article 13(1)(f) GDPR. Therefore, the DPA was entitled to impose administrative fines. However, the Court left the controller’s appeal against the amount of the fines for a later judgment.
Corrective measures
Fourth, the Court assessed the corrective orders. It held that the DPA had not erred in law by considering whether a suspension order and processing order were necessary, appropriate and proportionate. The DPA was not required to make a further infringement finding before adopting corrective orders.
However, the Court found that the DPA had not adequately assessed later evidence submitted by the controller. This included an updated Chinese law opinion and, in particular, the Project Clover measures. The Court accepted that Project Clover involved significant changes to the controller’s transfer model, including data localisation, access controls, reduced data flows and privacy-enhancing technologies.
The Court held that the DPA had not sufficiently explained why the controller’s pseudonymisation and differential privacy measures were ineffective, or why they did not affect the need for a suspension order. In particular, the DPA had not properly assessed whether EEA users remained identifiable in the data still accessible by China-based personnel under Project Clover. The Court noted that pseudonymised data is not automatically non-personal data, but it is also not necessarily personal data in every context. This required a reasoned assessment.
Outcome
The Court therefore upheld the finding that the controller’s transfers to China were unlawful under Article 46(1) GDPR and confirmed that the DPA was entitled to impose administrative fines. However, it vacated the DPA’s order requiring the suspension of the transfers, as well as the related processing order. The matter was remitted to the DPA, which must reassess whether corrective measures remain necessary and proportionate in light of Project Clover and the other later evidence.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the English original. Please refer to the English original for more details.
APPROVED [2026] IEHC 347
THE HIGH COURT
COMMERCIAL
Record No.: 2025/248 MCA
IN THE MATTER OFSECTION 142AND SECTION 150
OFTHE DATAPROTECTIONACT 2018
Between:
TIKTOK TECHNOLOGY LIMITED and TIKTOK INFORMATION
TECHNOLOGIES UK LIMITED
Appellants
And
DATAPROTECTION COMMISSION
Respondent
JUDGMENT of Mr Justice Rory Mulcahy delivered on 3 June 2026
CONTENTS
Introduction................................................................................................................................3
The transfers...............................................................................................................................8
The General Data Protection Regulation (GDPR).....................................................................9
Data Protection Act 2018.........................................................................................................20
The inquiry...............................................................................................................................24
The Decision............................................................................................................................44
The Data TransferAssessments...............................................................................................50
Scope of the appeal..................................................................................................................56
Nature of the Inquiry................................................................................................................65
Grounds of appeal....................................................................................................................69Ground 3 – Errors of law.........................................................................................................71
The decision in Schrems II...................................................................................................73
Alleged misinterpretation of the GDPR...............................................................................79
Arguments.........................................................................................................................79
Discussion.........................................................................................................................81
Alleged reversal of burden of proof.....................................................................................90
Arguments.........................................................................................................................90
Discussion.........................................................................................................................92
Alleged requirement to carry out risk assessment................................................................95
Arguments.........................................................................................................................95
Discussion.........................................................................................................................98
Overall conclusion on Ground 3............................................................................................101
Grounds 1 – Breach of fair procedures..................................................................................102
Failure to put adverse findings to TikTok ..........................................................................104
Arguments.......................................................................................................................104
Discussion.......................................................................................................................107
Failure to have regard to submissions made......................................................................115
Arguments.......................................................................................................................115
Discussion.......................................................................................................................118
Failure to adequately assess Project Clover.......................................................................121
Arguments.......................................................................................................................121
Discussion.......................................................................................................................122
Impermissible amendment of temporal scope....................................................................124
Arguments.......................................................................................................................124
Discussion.......................................................................................................................125
Failure to make the file available.......................................................................................126
Arguments.......................................................................................................................126
Discussion.......................................................................................................................128
Ground not pleaded............................................................................................................129
Overall conclusion on Ground 1............................................................................................130
Grounds 2 and 10...................................................................................................................130
Alleged errors in assessment..............................................................................................130
Arguments.......................................................................................................................132
Discussion – errors in assessment of Chinese law evidence..........................................133
Discussion – errors in assessment of Project Clover.....................................................145Overall conclusions on Ground 2 and 10...............................................................................155
Ground 11 – Error in making the corrective orders...............................................................156
Arguments – ground 11.......................................................................................................156
Discussion – ground 11......................................................................................................158
Overall conclusion on Ground 11..........................................................................................160
Ground 5 – misrepresentation and misapplication ofArticle 13(1)(f)...................................161
Arguments...........................................................................................................................164
Discussion..........................................................................................................................166
Overall conclusion on Ground 5............................................................................................169
Appeal against fines...............................................................................................................169
Ground 6 – failure by the DPC to establish that TikTok was negligent ................................170
Arguments.......................................................................................................................173
Discussion.......................................................................................................................174
Overall conclusion on Ground 6............................................................................................177
Summary of conclusions........................................................................................................178
Proposed Order ......................................................................................................................181
Introduction
1. The General Data Protection Regulation (Regulation (EU) 679/2016), generally known
as the GDPR, confers significant rights on all EU citizens in respect of their personal data,
including rights to clear information, rights of access, rights of rectification, and rights of
redress. Its territorial scope is the EU (and EEA, the GDPR having been formally
incorporated into the EEAAgreement on 6 October 2018).
2. Controllers and processors of personal data may only transfer that personal data outside
the EEA when the data will be subject to essentially equivalent levels of protection in the
third countries to which the data is transferred to that guaranteed within the EEA.
3. This appeal concerns, at its heart, the scope of the obligations imposed on controllers
of personal data when transferring personal data outside the EEA.
4. The appellant (“TikTok”) challenges a finding by the respondent (“the DPC”) that
TikTok had failed to fulfil its obligation when transferring certain personal data of its usersto China, and that it must stop transferring that data until it is in a position to comply with
the requirements of the GDPR. TikTok contends that the DPC has misunderstood the nature
of the obligations imposed by the GDPR.
5. On 14 September 2021, the DPC commenced an inquiry (“the Inquiry”) into TikTok
in accordance with section 110 of the Data ProtectionAct 2018 (“the 2018Act”). The DPC
is the State’s supervisory authority for the purpose of the GDPR.
6. Following a lengthy investigation, and having consulted with other supervisory
authorities in accordance with Article 60 of the GDPR, the DPC issued its decision on 30
April 2025 (“the Decision”). The Decision for the first time defined the temporal scope of
the Inquiry as relating to data transfers taking place from 29 July 2020 until 17 May 2023
(“the temporal scope”). In the Decision, the DPC found that TikTok had infringed Article
46(1) of the GDPR by failing to ensure that personal data of its users within the European
EconomicArea(“EEAUsers”)whichwastransferredoutsidetheEEA,inthiscasebybeing
made available by remote access to personnel based in China (“the data transfers”), was
afforded a level of protection essentially equivalent to that provided within the European
Union (“EU”) during the Inquiry’s temporal scope. The particular concern identified by the
DPC was that theregulation ofpublicauthorityaccess to personal datapursuant to identified
Chinese laws (“the relevant Chinese laws”) diverged materially from the protections
conferredbytheGDPRandTikTokhadnotestablishedthattherelevantChineselawswould
not apply to the data transfers.
7. The Decision also found that TikTok had breached Article 13(1)(f) of the GDPR by
failing to provide required information on the data transfers to data subjects from 29 July
2020 to 1 December 2022.
8. The DPC imposed administrative fines totalling €530 million pursuant to Article
58(2)(i) of the GDPR. The second appellant (“TikTok UK”) has been joined to these
proceedings on the basis that it is the party which will ultimately be responsible for paying
any such administrative fine. The DPC disputes its standing as a party in these proceedings
though it is not necessary to address that issue for the purpose of this judgment.9. In addition to the administrative fines, the DPC made orders pursuant toArticle 58(2)(j)
of the GDPR requiring TikTok to suspend the data transfers (“the suspension order”) and
to bring the manner in which it processed personal data into line with the GDPR “in the
manner described in” the Decision (“the processing order”) (together “the corrective
orders”).
10. The Decision can, therefore, be considered as comprising four relevant parts: (1) a
decision that TikTok had infringedArticle 46(1) of the GDPR between 29 July 2020 and 17
May 2023; (2) a decision that TikTok had infringed Article 13(1)(f) of the GDPR between
29 July 2020 and 1 December 2022; (3) a decision to impose the corrective orders; and (4)
a decision to impose administrative fines for the infringements.
11. By originating notice of motion issued on 27 May 2025, TikTok appealed the Decision
pursuant to section 142 and, if necessary, section 150 of the 2018Act.
12. In the affidavit of Elaine Fox, Head of Privacy, Europe and Head of Ireland at TikTok,
TikTok identified a total of eleven grounds of appeal. As discussed in further detail below,
the grounds are directed to each of the constituent parts of the Decision. Many of the eleven
grounds comprise a number of individual grounds.
13. It is worth observing at this point that a central feature of TikTok’s position that it had
complied (and continues to) with the requirements of Article 46 is that it employs what is
termed the “remote access solution”, whereby personal data processed in China is stored
outside China and remotely accessed from China. TikTok’s position is that as a matter of
Chinese law, any entitlement of the Chinese authorities to access personal data pursuant to
the relevant Chinese laws is subject to the territoriality principle, and that the Chinese
authorities have no power to access data stored outside of China. It contends that the
personal data the subject of the Inquiry, although remotely accessed (and accessible) in
China, is at all times stored outside China and therefore outside the jurisdiction of Chinese
authorities. In substance, the DPC accepted that by virtue of the territoriality principle, data
stored outside China is not subject to the relevant Chinese laws and therefore not at risk of
a lower level of protection than that guaranteed in the EU. However, it concluded that
TikTok had not addressed the application of the relevant Chinese laws to personal data
which was actually being processed in China.14. The institution of proceedings automatically stayed the requirement to pay the
administrative fines, by operation of section 142 of the 2018 Act. The corrective orders,
however, had immediate effect, and accordingly, TikTok sought a stay on those orders.
Following a four-day hearing between 7 and 10 October, I granted TikTok a stay on
implementation of the corrective orders, subject to certain conditions, in a judgment dated
13 November 2025 ([2025] IEHC 619) (“the stay judgment”). Some of the factual content
in this judgment has already been rehearsed in the stay judgment. The DPC sought and
obtained leave to appeal from that judgment to the Supreme Court, and an appeal was heard
between 17 and 19 February 2026. By judgment dated 30April 2026 ([2026] IESC 27), the
Supreme Court decided to continue the stay pending the determination of these proceedings
in the High Court.
15. On 12 February 2026, TikTok issued a motion seeking a similar order to one obtained
in the stay application, to protect the confidentiality of information it had provided to the
DPC in confidence during the Inquiry. The application was heard on 20 February 2026, and
I made the order sought in similar terms to the earlier order, for similar reasons (see §10 -
§13 of the stay judgment). During the course of the hearing, some of the information over
which protection had been provided was referred to in open court, either because TikTok
elected to do so, or because it became apparent that the protection was not required in
relation to that information. I have referred in this judgment to some of the material
identified as confidential by TikTok. I provided this judgment to the parties in draft form to
enable the parties to identify any information contained within it which theywished to apply
to have redacted. Very limited redactions were proposed by TikTok in order to continue to
protect confidential information the disclosure of which could undermine its security
measures. I am satisfied that the making of the redactions proposed is consistent with the
confidentiality orders previously made and I have, accordingly, applied those limited
redactions to this judgment.
16. These proceedings were heard over ten days between 3 and 19 March 2026. During the
course of the hearing, the parties indicated that they were in agreement that certain of the
legal issues raised in the appeal regarding the administrative fines might benefit from a
preliminary reference to the CJEU pursuant toArticle 267 of the Treaty on the Functioning
of the European Union (“TFEU”). In this regard, it should be noted that Ground 6 of the
appeal related to the DPC’s entitlement to impose administrative fines, and the remaininggrounds, Grounds 7, 8, and 9, related to the calculation of those fines. Certain of the legal
issues between the parties are also the subject of pending annulment proceedings before the
General Court of the CJEU, Case C-97/23P, WhatsApp v EDPB, and it was contended that
the duty of sincere co-operation atArticle 4(3) of the TFEU might necessitate a reference in
those circumstances. The parties engaged regarding the questions which they considered
should be referred, and a document setting out their respective positions was provided on
18 May 2026. The parties agreed the terms of some questions and made separate proposals
in relation to others.
17. In light of this development, I suggested to the parties that I could deliver separate
judgments, one on the grounds of appeals relating to the administrative fines (Grounds 6, 7,
8 and 9), and one on all the other grounds. The parties were amenable to that approach.
However, having considered the matter further, and in particular having considered the
issues which the parties suggest should be referred to the CJEU, it appears to me sensible to
deal in this judgment with all issues concerning whether the DPC was entitled to impose
administrative fines at all (i.e. Ground 6), which I consider can be addressed without the
necessity for a reference to the CJEU, and to leave over for a further judgment the grounds
relating to how any such fine should be calculated, which do give rise to some issues where
a reference would be appropriate.
18. This, accordingly, is the first of two intended judgments on the substantive appeal. A
second judgment (“the fines judgment”), dealing with Grounds 7, 8 and 9 of the appeal
will follow in early course.
19. At the time of hearing, judgment was awaited in a trial of preliminary issues in a
separate appeal against a decision of the DPC. It was anticipated that the judgment would
address the scope of the appeal provided for under the 2018Act, and accordingly the parties
did not address that issue in detail but set out a summary of their positions in their written
submissions. It was agreed that short further submissions would be provided once judgment
was delivered. Those further submissions were provided by TikTok and the DPC
respectively on 7 and 14 May 2026 in light of the judgment in LinkedIn v DPC [2026] IEHC
235, which is discussed below. 20. Having regard to the multiplicity of issues raised in this appeal, I propose to address
each ground separately, setting out the arguments and the analysis in relation to each in turn.
There are, however, some issues which could cut across multiple grounds, such as the
standard of review applicable to decisions of the DPC in a statutory appeal, and the nature
of the inquiry and sanctions provided for in the GDPR. I will deal with those overarching
questions before addressing the individual grounds. Before doing so, however, I propose to
identify the relevant provisions of the GDPR and the 2018 Act and then set out in a little
detail the history of the Inquiry. It might be helpful first to explain the nature of the transfers
the subject of that Inquiry.
The transfers
21. The TikTok Platform is a global entertainment platform that was launched in the EU in
2017 and in the EEA in 2018. It is available in more than 150 countries via an application
that can be downloaded on mobile phones and tablets, VR headsets and other smaller
distribution channels as well as via a web browser. The TikTok Platform enables its users
(individuals that view and/or engage with content on the TikTok Platform, referred to as
“Users”) and creators (TikTok Users who create and/or post videos, audio, images and other
content on the TikTok Platform, referred to as “Creators”) to create, share and watch video
content.
22. TikTok collects data from its users which is stored in data centres.Asubset of that data
can be accessed remotely by personnel of certain China Group Entities (“CGEs”), being a
list of identified companies associated with TikTok, for the purpose of carrying out a variety
of processes which TikTok says are essential to its operations. The access is subject to strict
conditions. TikTok accepts that some of the data which is remotely accessed is personal data
within themeaning ofthe GDPR. Italso accepts that this remoteaccess constitutes atransfer
for the purpose of the GDPR. TikTok calls the data which can be accessed remotely
‘allowable’data.Allowable data consists of (i) inter-operable data, which is data needed for
the TikTok platform to operate globally; (ii) public data, a type of inter-operable data which
is publicly available and accessible by anyone on the TikTok platform, and (iii) aggregated
data, allowable data which is compiled and expressed in a summary way. 23. As set out below, during the course of the Inquiry, TikTok added additional protections
to the data which can be accessed in China as part of a suite of measures it calls Clover or
Project Clover.
24. In the context of the stay application,TikTok explained in a little detail the purposes for
which the transferred data is used in China and the business processes which would be
affected if it was not permitted to transfer any data to China. These include product and
feature updates, algorithm updates, bug identification and issues resolution, and prevention
and resolution of platform and services outages. The key business groups involved are the
e-commerce group, the monetisation group, the TikTok Short Video group and the TikTok
live group.As set out in the stay judgment, many thousands of CGE employees are engaged
in theprocessing ofEEAuserdataforthesepurposes.Thevolumeofdatainvolvedis clearly
very significant.
The General Data Protection Regulation (GDPR)
25. Recital 1 of the GDPR recognises that the protection of natural persons in relation to
the processing of personal data is a fundamental right and references Article 8(1) of the
Charter of Fundamental Rights of the European Union (“the Charter”) andArticle 16(1) of
the TFEU, each of which provides that everyone has the right to the protection of personal
data concerning him or her.
26. Recital 4 provides that:
The processing of personal data should be designed to serve mankind. The right to the
protection of personal data is not an absolute right; it must be considered in relation to
its function in society and be balanced against other fundamental rights, in accordance
with the principle of proportionality. This Regulation respects all fundamental rights
and observes the freedoms and principles recognised in the Charter as enshrined in the
Treaties,inparticulartherespectforprivateandfamilylife,homeandcommunications,
the protection of personal data, freedom of thought, conscience and religion, freedom
of expression and information, freedom to conduct a business, the right to an effective
remedy and to a fair trial, and cultural, religious and linguistic diversity.27. Recital 26 refers to the scope of the GDPR and, in particular, its application to
information about “identified or identifiable natural persons”:
The principles of data protection should apply to any information concerning an
identified or identifiable natural person. Personal data which have undergone
pseudonymisation, which could be attributed to a natural person by the use of
additional information should be considered to be information on an identifiable
natural person. To determine whether a natural person is identifiable, account should
be taken of all the means reasonably likely to be used, such as singling out, either by
the controller or by another person to identify the natural person directly or indirectly.
To ascertain whether means are reasonably likely to be used to identify the natural
person, account should be taken of all objective factors, such as the costs of and the
amount of time required for identification, taking into consideration the available
technologyatthetimeoftheprocessingandtechnologicaldevelopments.Theprinciples
of data protection should therefore not apply to anonymous information, namely
information which does not relate to an identified or identifiable natural person or to
personal data rendered anonymous in such a manner that the data subject is not or no
longer identifiable. This Regulation does not therefore concern the processing of such
anonymous information, including for statistical or research purposes.
28. Recital 60 relates to transparency obligations:
The principles of fair and transparent processing require that the data subject be
informed of the existence of the processing operation and its purposes. The controller
should provide the data subject with any further information necessary to ensure fair
and transparent processing taking into account the specific circumstances and context
in which the personal data are processed.
29. Recital 74 concerns the responsibilities of controllers:
The responsibility and liability of the controller for any processing of personal data
carried out by the controller or on the controller's behalf should be established. In
particular, the controller should be obliged to implement appropriate and effective measures and be able to demonstrate the compliance of processing activities with this
Regulation, including the effectiveness of the measures. Those measures should take
into account the nature, scope, context and purposes of the processing and the risk to
the rights and freedoms of natural persons.
30. Recital 101 concerns the transfer of data outside the EU:
Flows of personal data to and from countries outside the Union and international
organisations are necessary for the expansion of international trade and international
cooperation. The increase in such flows has raised new challenges and concerns with
regardtotheprotectionofpersonaldata. However,whenpersonaldata aretransferred
from the Union to controllers, processors or other recipients in third countries or to
international organisations, the level of protection of natural persons ensured in the
Union by this Regulation should not be undermined, including in cases of onward
transfers of personal data from the third country or international organisation to
controllers, processors in the same or another third country or international
organisation. In any event, transfers to third countries and international organisations
may only be carried out in full compliance with this Regulation. A transfer could take
placeonlyif, subject to theotherprovisions of this Regulation, theconditions laiddown
in the provisions of this Regulation relating to the transfer of personal data to third
countries or international organisations are complied with by the controller or
processor.
31. Recitals 124 to 126 discuss the role of supervising authorities and the competence of
lead supervising authorities.
32. Recital 129 relates to the tasks and powers of supervisory authorities. It includes the
following:
... The powers of supervisory authorities should be exercised in accordance with
appropriate procedural safeguards set out in Union and Member State law, impartially,
fairly and within a reasonable time.In particular each measure should be appropriate,
necessary and proportionate in view of ensuring compliance with this Regulation,
taking into account the circumstances of each individual case, respect the right of every person to be heard before any individual measure which would affect him or her
adversely is taken and avoid superfluous costs and excessive inconveniences for the
persons concerned ...
33. Recital 143 refers to the entitlement to a judicial remedy.
Any natural or legal person has the right to bring an action for annulment of decisions
of the Board before the Court of Justice under the conditions provided for in Article
263 TFEU ... ... Without prejudice to this right under Article 263 TFEU, each natural
or legal person should have an effective judicial remedy before the competent national
court against a decision of a supervisory authority which produces legal effects
concerning that person. Such a decision concerns in particular the exercise of
investigative, corrective and authorisation powers by the supervisory authority or the
dismissal or rejection of complaints ... ... Proceedings against a supervisory authority
should be brought before the courts of the Member State where the supervisory
authority is established and should be conducted in accordance with that Member
State’s procedural law. Those courts should exercise full jurisdiction, which should
include jurisdiction to examine all questions of fact and law relevant to the dispute
before them. Where a complaint has been rejected or dismissed by a supervisory
authority, the complainant may bring proceedings before the courts in the same
Member State....
34. Article4 ofthe GDPR contains anumberofdefinitions relevant for thepurposeofthese
proceedings:
(1) ‘personal data’means any information relating to an identified or identifiable
natural person (‘data subject’); an identifiable natural person is one who can be
identified, directly or indirectly, in particular by reference to an identifier such as a
name, an identification number, location data, an online identifier or to one or more
factors specific to the physical, physiological, genetic, mental, economic, cultural or
social identity of that natural person; (2) ‘processing’ means any operation or set of operations which is performed on
personal data or on sets of personal data, whether or not by automated means, such as
collection, recording, organisation, structuring, storage, adaptation or alteration,
retrieval, consultation, use, disclosure by transmission, dissemination or otherwise
making available, alignment or combination, restriction, erasure or destruction;
...
(5) ‘pseudonymisation’ means the processing of personal data in such a manner
that the personal data can no longer be attributed to a specific data subject without the
use of additional information, provided that such additional information is kept
separately and is subject to technical and organisational measures to ensure that the
personal data are not attributed to an identified or identifiable natural person;
...
(7) ‘controller’means the natural or legal person, public authority, agency or other
body which, alone or jointly with others, determines the purposes and means of the
processing of personal data; where the purposes and means of such processing are
determined by Union or Member State law, the controller or the specific criteria for its
nomination may be provided for by Union or Member State law;
(8) ‘processor’means a natural or legal person, public authority, agency or other
body which processes personal data on behalf of the controller...
35. Article 5(1) of the GDPR sets out the principles which apply to all processing of
personal data: lawfulness, fairness, transparency, purpose limitation, data minimisation,
accuracy, storage limitation, and integrity and confidentiality.Article 5(2) provides that the
principle of accountability should apply to all of the foregoing, i.e. that a data processor
should be able to demonstrate compliance with all of the foregoing:
1. Personal data shall be:
a. processedlawfully, fairlyandin atransparent manner in relation to thedata
subject (‘lawfulness, fairness and transparency’); b. collected for specified, explicit and legitimate purposes and not further
processed in a manner that is incompatible with those purposes; further
processing for archiving purposes in the public interest, scientific or
historical research purposes or statistical purposes shall, in accordance
with Article 89(1), not be considered to be incompatible with the initial
purposes (‘purpose limitation’);
c. adequate, relevant and limited to what is necessary in relation to the
purposes for which they are processed (‘data minimisation’);
d. accurate and, where necessary, kept up to date; every reasonable step must
be taken to ensure that personal data that are inaccurate, having regard to
the purposes for which they are processed, are erased or rectified without
delay (‘accuracy’);
e. kept in a form which permits identification of data subjects for no longer
than is necessary for the purposes for which the personal data are
processed; personal data may be stored for longer periods insofar as the
personal data will be processed solely for archiving purposes in the public
interest, scientific or historical research purposes or statistical purposes in
accordance with Article 89(1) subject to implementation of the appropriate
technical and organisational measures required by this Regulation in order
to safeguard the rights and freedoms of the data subject (‘storage
limitation’);
f. processed in a manner that ensures appropriate security of the personal
data, including protection against unauthorised or unlawful processing and
against accidental loss, destruction or damage, using appropriate technical
or organisational measures (‘integrity and confidentiality’).
2. Thecontroller shall beresponsiblefor,andbeableto demonstrate compliancewith,
paragraph 1 (‘accountability’).
36. The requirement for accountability, or responsibility, is also found inArticle 24(1):
Taking into account the nature, scope, context and purposes of processing as well as
the risks of varying likelihood and severity for the rights and freedoms of natural
persons, the controller shall implement appropriate technical and organisational measures to ensure and to be able to demonstrate that processing is performed in
accordance with this Regulation. Those measures shall be reviewed and updated where
necessary.
37. Chapter V relates to the cross-border transfer of data, that is transfers outside the EEA.
The overriding requirement is that the rights guaranteed by the GDPR are not compromised
by any such transfer of personal data, that data is afforded an equivalent level of protection
in a third country as it would have within the EEA. Thus,Article 44 provides:
Any transfer of personal data which are undergoing processing or are intended for
processing after transfer to a third country or to an international organisation shall
take place only if, subject to the other provisions of this Regulation, the conditions laid
down in this Chapter are complied with by the controller and processor, including for
onward transfers of personal data from the third country or an international
organisation to another third country or to another international organisation. All
provisions in this Chapter shall be applied in order to ensure that the level of protection
of natural persons guaranteed by this Regulation is not undermined
38. Articles 45 and 46 provide alternative mechanisms for ensuring equivalent protection.
Article 45 provides for the making of adequacy decisions by the European Commission.
Where the Commission has determined that adequate protection is provided in a third
country, and makes a decision to that effect, then transfers to that country do not require
further authorisation.
39. Where, as here, there is no adequacy decision under Article 45, transfers are still
permitted without specific authorisation where the data processor satisfies the requirements
ofArticle 46:
1. Intheabsenceof a decisionpursuant to Article45(3),acontroller or processor may
transfer personal data to a third country or an international organisation only if the
controller or processor has provided appropriate safeguards, and on condition that
enforceable data subject rights and effective legal remedies for data subjects are
available. 2. The appropriate safeguards referred to in paragraph 1 may be provided for, without
requiring any specific authorisation from a supervisory authority, by:
a) a legally binding and enforceable instrument between public authorities or
bodies;
b) binding corporate rules in accordance with Article 47;
c) standard data protection clauses adopted by the Commission in accordance
with the examination procedure referred to in Article 93(2);
d) standard data protection clauses adopted by a supervisory authority and
approved by the Commission pursuant to the examination procedure referred to
in Article 93(2);
e) an approved code of conduct pursuant to Article 40 together with binding and
enforceable commitments of the controller or processor in the third country to
apply the appropriate safeguards, including as regards data subjects’rights; or
f) an approved certification mechanism pursuant to Article 42 together with
binding and enforceable commitments of the controller or processor in the third
country to apply the appropriate safeguards, including as regards data subjects’
rights.
40. Commission decisions under Article 45 and 46(2)(c) were the subject of the leading
cases in Case C-362/14, Schrems v DPC (“Schrems I”) and Case C-311/18, DPC v
Facebook Ireland (“Schrems II”).
41. Chapter VI of the GDPR deals, inter alia, with the decision-making functions of
supervisory authorities. Pursuant to Article 51, each member state is required to designate
at least one supervisory authority responsible for monitoring the application of the GDPR.
Article 56 sets out the competencies of a supervisory authority.Article 56(1) provides:
Without prejudice to Article 55, the supervisory authority of the main establishment or
of the single establishment of the controller or processor shall be competent to act as
leadsupervisoryauthorityforthecross-borderprocessingcarriedoutbythatcontroller
or processor in accordance with the procedure provided in Article 60.42. Article 60 sets out the co-operation procedure between supervising authorities when,
inter alia, investigating a complaint. Sub-articles 1 to 3 concern obligations in relation to
the sharing of information. These include, at sub-article 3, an obligation on a lead
supervising authority (“LSA”) to provide draft decisions to other supervisory authorities
concerned (“SACs”) for their opinion and to “take due account of their views”. Other SACs
may provide reasoned objections to any such draft decision. If agreement cannot be reached
on those objections, a consistency mechanism is provided at sub-article 4, whereby any
disagreement can be referred to the European Data Protection Board (“EDPB”) for
resolution.Adecision of the EDPB pursuant toArticle 65 of the GDPR is binding upon the
supervisory authorities. The EDPB is established by Article 68(1) of the GDPR as a union
body with legal personality. It is comprised of the heads of at least one supervisory authority
from each member state. If there are no reasoned objections, the LSA and SACs shall be
deemed to be in agreement with the draft decision and “shall be bound by it”.
43. Article 78 of the GDPR requires that member states provide effective remedies
regarding decisions of supervisory authorities:
1. Without prejudice to any other administrative or non-judicial remedy, each natural
or legal person shall have the right to an effective judicial remedy against a legally
binding decision of a supervisory authority concerning them.
2. Without prejudice to any other administrative or non-judicial remedy, each data
subject shall have the right to an effective judicial remedy where the supervisory
authority which is competent pursuant to Articles 55 and 56 does not handle a
complaint or does not inform the data subject within three months on the progress
or outcome of the complaint lodged pursuant to Article 77.
3. Proceedings against a supervisory authority shall be brought before the courts of
the Member State where the supervisory authority is established.
4. Where proceedings are brought against a decision of a supervisory authority which
was preceded by an opinion or a decision of the Board in the consistency
mechanism, the supervisory authority shall forward that opinion or decision to the
court.
44. Article 83 sets out the conditions for imposition of administrative fines:1. Each supervisory authority shall ensure that the imposition of administrative fines
pursuant to this Article in respect of infringements of this Regulation referred to in
paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and
dissuasive.
2. Administrative fines shall, depending on the circumstances of each individual case,
be imposed in addition to, or instead of, measures referred to in points (a) to (h)
and (j) of Article 58(2). When deciding whether to impose an administrative fine
and deciding on the amount of the administrative fine in each individual case due
regard shall be given to the following:
a. the nature, gravity and duration of the infringement taking into account the
nature scope or purpose of the processing concerned as well as the number
of data subjects affected and the level of damage suffered by them;
b. the intentional or negligent character of the infringement;
c. any action taken by the controller or processor to mitigate the damage
suffered by data subjects;
d. the degree of responsibility of the controller or processor taking into
account technical and organisational measures implemented by them
pursuant to Articles 25 and 32;
e. any relevant previous infringements by the controller or processor;
f. the degree of cooperation with the supervisory authority, in order to remedy
the infringement and mitigate the possible adverse effects of the
infringement;
g. the categories of personal data affected by the infringement;
h. the manner in which the infringement became known to the supervisory
authority, in particular whether, and if so to what extent, the controller or
processor notified the infringement;
i. where measures referred to in Article 58(2) have previously been ordered
against the controller or processor concerned with regard to the same
subject-matter, compliance with those measures;
j. adherence to approved codes of conduct pursuant to Article 40 or approved
certification mechanisms pursuant to Article 42; and
k. any other aggravating or mitigating factor applicable to the circumstances
of the case, such as financial benefits gained, or losses avoided, directly or
indirectly, from the infringement.3. If a controller or processor intentionally or negligently, for the same or linked
processing operations, infringes several provisions of this Regulation, the total
amount of the administrative fine shall not exceed the amount specified for the
gravest infringement.
4. …
5. Infringements of the following provisions shall, in accordance with paragraph 2, be
subject to administrative fines up to 20 000 000 EUR, or in the case of an
undertaking, up to 4 % of the total worldwide annual turnover of the preceding
financial year, whichever is higher:
a. the basic principles for processing, including conditions for consent,
pursuant to Articles 5, 6, 7 and 9;
b. the data subjects’rights pursuant to Articles 12 to 22;
c. the transfers of personal data to a recipient in a third country or an
international organisation pursuant to Articles 44 to 49;
d. any obligations pursuant to Member State law adopted under Chapter IX;
e. non-compliance with an order or a temporary or definitive limitation on
processing or the suspension of data flows by the supervisory authority
pursuant to Article 58(2) or failure to provide access in violation of Article
58(1).
6. Non-compliance with an order by the supervisory authority as referred to in Article
58(2) shall, in accordance with paragraph 2 of this Article, be subject to
administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to
4 % of the total worldwide annual turnover of the preceding financial year,
whichever is higher.
7. …
8. The exercise by the supervisory authority of its powers under this Article shall be
subject to appropriate procedural safeguards in accordance with Union and
Member State law, including effective judicial remedy and due process.
9. Where the legal system of the Member State does not provide for administrative
fines, this Article may be applied in such a manner that the fine is initiated by the
competent supervisory authority and imposed by competent national courts, while
ensuring that those legal remedies are effective and have an equivalent effect to the
2
administrative fines imposed by supervisory authorities. In any event, the fines
3
imposed shall be effective, proportionate and dissuasive. Those Member States shall notify to the Commission the provisions of their laws which they adopt
pursuant to this paragraph by 25 May 2018 and, without delay, any subsequent
amendment law or amendment affecting them.
Data ProtectionAct 2018
45. On the face of the Decision , it notes that the inquiry was commenced of the DPC’s own
volition pursuant to s. 110 of the 2018 Act. The decision itself was then made pursuant to
section 111 of same, and pursuant toArt 60 of the GDPR. Section 111 provides:
(1) Where an inquiry has been conducted of the Commission’s own volition, the
Commission, having considered the information obtained in the inquiry, shall—
(a) if satisfied that an infringement by the controller or processor to which the
inquiry relates has occurred or is occurring, make a decision to that effect, and
(b) if not so satisfied, make a decision to that effect.
(2) Where the Commission makes a decision under subsection (1)(a), it shall, in
addition, make a decision—
(a) as to whether a corrective power should be exercised in respect of the
controller or processor concerned, and
(b) where it decides to so exercise a corrective power, the corrective power that
is to be exercised.
(3) The Commission, where it makes a decision referred to in subsection (2)(b), shall
exercise the corrective power concerned.
46. Accordingly,wheretheDPCconcludesthattherehasbeenaninfringement,itisobliged
to consider whether to exercise a corrective power.
47. Regarding the draft decision which was circulated to the SACs, the Decision (at §5)
states that it was submitted to the SACs in accordance with Article 4(22) and 60(3) of the
GDPR.Adraft decision is provided for in section 113 of theAct:(1) This section applies to a complaint in respect of which the Commission is the lead
supervisory authority.
(2) Where section 109(4)(a) applies, the Commission shall—
(a) in accordance with subsection (3), make a draft decision in respect of the
complaint (or, as the case may be, part of the complaint) and, where applicable,
as to the envisaged action to be taken in relation to the controller or processor
concerned, and
(b) in accordance with Article 60 and, where appropriate, Article 65, adopt its
decision in respect of thecomplaint or,as thecasemaybe, part of thecomplaint.
(3) In making a draft decision under subsection (2)(a), the Commission shall, where
applicable, have regard to—
(a) the information obtained by the Commission in its examination of the
complaint, including, where an inquiry has been conducted in respect of the
complaint, the information obtained in the inquiry, and
(b) any draft for a decision that is submittedto the Commission by a supervisory
authority in accordance with Article 56(4).
(4) Where the Commission adopts a decision under subsection (2)(b) to the effect that
an infringement by the controller or processor concerned has occurred or is occurring,
it shall, in addition, make a decision—
(a) where an inquiry has been conducted in respect of the complaint—
(i) as to whether a corrective power should be exercised in respect of the
controller or processor concerned, and
(ii) where it decides to so exercise a corrective power, the corrective
power that is to be exercised,…
(5) The Commission, in making its decision under subsection (4), shall have due regard
to the decision as to the envisaged action to be taken in relation to the controller or
processor included in the Commission’s draft decision under subsection (2)(a) or, as
the case may be, its revised draft decision under Article 60. (6) The actions referred to in subsection (4)(b) include any or all of the following:
(a) the serving on the controller or processor concerned of an enforcement
notice, requiring it to do one or more than one of the following:
(i) comply with the data subject’s request to exercise his or her rights
pursuant to a relevant enactment;
(ii) where the enforcement notice is given to the controller, communicate
a personal data breach to the data subject;
(iii) rectify or erase personal data or restrict processing pursuant to
Article 16, 17 or 18, and, in respect of that action, to comply withArticle
19 and, where applicable, Article 17(2);
(aa) the issuing of a reprimand to the controller or processor concerned;]
(b)thetaking of such other actionin respect of the complaint as theCommission
considers appropriate.
(7) The Commission—
(a) where it makes a decision referred to in subsection (4)(a)(ii), shall exercise
the corrective power concerned, …
48. Notably, neither Article 60 of the GDPR, nor section 113 of the 2018 Act suggest that
there is any obligation to provide a draft decision to the parties to an inquiry.
49. Section 115(1) of theAct states:
(1) For the purposes of exercising a corrective power under section 111, 112 or 113, the
Commission may do either or both of the following:
(a) subject to Chapter 6, decide to impose an administrative fine on the
controller or processor concerned;
(b) exercise any other corrective power specified in Article 58(2).
(2) Without prejudice to the generality of subsection (1)(b), the Commission may, for
the purposes of exercising a power referred to in that provision, serve on the controller
or processor concerned an enforcement notice requiring it to take such steps as the
Commission considers necessary for those purposes.50. Enforcement notices are provided by section 133 of theAct:
(1) In this Part, “enforcement notice” means a notice in writing served in accordance
with subsection (2), subsection (3) or section 109(5)(d), 115(2), 122(4)(d) or 127(2),
on a controller or processor, requiring the controller or processor to take such steps as
are specified in the notice, within such time as may be so specified…
51. It seems that no enforcement notice was issued by the DPC following the Inquiry. The
Decision would appear to meet the requirements of an enforcement notice within the
meaning of section 115(2), a notice in writing requiring the taking of one of the corrective
measures set out in Article 58(2) of the GDPR. However, at the hearing of the appeal, the
court was advised by the DPC that it did not consider that the Decision should be treated as
an enforcement notice, the DPC apparently being of the view that an enforcement notice
would only issue if a requirement imposed by a decision was “not obeyed” (Transcript, Day
9, p 140, lines 3 -5). That does not appear to accord with the scheme of the 2018Act, but no
issue was taken by TikTok with the absence of an enforcement notice, so I do not need to
consider this issue further.
52. The relevant provisions of section 142 provide as follows:
(1) Without prejudice to section 150, a controller or processor that is the subject of a
decision under section 111, 112, 113 or 133(9) to impose an administrative fine may,
within 28 days from the date on which notice of the decision concerned was given to it
under section 116 or, as the case may be, section 133(9)(b) appeal to the court against
the decision.
(2) The court, on hearing an appeal under subsection (1), may consider any evidence
adduced or argument made by the controller or processor concerned, whether or not
already adduced or made to an authorised officer or the Commission.
(3) Subject to subsections (4) and (5), the court may, on the hearing of an appeal
under subsection (1)—
(a) confirm the decision the subject of the appeal,
(b) replace the decision with such other decision as the court considers just and
appropriate, including a decision to impose a different fine or no fine, or
(c) annul the decision ... 53. Finally, section 150 is in the following terms:
(1) A controller or processor on which an information notice or enforcement notice or
a notice under section 135(1) is served may, within 28 days from the date on which the
notice is served, appeal against a requirement specified in the notice.
(2) The court, on hearing an appeal under subsection (1), shall—
(a) annul the requirement concerned,
(b) substitute a different requirement for the requirement concerned, or
(c) dismiss the appeal.
(3) This subsection applies to an appeal brought under subsection (1)—
(a) against a requirement specified in an information notice to which section
132(3) applies, or an enforcement notice to which section 133(6) applies, and
(b) that is brought within the period specified in the notice concerned ...
The Inquiry
54. In the Decision, the DPC describes the TikTok platform as follows:
“36. The TikTok platform is a social media service allowing users to create and share
short-form videos of up to 10 minutes in length. It is available as an app for Android
and iOS, and via the website www.tiktok.com. TikTok accounts can be created by users
aged 13 years and over using a phone number and email address. A TikTok profile
typicallycontains a profilephoto or videoandusername.Theappshows apersonalised
‘For You’feed of videos for each user, recommended based on factors such as the user’s
selected interest categories, device and account settings, and interaction with the app.
Users can create, watch, ‘like’ and comment on videos, ‘follow’ other users’ profiles,
and send direct messages to other users.
37. The TikTok platform is understood to have more than 1 billion monthly active users
globally as of 27 September 2021. TikTok Ireland has informed the DPC that in May
2022, the TikTok platform had approximately 128 million monthly active users in the
EEA. TikTok also reports, pursuant to its obligation under Article 24(2) of the Digital Services Act, that it had on average 159 million monthly active recipients in the
European Union member state countries between July 2024 and December 2024.
38. TikTok Ireland has stated that the TikTok service is not offered or available in
China, where the ByteDance group of companies separately operates “a similar but
entirely distinct” video-sharing platform called Douyin…”
55. ByteDance Limited (“ByteDance”) is TikTok’s ultimate parent. Though it is registered
in the Cayman Islands, many of the ByteDance group of companies and its employees are
based in China.
56. For the purpose of these proceedings, it is not in dispute thatTikTok acts as a controller,
within themeaning ofArticle4(7)oftheGDPR in respect of thepersonal dataontheTikTok
platform, that it has its main establishment in Ireland, that it engages in the cross-border
processing of data and that the DPC is the competent authority to act as LSA for the cross-
border processing of data the subject of the Inquiry in accordance with the procedure set
down inArticle 60 of the GDPR.
57. As appears from the Decision, during the course of its supervision interactions with
TikTok, the DPC was informed by TikTok that certain personnel located in China accessed
personal data of TikTok’s EEAusers in order to provide support services in connection with
the operation of its platform, including functions related to software engineering,
maintenance and development. On 26 March 2021, TikTok provided the DPC with its data
transfer assessment (“DTA”) for China, an assessment of the level of protection afforded to
data transferred to China, together with supporting documentation. This DTAidentified that
that there was a divergence between the level of protection afforded to personal data in
China from that afforded within the EU, but concluded that, in light of standard contractual
clauses together with supplementary measures employed by TikTok, personal data
transferred to China was afforded essentially equivalent levels of protection to that
guaranteed within the EU. The DTA was updated four times throughout the Inquiry. Each
DTAreached the same overall conclusion. The five DTAs are addressed together in the next
section of this judgment.58. On 7 April 2021, the DPC received a submission from Stichting Onderzoek
Marktinformatie, a Dutch non-governmental organisation, raising concerns about the
processing of personal data by TikTok, due to risks for young users, and the non-EEA
transfer of personal data.
59. On 28 May 2021 and 5 July 2021, the DPC received requests for mutual assistance
from the French supervisory authority, Commission Nationale de l’Informatique et des
Libertés, requesting that the DPC investigate matters pertaining to TikTok’s transfer of
personal data to China.
60. On14September2021,theDPCnotifiedTikTokofthecommencementoftwoinquiries
pursuant to section 110 of the Data ProtectionAct 2018 (so-called “own volition” inquiries),
including the inquiry which led to the decision the subject of these proceedings (“the Notice
of Commencement” or “the Notice”).
61. The Notice of Commencement explained the background to the Inquiry and the legal
basis for it. It identified that the Inquiry would focus on three specific issues as follows:
Issue 1:
With regard to TikTok’s analysis of China’s laws and practices that impact data
protection of EEA users, what specific issues did it identify that indicated that Chinese
laws and practices do not provide protection essentially equivalent to that in the EU
and that would require TikTok to implement supplementary measures?
Issue 2:
Concerning GDPR Chapter V whether TikTok can demonstrate it has fulfilled its
Chapter V obligations with regard to transfers of personal data in terms of the
effectiveness and/or appropriateness of the supplementary measures applied to
personal data transfers to China. Can TikTok demonstrate how the supplementary
measures specifically overcome the deficits in protection identified in terms of the laws
and practices of China to provide a level of protection essentially equivalent to the one
guaranteed in the EEA?
Issue 3: Concerning GDPR Article 13(1)(f) whether TikTok can demonstrate that it has fulfilled
its obligations with regard to provision of information to its users in relation to
transfers of personal data to China.
62. The notice also set out the procedure which would be followed by the DPC in the
Inquiry, highlighting the fact that it would be subject to the provisions of Article 60 of the
GDPR. It noted that following its information gathering it would prepare a “Draft Decision”
for the purpose of the Article 60 process. The notice stated that the “Draft Decision will be
furnished to TikTok for its consideration and submissions before it is submitted to theArticle
60 process.” As appears from the following, the DPC did not, in fact, adopt the precise
procedure mapped out in the Notice.
63. Attached as an appendix to the Notice of Commencement was a request for information
(“the first RFI”) containing five questions regarding the “data transfers”.
64. TikTok responded to the Notice of Commencement and the first RFI on 12 October
2021. The response included an updated DTA. A further updated DTA was provided on 28
January 2022. Each reached similar conclusions in relation to the personal data being
transferred to China.
65. On 11 May 2022, the DPC requested further information from TikTok (“the second
RFI”). This request was far more detailed than the first RFI and raised queries under the
headings ‘General’, ‘Remote Access by the China Group Entities’, ‘Intra-Group Agreement
and the 2010 SCCs’, ‘Article 49 Derogations’, and ‘Analysis of Chinese Legal Framework
in the Data Transfer Assessment’.
66. The first question posed under the ‘Remote Access’heading was the following:
Please further clarify the circumstances and in particular the technical means by which
personal data is remotely accessed by personnel of the China Group Entities, referring
to or further clarifying the information set in the Data Transfer Assessment and TikTok
Ireland’s Response dated 12 October 2021 (in particular pages 16 to 17, paragraphs
12.8 to 12. 9 of same, as appropriate).67. Under the last heading, ‘Analysis of Chinese legal framework in the Data Transfer
Assessment’, the DPC raised the following query (Query V(3)) :
Please further clarify the factual and legal basis for TikTok Ireland’s position that
problematic laws and practices in China are not at risk of being applied to the transfers
the subject of the Inquiry in circumstances where the personal data of EEA users is
stored outside of the territory of China, but is processed by the China Group Entities
within the territory of China.
* emphasis in original
68. Having sought an extension of time to provide a response, TikTok responded on 20
June 2022 on a query-by-query basis to the questions raised. Its response to the query about
the technical means by which personal data is remotely accessed detailed the access
restrictions imposed but did not explain what was actually happening when data was
transferred. Its response to Query V(3) was as follows:
Chinese authorities do not have the power to compel disclosure of the remotely
accessible EEA User Data, have not made any such requests and, in the extremely
unlikely event that such request was made, the China Group Entities would be entitled
to refuse it. Accordingly, the China Group Entities are in a position to comply with the
2010 SCCs. This is explained further below…
69. The response then further explained the territoriality principle on which TikTok relies.
70. On 7 July 2022, the DPC provided TikTok with a detailed Statement of Issues and
invited submissions on same. The issues for determination were summarised as follows:
(1) The DPC will consider and determine, within the scope of the Inquiry, the relevant
facts as to TikTok Ireland’s reliance on the 2010 SCCs in connection with the transfers
the subject of the Inquiry involving remote access to personal data of EEA users by the
China Group Entities.
(2) The DPC will consider and determine, within the scope of the Inquiry, the relevant
facts as to the scope of TikTok Ireland’s reliance, if any, on the derogations set out in Article 49 GDPR, and in particular Article 49(1)(b) GDPR, and, if necessary, review
and determine the lawfulness of same in the context of the transfers the subject of the
Inquiry.
(3)TheDPCwillconsideranddeterminewithinthescopeoftheInquirywhetherTikTok
Ireland can demonstrate that it has complied with its responsibility to assess the level
of protection of personal data of EEA users the subject of transfers to the China Group
Entities using SCCs under Article 46(2)(c) GDPR for the purpose of Articles 44 and
46(1) GDPR, having regard in particular to TikTok Ireland’s responsibility as a
controller in light of Article 5(2) and 24 GDPR. This will include consideration as to
whether TikTok Ireland has adequately assessed whether, and the extent to which, there
is a risk that the personal data of EEA users remotely accessed by the China Group
Entities may be subject to potentially problematic laws and practices in effect in China,
and whether, and extent to which, there is a risk that the 2010 SCCs are not being
complied with, or cannot be complied with, by the China Group Entities in the context
of the transfers the subject of the Inquiry.
(4) The DPC will consider and determine, within the scope of in the Inquiry, whether
TikTok Ireland can demonstrate that the supplementary measures implemented by
TikTok Ireland and the China Group Entities in respect of the remote access by the
China Group Entities to personal data of EEA users are effective, together with the
2010 SCCs, to ensure that EEA users are provided with the appropriate safeguards,
enforceable rights and effective legal remedies required by Articles 44, 46(1) and
46(2)(c) GDPR, so that the personal data of EEA users is afforded a level of protection
essentially equivalent to that guaranteed within EU by the GDPR.
(5) The DPC will consider and determine whether TikTok Ireland has complied with its
obligations under Article 13(1)(f) GDPR with reference to the information it provides
to EEA users of the TikTok platform concerning the transfers the subject of the Inquiry.
71. When furnishing the Statement of Issues, the DPC indicated that in respect of the
second issue, it intended having regard to information on government access to personal
data in China set out in the “Final Report EDPS/2019/02-13, Legal study on Government
access to data in third countries for the EDPB (November 2021)” (“the Milieu Report”).It seems clear that the question of public authority access to data transferred by TikTok to
China was becoming the focus of the Inquiry.
72. TikTok raised certain queries on the Statement of Issues and responded in substance on
15 September 2022. TikTok notified the DPC of its intention to submit expert evidence in
relation to the Milieu Report. It also informed DPC that it was in the process of updating its
DTA for China and expected to complete this by 13 October 2022. It also stated that it was
in the process of updating its EEAprivacy policy, and that it would shortly be amending its
Intra-GroupAgreement for the purpose of transitioning from the 2010 standard contractual
clauses (“the 2010 SCCs”) to the new SCCs (“the 2021 SCCs”), and that this would be
done by 27 December 2022. TikTok also queried the temporal scope of the Inquiry and were
advised it was “ongoing”. The substantive response identified a number of “procedural
issues”, including querying whether the DPC was involved in further fact finding. In a
response dated 3 October 2022, the DPC appeared to indicate, by reference to an earlier
letter dated 25 July 2022, that fact-finding was not complete.
73. On 13 October 2022, TikTok provided the DPC with an expert opinion on Chinese law,
addressing the MilieuReport,from Professor Ke Xu,AssociateProfessor ofLaw of the Law
School, University of International Business and Economics, Beijing (“the first Xu
opinion”). It also provided an update to the DTA (“the October 2022 DTA”). It provided
its updated privacy policy on 22 October 2022, and information on the 2021 SCCs in
December 2022.
74. The DPC sent a request for further information on 21 February 2023, raising queries
regarding the 2021 SCCs (“the third RFI”).
75. When responding to this request on 28 March 2023, TikTok provided information on
further measures it was putting in place, referred to as Project Clover, to ensure the
protection of EEAuser data. It advised that the measures comprising Project Clover were at
anadvancedstageofdesignandimplementationhadalreadycommenced. Noclearevidence
of implementation of any particular measure within the temporal scope has ever been
provided by TikTok and in the circumstances, I have treated the Project Clover measures as
having been implemented outside the temporal scope of the Inquiry.76. The DPC raised queries about the turnover of TikTok’s parent company, ByteDance, in
April 2023. On 17 May 2023, it issued a Preliminary Draft Decision (“the PDD”).The PDD
defined the temporal scope of the Inquiry as commencing on 29 July 2020 and ongoing.
77. In relation to Issue 1 (of the Statement of Issues), the PDD identified the following facts
which it proposed to have regard to as established for the purpose of the Inquiry (at §165):
165.1. I am satisfied that the remote access by personnel of the China Group entities to
personal data of EEA users of the TikTok platform stored on servers in Singapore and
the Unities States is a “transfer” of personal data for the purposes of Chapter V of the
GDPR. This not disputed and is supported by the Supplementary Measures
Recommendations.
165.2. I note, in that regard, that the position under the 2010 SCCs was, and under the
2021 SCCs remains, that EEA user data is stored on servers located in Singapore and
the US, and is not itself stored on servers in China.
165.3. I am also satisfied that from 29 July 2020 to 19 December 2022, the transfers
were made pursuant to the 2020 Intragroup Agreement implementing the 2010 SCCs,
and from 19 December 2022 to date, the transfers were made pursuant to the 2022
Intragroup Agreement implementing the 2021 SCCs.
165.4. The situation under the 2010 SCCs was that transfers were made directly by
TikTok Ireland as controller to 26 China Group Entities acting as processors until 13
October 2022, and to 16 China Group Entities acting as processors thereafter. Under
the 2021 SCCs, the transfers are made directly, in the first instance, to one of the China
Group Entities acting as processor, and then onward to one or more of the 15 other
China Group Entities acting as subprocessors. The processing may engage one or more
of multiple processors located in China.
165.5. Ihavehad regard to thecircumstances of the remoteaccess as outlinedbyTikTok
Ireland under both the 2010 SCCs and the 2021 SCCs. Both the factual description of
the remote access, and the information furnished in respect of the nature of the
processing lead me to believe that the transfers are regular, systematic, and frequent. The transfers are made for a large and complex range of tasks and functions performed
by the China Group Entities that appear essential to the operation of the TikTok
platform. When remote access is authorised for a specific business purpose, it is in
general authorised for up to 12 months, a considerable length of time.
165.6. The purposes for which the transfers were made under the 2010 SCCs, and the
2021 SCCs are extensive, and the categories of personal data, and, indeed, the volume
of personal data in terms of individual data points relating to each user that may be the
subject of the processing are very significant in number. This must be viewed relative to
the act that TikTok is a popular and widely used platform with approximately 128
million users in the EEA as of May 2022.
165.7. The personal data of EEA users may be accessed remotely by the China Group
Entities may include sensitive data (aligning broadly to the concept of personal data
that may fall within Articles 9 and 10 of the GDPR). It may also include, based on a
demonstrated business need, personal data in decrypted or plaintext form.
165.8. At present, based on TikTok Ireland’s submissions, I am not led to form the view
thatpersonaldataofEEAusersoftheTikTokplatformwithotherByteDancecompanies
in China for use in other ByteDance products (such as Toutiao and Douyin).
78. The final paragraph should, it seems, include the words “is being shared” after the
words “users of the TikTok platform”, i.e. the DPC formed the view that EEA user data is
not shared for use in ByteDance Chinese platforms.
79. In its analysis of Issue 2, the PDD commented as follows in relation to the information
provided by TikTok in relation to Chinese law (at §210):
Inlight of theabove, Ihave considered the manner in whichI shouldassessinformation
furnished by TikTok Ireland relating to the content, meaning or effect of Chinese law in
the context of this PDD. Where TikTok Ireland has confirmed that the legal analysis in
Section 2 of the Data Transfer Assessments was “prepared by one of China’s leading
independent law firms”, I have taken the information set out in the PDD at its height,
and at face value, with regard to its veracity. However, in the context of the Inquiry, I am obliged to ensure that I am satisfied that there is sufficient information and evidence
to enable me to review and verify TikTok Ireland’s assessment, and ultimately to
conclude that the personal data of EEA users is afforded appropriate safeguards in the
context of transfers to China the subject of the Inquiry. A failure on TikTok Ireland’s
part to verify, guarantee and demonstrate adequate protection would render the data
transfers unlawful.
80. The PDD identified that notwithstanding TikTok’s analysis of the territoriality
principle, there remained “two key concerns” which were set out at §254 – §257 of the PDD.
Given the centrality of these paragraphs to TikTok’s appeal, it is appropriate to set these
paragraphs out in full:
253. I have had due regard to the above submissions, in particular with regard to the
effect of the territorial principle in Chinese law. While I note TikTok Ireland’s analysis
in this regard, I nonetheless remain with two key concerns.
254. The first concern takes as its premise that TikTok Ireland’s analysis of the
application of the territoriality principle in Chinese law in the specific factual context
is fully correct. The concern relates to those laws such as the Anti Terrorism Law,
Counter-Espionage Law, Cybersecurity Law or the National Intelligence Law that may
be interpreted to have extra-territorial effect, to the extent that activities within their
scope constitute a crime under either that legislation itself, or the Criminal Law. I note
TikTok Ireland’s acknowledgement that, insofar as aspects of their application are not
as clear and precise as required by the EU standard, these laws would not comply with
the requirements for necessity and proportionality required by EU law. As such, these
laws, are, in my view, problematic, and although TikTok Ireland has submitted that this
could only arise in practice in rare or exceptional cases, it does not dispute the risk that
they may apply exterritorialy to enable Chinese authorities to exercise jurisdiction
under Chinese law to request disclosure of personal data of EEA users the subject of
the transfers and remote access by the China Group Entity. For example, Article 10 of
the National Intelligence Law expressly provides for intelligence activities both within
and outside of China. The second concern relates to the basis for the premise that
TikTok Ireland’s analysis regarding the application of the territoriality principle in the
specific factual context of the transfers is accurate. The concern itself is that TikTokIreland has furnished insufficient information in the Inquiry to enable me to conclude
that the territoriality principle does in fact operate so as to prevent the application of
problematic surveillance laws, such as the Anti-Terrorism Law, Counter-Espionage
Law, Cybersecurity Law and National Intelligence Law, to the personal data of EEA
users the subject of the transfers, save in situations where those laws have extra-
territorial effect. This leads to the conclusion that TikTok Ireland has itself failed to
verify, guarantee and demonstrate the adequacy of the protection in respect of the Data
Transfers.
255. In this regard, having reviewed the Data Transfer Assessments, I do not consider
that TikTok Ireland has demonstrated the basis for its conclusion that those laws, which
clearly have effect within the territory of China, could not be used to compel the China
Group Entities or their employees (who are persons within the territory of China and
the jurisdiction of the Chinese authorities) to provide assistance in accessing or
disclosing personal data stored in the territory of foreign States but remotely accessed
within the territory of China.
256. In particular, I do not agree that it has been sufficiently demonstrated how the
China Group Entities, or their employees, who are personally within the jurisdiction of
China and the Chinese authorities, would fall outside of the scope of laws such as the
Anti-Terrorism Law, Counter-Espionage Law, Cybersecurity Law and National
Intelligence Law which appear to provide for broadly defined obligations on persons
within the jurisdiction of China to assist with the work of its surveillance authorities.
In short, it is not clearly explained why it would not be open to the Chinese authorities
to impose obligations on the employees of the China Group Entities, who are able to
access the personal data contained on servers in the US and Singapore from China, to
provide the Chinese authorities with such data.
257. I consider, further, that TikTok Ireland’s submissions, and Data Transfer
Assessments, are vague in describing the exact contours of the territoriality principle.
Although it is described as a fundamental norm of Chinese law and various provisions
of the PRC Constitution and other legal measures are referenced in support of its
existence, the text of these provisions do not, in my view, sufficiently delineate the
contours of this principle to enable me to be satisfied of the manner of its application to the laws and practices outlined by TikTok Ireland in Section 2.2 of the Data Transfer
Assessment. Further, I note that TikTok Ireland does not refer to legal authorities that
interpret this principle in practice in a scenario that is analogous to the present one,
concerning remote access, using technical means, by persons within the jurisdiction of
China to data stored on servers in a foreign jurisdiction.
81. These concerns led the DPC to form the provisional view on Issue 2 that TikTok had
failed to “verify, guarantee and demonstrate” that the level of protection was essentially
equivalent to that provided by EU law (at §299.3 of the PDD).
82. These concerns also informed the DPC’s analysis of Issue 3. The DPC’s preliminary
views in respect of that issue are set out at §368 - §371
368. The supplementary measures are not effective in addressing the risk that Chinese
authoritiescouldimposeobligations ontheemployees of theChinaGroupEntities, who
are able to access the personal data contained on servers in the US and Singapore from
China, to provide the Chinese authorities with such data. The system entry controls and
Network Security measures, while reflective of general security, cannot act to prevent
access under problematic laws. Encryption of the EEA user data in transit, along with
the storage of the master keys outside of China, does not address the risk of Chinese
authorities accessing the personal data that is accessed in by employees of the China
Group Entities in plain text. TikTok Ireland has set out a broad range of purposes for
which personal data is accessed remotely in plain text. TikTok Ireland has also set out
the broad nature of what this processing entails. This Preliminary Draft Decision sets
out how these transfers in plain text are systematic, repetitive, and continuous.
Therefore, I consider that the encryption measures implemented do not compensate for
the lack of essentially equivalent protection outlined above in light of the data that is
accessed in plain text. While the physical separation is good practice in terms of a
security measure, this does not address the issue of the risk of Chinese authorities
imposing obligations on the employees of the China Group Entities in respect of the
personal data accessed in plain text. This personal data may be subject to such access
irrespective of whether it was originally encrypted at rest. Furthermore, in any event,
theMasterkeysbeingstoredoutsideofChina,naturally,doesnotpreventremoteaccess
to them from China.369. The contractual measures are merely contractual in nature and are not binding on
public authorities in China. Furthermore, in respect of the contractual provisions
regarding the obligation to notify TikTok Ireland, while TikTok Ireland has outlined the
situations in which the public authorities of China may impose confidentiality
obligations or may request a disclosure request be kept confidential by the person or
entity that is the recipient of the request, it has failed to assess how these aspects of
Chinese law affect the suitability of the contractual measures as supplementary
measures in terms of compensating for the lack of essentially equivalent protection. By
failing to clarify these issues in its assessments, TikTok Ireland has failed to comply
with its responsibility to adequately assess the level of protection of EEA users under
the Chinese legal framework for the purpose of Articles 44 and 46 GDPR, and, further,
has failed to comply with its obligation to demonstrate its compliance with Articles 44
and 46 of the GDPR with regard to the processing the subject matter of the transfers.
370. The access controls, in light of the broad nature of the purposes for which the
personal data is remotely accessed, and the systematic, repetitive, and continuous
nature of the transfers, are of limited utility in terms of compensating for the lack of
essentially equivalent protection. These access controls do not address the potential for
Chinese authorities to impose obligations on the employees of the China Group
Entities, who access the data for broad purposes, to provide the Chinese authorities
with such data. Therefore, they so [sic] not compensate for the lack of essentially
equivalent protection outlined above.
371. TikTok Ireland’s assessments failed to verify, guarantee, and demonstrate that the
supplemental measures or the SCCs address the identified risks associated with the
transferred data falling the subject to laws in China, such as the Anti-Terrorism Law,
Counter-Espionage Law, Cybersecurity Law or the National Intelligence Law. I
provisionally find that TikTok Ireland has failed to verify, guarantee and demonstrate
that the supplementary measures and the SCCs are effective to ensure that the personal
data of EEA users is afforded a level of protection essentially equivalent to that
guaranteed within the EU. Therefore, in light of the analysis above, I provisionally find
that TikTok Ireland’s has failed to provide appropriate safeguards in respect of the data
transfers and its reliance on Article 46 GDPR for the data transfers is invalid.83. The DPC also made preliminary findings in relation to Article 49 of the GDPR which
are not necessary to consider for the purposes of these proceedings. Taking the preliminary
findings in relation to Issues 1 to 4 together, the DPC made the following “provisional
finding of infringement” (at §398):
[T]hat TikTok Ireland had infringed Article 46(1) GDPR regarding the Data Transfers
by failing to verify, guarantee and demonstrate that the supplementary measures and
the SCCs are effective to ensure that the personal data of EEA user is afforded a level
of protection essentially equivalent to that guaranteed within the EU”.
84. In relation to Issue 5, the question of whether TikTok had complied with its obligations
under Article 13(1)(f) of the GDPR, the DPC formed the preliminary view that TikTok’s
October 2021 Privacy Policy failed to comply with the requirements ofArticle 13(1)(f). Its
updated December 2022 policy was assessed as compliant (see §432 of the PDD).
85. In light of those preliminary views and findings, the DPC provisionally decided (i) to
make an order pursuant to Article 58(2)(j) requiring TikTok Ireland to suspend the Data
Transfers, (ii) to make an order pursuant toArticle 58(2)(d) GDPR requiring TikTok Ireland
to bring the processing into compliance in the manner specified in the PDD, and (iii) to
impose two administrative fines pursuant to Article 58(2)(i) GDPR in the ranges of €450 -
€500 million and €30 - €50 million respectively (see §437 of the PDD).
86. TikTok made submissions on the PDD on 8 September 2023. It provided a second
opinion from Professor Xu (“the second Xu opinion”), reports from two law firms, Fangda
and Clifford Chance, a technical report on Project Clover (“the Project Clover Technical
Report”) and a report from NCC Group regarding the Project Clover measures. The Project
Clover measures are described below.
87. On 29 September 2023, TikTok provided a report from Dr Prateek Mittal concerning
TikTok’s privacy solution (“the Mittal report”). Dr Mittal is Professor in the Department
of Electrical and Computer Engineering at Princeton University. He is also an affiliated
faculty at Princeton University’s Center for Information Technology Policy, Andlinger
Center for Energy and the Environment, and the Department of Computer Science. Hisreportnotesthathehaspublishedover100 papersatpeer-reviewedconferencesandjournals
in the field of privacy and security.
88. The Mittal report concluded as follows:
By virtue of the mathematical guarantees provided by TikTok’s Differential Privacy
Solution, an adversary would not be able to determine with a reliable level of
confidence (through any possible means either currently available or devised in the
future and using any other internal or external data either currently available or
obtainable in the future), any incremental information about any attribute of any single
individual (or even the presence of any single individual) from Differentially Private
Aggregated Data. This results in Differentially Private Aggregate Data that are
effectively anonymous, in line with the GDPR, for individual personnel working for the
CGEs (or their employee groups).
89. TikTok provided an updated DTAon 6 October 2023 (“the October 2023 DTA”).
90. In its written response to the PDD, TikTok made the following submission which now
forms one of the central planks of its appeal (at §13):
Forthereasons explained in Sections IVandSectionVI,Part Bof this Response,TikTok
submits that the manner in which the issues have been drawn by the DPC does not
accord with the judgment of the CJEU in Schrems II. Specifically, insofar as the DPC
contends that TikTok has failed to adequately assess whether, and the extent to which,
the SCCs are not being complied with and/or cannot be complied with by the China
Group Entities in the context of the Data Transfers, it is incumbent on the DPC to
investigate and carry out this assessment itself by reference to the relevant provisions
of Chinese law and having regard to the circumstances of the Data Transfers. A
suspension order can be made only if the DPC, having carried out this assessment,
makes a finding that: (i) potentially problematic laws and practices in China have the
effect that the China Group Entities cannot comply (or are not complying) with the
SCCs, and (ii) the protection of the EEA User Data transferred that is required by EU
law cannot be ensured by other means.91. As indicated, this submission was elaborated on at sections IV and VI of the response
document and was reflected to a significant degree in the submissions made in this appeal.
Notwithstanding that the Notice of Commencement had requested that TikTok demonstrate
totheDPCthatthetransferreddatawas affordedequivalentprotectioninChina,thisappears
to have been the first occasion where TikTok suggests, in effect, that it was under no
obligation to do so.
92. On 8 February 2024, the DPC wrote to TikTok seeking clarification on matters arising
from TikTok’s response to the PDD, including whether remote access by personnel in China
involved storage of EEA user data in China, including temporary storage. The requests for
clarification were not described as a request for further information, but this letter was
characterised by TikTok as the fourth RFI at the hearing. Though the DPC pointed out that
it was not so described, it accepted that this had no legal significance. I will, accordingly,
refer to it as the fourth RFI in this judgment. The covering letter stated:
Since the commencement of this Inquiry, TikTok Ireland has been consistent in its
position that EEA User data is not stored on servers in the People’s Republic of China
(‘China’). However, as I understand it, TikTok Ireland’s response to the Preliminary
Draft Decision represents the first instance in which TikTok Ireland has claimed that no
storage of any kind, including temporary storage, of EEA User Data occurs in China.
During the Inquiry, TikTok Ireland outlined the circumstances in which the China
Group Entities obtain remote access to EEA User Data stored in the Global Data
Centres. In this regard, TikTok Ireland has outlined to the Inquiry that there is remote
access through applications and other measures that enable the foreign State servers
to be accessed from China. For the purpose of confirming whether that remote access
results in the storage of EEA User Data in China, including temporary storage, please
respond to the queries set out in the Schedule to this letter…
93. The suggestion in the letter that the response to the PDD was the first time that TikTok
had claimed that there was no storage of any kind, including temporary storage in China
seems to have been an inference drawn by the DPC from the response.There is no reference
to temporary storage in the response to the PDD, though TikTok does state that no EEAuser
data is stored on servers in China.94. The issues raised in the schedule to the letter were as follows:
1. Please describe in detail the manner in which computer information systems and
devices within the territory of China enable the China Group Entities to obtain remote
access to EEA User Data. This description must outline:
(i) The technological operations deployed on those computer information systems and
devices that enable personnel within the China Group Entities to interact with EEA
User Data;
(ii) The technical solution used to provide such interaction, including a description of
the physical location of the technical architecture (such as multi-tier, client- server
models) and the interaction with any ICT security layers that protect information in
transit between the servers and the presentation layers (to include the location of
physical gateway devices on the transport layer and how those interact with any VPN
tunnelling);
(iii) Any permanent or temporary storage of EEA User Data that occurs on computer
information systems and devices including within the territory of China, including, but
not limited to storage or processing by means of any Central Processing Unit, Main
Memory, Random Access Memory, Secondary Storage or any other element of the
computer information systems, networks, and devices located in China;
(iv) Any processing, as defined in Article 4(2) GDPR, of EEA User Data that occurs on
computer information systems and devices within the territory of China;
(v) The means by which TikTok Ireland shares information with personnel within the
China Group Entities, and the means by which that data and how that data is made
available for those personnel; and
(vi) The applications and other measures that enable the foreign State servers to be
accessed from China.
2. If it is the case that the China Group Entities obtain remote access to EEA User Data
without any EEA User Data being stored temporarily or permanently on computer
information systems and devices in China, please outline the technical means by which
personnel within the China Group Entities can view and interact with that data without
any temporary or permanent storage occurring in China.95. At the hearing, the DPC characterised this letter as a repeated request for information
which had been sought previously, in particular in the second RFI, but not provided.
Although in its response TikTok contended that this was the first time such information was
sought, in my view, the DPC’s characterisation is reasonable. The second RFI had asked for
details of the technical processes involved in the remote access and this had not been
provided.
96. In its response, dated 11 March 2024, TikTok confirmed that personal data was
temporarily processed in China, and that this involved a transfer of data for the purpose of
Chapter V of the GDPR. It suggested that this local processing was “implicit in any remote
access solution.” The precise details of the technical measures described will be addressed
below.
97. The response also stated, in apparent response to the DPC’s second query:
Second, TikTok does not consider that the use of the Remote Access Solution results in
any “storage” of EEA User Data in China. In particular, TikTok does not consider that
the processing carried out in China in connection with the Remote Access Solution is
storage or a storage solution. This is because that processing does not, using the
conventional meaning of “storage”, provide a location for data when it is not being
used, so that it can be later retrieved for any purpose.
98. This passage included a footnote in which English-language dictionary definitions of
the word “storage” were provided.
99. In the response, TikTok sought confirmation that the DPC would have regard to the
materially new information provided by it since the PDD. It requested that the DPC
withdraw the PDD and issue a revised PDD in light of the new measures which TikTok had
put in place. In a letter dated 18 April 2024, TikTok suggested that an in-person meeting to
discuss Project Clover would be the “optimal format” to explain its technical features and
implementation and any other queries arising.
100.TikTok repeated the request for a revised PDD in letters dated 14 June 2024, 28 June
2024, 2 October 2024 and 6 December 2024, stating that fair procedures required that it beafforded an opportunity to respond to the DPC’s preliminary views of its response to the
PDD before a draft decision was submitted to theArticle 60 process.
101.Although the DPC confirmed, in a letter dated 21 June 2024, that it would have regard
to all information provided when makingits draftdecision(as previously advisedin its letter
of 15 April 2024), it declined to withdraw the PDD, stating that it considered this to be
unnecessary. The letter stated that “during the course of the DPC’s consideration of TikTok
Ireland’s latest submissions, if any issue requiring clarification or further submissions
arises, the DPC will inform TikTok Ireland of same.” Despite TikTok’s requests, there was
never any in-person meeting between TikTok and representatives of the DPC regarding the
issues the subject of the Inquiry.
102.On 31 July 2024, TikTok provided the DPC with a further revision to its DTA (“the
July 2024 DTA”). This is the most up-to-date DTAso far provided by TikTok. The relevant
contents of this DTAare detailed below.
103.On 6 December 2024, TikTok advised the DPC that it had updated its Intra-Group
Agreement to reflect changes in the processing of data in China. On 14 February 2025, it
indicated that it intended to provide updates on the further implementation of Project Clover
by 10 March 2025.
104.On 21 February 2025, the DPC informed TikTok that it had finalised a draft decision
(“the Draft Decision”) and circulated it to the SACs pursuant to Article 60 of the GDPR.
As stated in the Decision (at §95):
“Given that thematters under examinationin theinquiryentail cross-border processing
across Europe, all other supervisory authorities were engaged as SACs for the purpose
of the co-decision-making process outlined in Article 60 of the GDPR.”
105.Article 60(4) of the GDPR provides that SACs may express reasoned objections within
four weeks of having been consulted. The consultation period, therefore, ran until 21 March
2025.106.The DPC provided TikTok with a copy of the Draft Decision. The temporal scope of
the Inquiry pursuant to the Draft Decision was stated to be from 29 July 2020 to 17 May
2023, which was the date of the PDD.
107.The Draft Decision contained findings on each of the five issues identified in the
Statement of Issues. For present purposes, the findings in the Draft Decision are mirrored in
the Decision and are set out when dealing with the Decision.
108.On 14 March 2025, TikTok requested that the DPC withdraw the Draft Decision,
alleging fundamental errors of fact and breaches of fair procedures. In particular, it alleged
thattheDPChaderredinconcludingthatTikTokhadnotassessedtheapplicationofChinese
laws to what it called “temporary data”:
As the processing of the Temporary Data is, as noted by the DPC, an inevitable part of
remote access, TikTok Ireland’s assessment of Chinese law and the territoriality
principle necessarily considered their application to the Temporary Data. Therefore,
contrary to the DPC’s assertions, TikTok Ireland’s assessment did consider that, as part
of Remote Access, data is transferred to China for temporary processing.
109.The letter stated that the position had been “put beyond doubt” by footnote 113 of the
July 2024 DTA. The letter also alleged various breaches of fair procedures and contended
thattherewasnobasisformakingasuspensionorderwhenthetemporalscopeoftheInquiry
concluded on 17 May 2023.
110.On 18 March 2025, still within the consultation period with the SACs, TikTok provided
a third opinion from Professor Xu (“the third Xu opinion”) to address a purported gap in
TikTok’s assessment of Chinese law which TikTok contended had been identified for the
first time in the Draft Decision.
111.By letter dated 25 March 2025, the DPC refused the request to withdraw the Draft
Decision, rejecting the claims of fundamental error and breach of fair procedures. In
rejecting TikTok’s contention that the processing of data in China had been addressed all
along because it was an inevitable feature of the remote access solution, the DPC stated: TikTok Ireland’s subsequent correspondence that contends that these matters were
addressed all along does not retrospectively remedy this failure to verify, guarantee and
demonstrate an essentially equivalent level of protection. Furthermore, even
considering TikTok Ireland’s most recent correspondence in the context of the ongoing
transfers, it is clear that fundamental flaws identified in the Draft Decision remain
unaddressed and ongoing.
112.The letter invited submissions from TikTok on the administrative fines to be imposed,
making clear that the submissions “should be limited to the determination, by the DPC, of
final fining amounts from within the fining ranges set out in the Draft Decision.”
113.On 27 March 2025, TikTok made the first of a number of requests for “a complete copy
of the DPC’s file.” By letter dated 2April 2025, the DPC stated that it had provided TikTok
with all material that it had relied on in making the Draft Decision or would rely on in
making the final decision. It stated that TikTok had no entitlement to details of its
engagement with the other SACs and that it had already been provided with all material to
which it was entitled.
114.By letter dated 11 April 2025, TikTok made submissions on the amounts of the
administrative fines to be imposed. The letter also provided updates on the Project Clover
measures.
115.Although the DPC received comments on the Draft Decision from three SACs (those
of France, Holland and Berlin), it received no reasoned objections. Accordingly, the DPC
adopted the Decision with “non-material” amendments from the Draft Decision on 30April
2025.
The Decision
116.At paragraph 378 of the Decision, the DPC observed as follows: In practice, the Data Transfers concerned remote access to the personal data by
persons within the jurisdiction of China. The Remote Access Solution resulted in EEA
User Data being processed on computer information systems in China. This is an
inevitable consequence of any remote access solution. This processing of personal data
occurs on devices within the territory of China.
117.The Decision continues:
379. Despite the fact that TikTok’s Remote Access Solution results in EEA User Data
being processed in China, TikTok Ireland has not established that Chinese Authorities
would require extraterritorial enforcement jurisdiction to obtain access to this data
when it is processed there. TikTok Ireland’s assessment of the territoriality principle
focused on the personal data when that data is located in Singapore, Malaysia, and the
United States. The submissions set out that Chinese authorities cannot carry out
intelligencegathering or investigativeactivitiesin aforeign State,andthereforecannot
compel a China Group Entity or one of their personnel in China to access and disclose
the remotely accessible EEA User Data stored in the US, Singapore or Malaysia.
TikTok Ireland outlined that compelling a person to disclose such data would involve
compelling the relevant entity/individual in China to take steps within the territory of a
foreign State in order to enable the Chinese authority to access or receive data stored
on a server in the territory of that foreign State, and that this would be contrary to the
territoriality principle.
380. TikTok Ireland’s assessment of the territoriality principle failed to properly
address the fact that the personal data routinely subject to the Remote Access Solution
is processed in China, and therefore is located within China, albeit on a temporary
basis. TikTok Ireland failed to establish that the territoriality principle prevents the
application of problematic laws to EEA User Data when that processing occurs in
China.”
118.The DPC concluded, therefore, that the additional information provided by TikTok had
not addressed the DPC’s concerns. In relation to Issue 2 in the Statement of Issues, it found: 417. For the reasons outlined above, the DPC finds that TikTok Ireland failed to
adequately assess the level of protection of personal data of EEA users the subject of
transfers by means of the Remote Access Solution to the China Group Entities using
SCCs. While TikTok Ireland acknowledged relevant divergences between the level of
protection afforded by the law and practices of China compared with European Union
law, its assessment of the territoriality principle resulted in it concluding that the Data
Transfers fell outside the territorial scope of the problematic laws. However, the DPC
finds that TikTok Ireland’s assessment of the territoriality principle failed to clarify
whether, and the extent to which, such laws may apply in the context of the Data
Transfers, and failed to set out in a clear way the deficiencies it acknowledged to exist
in the Chinese legal framework. By failing to adequately assess the law and practices
in China in the context of the Data Transfers, TikTok Ireland failed to comply with its
responsibility to assess the level of protection of personal data of EEA users the subject
of transfers to the China Group Entities using SCCs.
418. The DPC also finds that TikTok Ireland’s failure to adequately assess the level
of protection provided by Chinese law and practices resulted in it failing to verify,
guaranteeand demonstratethat that thepersonaldata of EEAUsers subject to theData
Transfers was afforded a level of protection essentially equivalent to that guaranteed
within the European Union. Under Issue 3 below, the DPC has set out how the
supplementary measures were not effective to ensure that EEA Users were provided a
level of protection essentially equivalent to that guaranteed in the EU in circumstances
where those measures were not sufficient to compensate for the risk of problematic
access by Chinese authorities supported by problematic laws. However, irrespective of
that finding, for the reasons that follow, TikTok Ireland’s failure in the first instance to
adequately assess the level of protection of personal data of EEA Users the subject of
transfers to the China Group Entities using SCCs has equally resulted in it failing to
verify, guarantee and demonstrate that that the personal data of EEA Users subject to
the Data Transfers was afforded a level of protection essentially equivalent to that
guaranteed within the European Union.
119.In relation to Issue 3, the Decision concluded: 500. The supplementary measures were not sufficient to prevent the risk of potential
application of problematic access by Chinese authorities supported by problematic
laws, and, thus, were not sufficient to ensure that the personal data of EEA users was
afforded a level of protection essentially equivalent to that guaranteed within the EU.
TikTok Ireland’s assessment of law and practices in China and the supplementary
measures implemented based on that assessment have failed to appropriately account
for theriskof access supportedbyproblematiclaws to EEAUser Datathat is processed
in China.For thereasonsset out above,theDPCfinds thatthesupplementarymeasures
implemented by TikTok Ireland were inadequate to compensate in respect of this risk.
Therefore, theDPC findsthat TikTokIreland failedto verifythat EEAUser Data subject
to the Data Transfers would be afforded a level of protection essentially equivalent to
that guaranteed within the European Union in circumstances where TikTok Ireland
failed to verify that problematic laws could not be applied to EEA User Data processed
in China. The DPC also finds that TikTok Ireland failed to implement appropriate
safeguards and supplemental measures to guarantee that EEA User Data subject to the
Data Transfers would be afforded a level of protection essentially equivalent to that
guaranteed within the European Union.
501. Accordingly, the DPC finds that TikTok Ireland failed to verify, guarantee and
demonstrate that the supplementary measures implemented by TikTok Ireland and the
China Group Entities in respect of the Data Transfers were effective, together with the
2010 SCCs and the 2021 SCCs, to ensure that EEA users were provided with the
appropriate safeguards, enforceable rights and effective legal remedies required by
Articles 44, 46(1) and 46(2)I GDPR, so that the personal data of EEA users was
afforded a level of protection essentially equivalent to that guaranteed within EU by the
GDPR.
120.The DPC made the following finding of infringement:
569. In light of the foregoing, as set out in Issues 1 – 4, the DPC finds that TikTok
Ireland infringed Article 46(1) GDPR regarding the Data Transfers. As set out above,
TikTok Ireland failed to adequately assess the level of protection provided by Chinese
law and practices to the personal data of EEA Users the subject of transfers to the
China Group Entities using SCCs. It failed to verify, guarantee and demonstrate that the supplementary measures and the SCCs were effective to ensure that the personal
data of EEA Users is afforded a level of protection essentially equivalent to that
guaranteedwithintheEU.TikTokIrelanddidnot,andcouldnot,relyonthederogations
under Article 49 GDPR in respect of the Data Transfers made during the temporal
scope. Consequently, TikTok Ireland transferred EEA User Data to China without
complying with the conditions laiddownbyChapter Vof theGDPRand did not identify
a valid lawful basis for the Data Transfers.
570. Accordingly, during the temporal scope of the Inquiry, from 29 July 2020 to 17
May 2023, TikTok Ireland infringed Article 46(1) GDPR by carrying out the Data
Transfers while failing to verify, guarantee and demonstrate that that the personal data
ofEEAUsers subjecttotheDataTransferswasaffordedalevelofprotectionessentially
equivalent to that guaranteed within the European Union.
121.Having regard to the fact that the DPC had decided that the temporal scope of the
Inquiry ended on the date the PDD was provided to TikTok, the DPC separately considered
the changes made by TikTok since that date when considering whether to make any
suspension or correction order.
122.The Decision records that:
691. The DPC has carefully considered all of the additional supplementary measures
implemented by TikTok Ireland after the temporal scope of the Inquiry, including TikTok
Ireland’s latest update on Project clover provided to the DPC on 11 April 2025. The
additional supplementary measures do not address the risk of Chinese authorities
accessing the personal data that is accessed by employees of the China Group Entities
in plain text. The DPC finds that TikTok Ireland has not demonstrated that EEA User
Data subject to the Data Transfers cannot be subject to problematic access by Chinese
public authorities. The DPC has also considered additional information submitted by
TikTok Ireland following the Draft Decision, including the Third Xi Report. However,
fundamental flaws in TikTok Ireland’s assessment, as identified above, remain
unaddressed and are ongoing. TikTok Ireland’s ongoing failure to adequately assess the
level of protection provided by Chinese law and practices to the personal data of EEA
users the subject of transfers interferes with its ability on an ongoing basis to select appropriate safeguards and supplementary measures, and prevents it from
demonstrating an essentially equivalent level of protection. Therefore, the DPC’s
concerns regarding the Data Transfers, as set out at Issues 2 and 3 of this Decision,
remain in respect of the ongoing Data Transfers. For that reason, the DPC finds that
TikTok Ireland has failed on a continuing basis to demonstrate that the supplementary
measures that it has implemented and the SCCs are effective to ensure that the personal
data of EEA users is afforded a level of protection essentially equivalent to that
guaranteed within the EU.
…
702. In light of the foregoing, the DPC orders TikTok Ireland pursuant to Article
58(2)(j) GDPR to suspend the Data Transfers in accordance with the timeline outlined
below.
* emphasis added
123.The highlighted reference in §691 to the third Xu opinion necessarily represents an
amendment from the Draft Decision.
124.The DPC made the following finding of infringement in respect of Article 13(1)(f) of
the GDPR (at §607):
The DPC finds that TikTok Ireland infringed Article 13(1)(f) GDPR by failing, in the
October 2021 EEA Privacy Policy, to provide information to EEA Users identifying the
third countries to which it transferred personal data. The DPC finds that TikTok Ireland
also infringed Article 13(1)(f) GDPR by failing to provide a basic factual description
of the transfers involving remote access to personal data of EEA users by personnel
located in China.
125.The DPC imposed administrative fines of €485 million for the infringement ofArticle
46(1) and €45 million for the infringement ofArticle 13(1)(f).
126.On7May2025,TikTokwrotetotheDPCnotingthatit“wouldwelcometheopportunity
to engage with the DPC so that TikTok Ireland can understand and address, as expeditiously as possible, the DPC’s concerns and therefore avoid the Suspension Order taking effect.” It
suggested that it might update its DTA, “elaborating further on our analysis of how Chinese
law applies to Temporary Data.” It asked that:
DPC could respond by return (and no later than Monday 12 May) to provide us with
an indication of: (1) the steps that we can take to address the DPCs concerns so as to
avoid the coming into effect of the Suspension Order; and (2) whether the DPC would
be open to a meeting with TikTok Ireland in the week commencing 19 May 2025 to
discuss the steps the DPC considers TikTok Ireland would need to take.
127.It followed up with this request on 19 May 2025. The DPC replied by letter dated 23
May 2025. It stated that it did not:
… intend to direct TikTok Ireland as to the particular steps to be taken by TikTok in
order to achieve compliance with its obligations as they arise under Chapter V of the
GDPR, and otherwise. In that regard, it is a matter for TikTok Ireland to identify (and
implement)anyandallsuchmeasuresasmaybenecessary to achievesuchcompliance.
If and when it does so, same will be carefully considered by the DPC in accordance
with the procedure laid down in Section O of the Decision, and by reference to
applicable provisions of the GDPR.
128.No updated DTAhas been submitted by TikTok since the date of the Decision.
129.TikTok appealed the Decision by originating notice of motion on 27 May 2025.
The Data TransferAssessments
130.The DTAin place at the outset of the Inquiry was dated 26 March 2021. It was updated
four times, the last occasion being July 2024.All of the DTAs reached the same conclusion,
in effect, that having regard to standard contractual clauses and TikTok’s supplementary
measures, EEA user data processed by TikTok in China was subject to an equivalent level
of protection to that guaranteed within the EU.131.Each DTAcontains a section headed ‘Regulation of Public Authority Access to Private
Data’ which, as noted above, became the focus of the Inquiry. TikTok’s assessment in the
March 2021 DTA was that the level of protection involved some safeguards but was
“materially below EU standards”. It reached the same conclusion under the headings
‘Regulation of Data Privacy’ and ‘International Treaties’. In respect of ‘Regulatory
Supervision’, it was concluded that there was a high level of safeguards, but below EU
standards. It reached a similar conclusion with regards to ‘Rights to Redress’.
132.The March 2021 DTA then set out the supplementary measures which TikTok had put
in place in order to ensure an equivalent level of protection notwithstanding the divergence
between Chinese and EU law. These were divided into technical, contractual and
organisational. The executive summary to the March 2021 DTAconcluded as follows:
In the specific context of Authorised Access, and in light of the assessment of China’s
legal framework, TikTok accepts that SCCs alone cannot provide guarantees beyond a
contractual obligation to ensure compliance with the level of protection required under
EU law. For this reason, TikTok has adopted a range of additional and complementary
safeguards to supplement the effectiveness of the SCCs (i.e. through the Supplementary
Measures, as summarised immediately above and described in detail in Section 3 of the
Assessment). In particular, the adoption of robust technical measures, a range of
binding contractual commitments that far exceed the requirements of SCCs, and
sophisticated internal organisational and policy controls, together ensure that any
perceived risks to EEA User Data under the China’s legal framework are minimised to
the extent that they do not undermine the effectiveness of the SCCs as a transfer
mechanism. Furthermore, the effectiveness of these measures is enhanced by the fact
that the relevant EEA User Data is stored on servers in Singapore and the US, which
means such data is stored outside the legal jurisdiction of Chinese law enforcement and
government authorities. This is further supplemented by the fact that encryption master
keys are stored and controlled from outside China, and likewise outside China’s legal
jurisdiction. In conclusion, taking account of the relevant aspects of China’s legal
framework, the SCCs together with the various Supplementary Measures ensure that
EEA User Data is afforded a level of protection essentially equivalent to that
guaranteed within the European Union.133.The DTAwas updated in October 2021. It noted changes in Chinese law, including the
coming into force of the Personal Information Protection Law (PIPL) and the Data Security
Law (DSL), both of which were in draft form at the time of the March 2021 DTA. These
lawsincreasedtheprotectionsavailableforpersonaldatainChina.Nonetheless,theOctober
2021 DTA reached the same conclusion regarding the regulation of public authority access
to private data, i.e. that it was below EU standards. But in light of the measures adopted by
TikTok, the overall conclusion of this DTAwas in the same terms as the earlier DTA.
134.The next update to the DTA, in October 2022 was, for the purpose of these proceedings,
in similar terms to the earlier two assessments. The overall conclusion was in similar terms,
but included the following:
These measures ensure that the China Group Entities are legally entitled, and
contractually required, to reject requests from Chinese authorities in respect of the EEA
User Data which they can remotely access.
Inconclusion,takingaccountoftherelevantaspectsofChina’scurrentlegalframework
in the specific context of the secure remote Authorised Access, the SCCs together with
the various Supplementary Measures ensure that EEA User Data is afforded a level of
protection essentially equivalent to that guaranteed within the European Union. There
is no impediment as a matter of Chinese law to the China Group Entities complying
with their obligations under the SCCs in the specific circumstances of the transfers.
TikTok is provided with monthly reports which confirm over a sustained period that the
China Group Entities have not to date received any requests from a Chinese authority
(whether law enforcement authorities, governmental authorities or judicial bodies),
whilst TikTok has similarly never received any such requests.
135.In 2021, the European Commission introduced new standard contractual clauses, the
2021 SCCs, and TikTok transitioned to these in 2022. It supplied a further revised DTA in
December 2022 reflecting this transition. The conclusion in the DTAremained substantially
the same.136.TikTok supplied a revised DTA in October 2023. Though the overall conclusion was
similar to the earlier DTAs, that the SCCs together with supplementary measures ensured
an equivalent level of protection, the October 2023 DTA differs significantly in form from
the earlier DTAs. In particular, it emphasises the reliance by TikTok on the remote access
solution and analyses its significance in detail. The October 2023 DTAexplains as follows:
• The following laws provide Chinese authorities with the power to obtain access to
personal data: the Anti-Terrorism Law, Counter-Espionage Law, Cybersecurity
Law, National Intelligence Law, Criminal Procedure Law and Criminal Law.
• These laws have been assessed in Section 2.2 of the Data Transfer Assessment
(Detailed) at Annex 2, for the purpose of determining whether the transfers might
fall within their scope. The assessment shows that these laws:
- do enable Chinese to obtain access to transferred data in the case of direct
transmission to servers in China; and
- do not enable Chinese Authorities to compel disclosure of transferred data in
the case of remote access transfers.
• These laws do not enable Chinese Authorities to compel disclosure of transferred
data in the case of remote access transfers to data stored outside China because (see
Section 2.B(3) of the Data Transfer Assessment (Detailed)):
- Chinese law requires mutual respect for sovereignty and territorial
integrity.
- Chinese law recognises that data stored outside China is subject to the
sovereign jurisdiction of the relevant foreign State, even if it can be remotely
accessed from China. Chinese law focuses on where the data is stored, not the
location of the person to whom the request is made.
- Chinese authorities must have both extra-territorial “adjudicative
jurisdiction” and “enforcement jurisdiction” to compel disclosure of data
stored in a foreign State:
o “Adjudicative jurisdiction” is the power to subject persons, things, and
conduct to judicial process, and o “Enforcement jurisdiction” refers to the power to compel compliance in
accordance with the law.
-ItisunlikelythataChineseauthoritywouldhaveadjudicativejurisdictionunder
the above laws in respect of acts occurring outside of China (e.g. where a non-
Chinese citizen commits a crime or engages in terrorist activities against China
or citizens of China), but it is possible in limited cases. However, even then, no
Chineselaws giveChineseauthoritiesenforcement jurisdictionto obtain (directly
or by compelling an entity or person to disclose it) data stored in a foreign State.
- If Chinese authorities want to access data stored outside of China, they must go
through a mutual legal assistance or other diplomatic process.
• TikTok’s transfers to the China Group Entities are made by way of remote access to
EEA User Data stored on servers in the US, Malaysia, and Singapore (not China).
The assessment thus shows that Chinese authorities cannot compel disclosure of the
transferred EEA User Data.
137. This summary of TikTok’s position is elaborated on in detail under the heading
‘Regulation of Public Authority Access to Private Data’. Under a heading to the effect that
Chinese law is territorial in nature and does not have extra-territorial effect unless expressly
provided for in Chinese law, the October 2023 DTAcontained the following statement:
The Chinese laws discussed in this Section 2.2B with extraterritorial adjudicatory
jurisdiction do not grant extraterritorial enforcement jurisdiction that would enable
Chinese authorities to compel a person or individual in China to disclose data stored
in a foreign State. This is consistent with the extension of the traditional territorial
principle to cyberspace and the “respect for sovereignty and territorial integrity”
principle under the Chinese Constitution, Foreign Relations Law and other laws.
138.The final DTA submitted by TikTok during the Inquiry was the July 2024 DTA. The
covering letter with this DTAsaid it included the following material updates:
• New technical measures
• Recent changes to Chinese law since the last DTA • Continued confirmation that TikTok has not received any requests from Chinese
authorities for access to EEAUser Data
• Updated factual information regarding government access to data held by third
parties
• Re-organisingthepresentationofthesummaryoftheChineseNationalSecurityLaw
139.The letter stated that:
Given the importance the DPC attached in its Preliminary Draft Decision to the
previous data transfer assessments, we anticipate you will want to consider these latest
updates carefully as part of the ongoing Inquiry.
140.The July 2024 DTAcontained a similar section on regulation of public authority access
to private data to the preceding DTA. In particular, it included precisely the same paragraph
as that quoted from the December 2023 DTA immediately above. However, the paragraph
concluded with the following footnote in the July 2024 DTA, footnote 113, upon which
TikTok placed significant reliance in the appeal:
We have been advised by Fangda and Professor Xu that the transient processing
inherent to the facilitation of remote access in China does not alter the above analysis.
This is because the relevant data is still stored outside of China (and only remotely
accessible from within China) and so is still subject to the requirements set out above.
In addition: (i) such transient processing is strictly protected by the constitutional right
to confidentiality of correspondence under Article 40 of the PRC Constitution and (ii)
such transiently processed data would in any event still be considered offshore data
when considering the scope of Chinese authorities jurisdiction (for example as a result
of the logic used in Article 4 of Provisions on Data Transfer, released on 22 March
2024).
141.The July 2024 DTA also described the supplementary measures, including the
additional Project Clovermeasures.The overall conclusion of this DTAwas to similar effect
to all the previous DTAs.Scope of the appeal
142.The parties set out their positions in their initial written submissions regarding the
standard of review in the appeal. However, in light of the pending judgment in LinkedIn v
DPCthepartiesdidnot engageindetailontheissueatthehearingandsoughtanopportunity
to make further submissions when the judgment was delivered. There are two related issues
in dispute.
143.First, TikTok contended that its entire appeal is an appeal pursuant to section 142 of the
Act. The DPC contends that section 142 only applies in relation to the appeal against the
administrative fines, and that section 150 applies to the balance of the appeal. In LinkedIn,
the court found that an appeal under section 142 is confined to an appeal against an
administrative fine (see §138). However, in light of the court’s conclusion that the same
standard of review applies in relation to an appeal under section 142 and an appeal under
section 150, nothing turns on this issue for the purpose of this appeal.
144.Second, TikTok contended irrespective of whether the appeal is an appeal pursuant to
section 142 or 150, that it is an “appeal on the record” (see Fitzgibbon v Law Society [2015]
1 IR 516) and, therefore, the court has full jurisdiction to examine all questions of fact and
law and is not obliged to defer to the DPC’s decision. It also contended that it was entitled
to adduce new evidence in respect of the entirety of its appeal, though it did not seek to do
so. It contends that this interpretation is consistent with Article 6(1) of the ECHR, Article
47 of the Charter andArticle 78 of the GDPR.
145.The DPC argued that the entire appeal is an appeal against error, citing Orange
Communications Ltd v The Director of Telecommunications Regulation [2000] 4 IR 159 to
the effect that the appellant must establish “taking the adjudicative process as a whole, the
decision reached was vitiated by a serious and significant error”. The DPC contends that
this is consistent with the CJEU’s decision in Case C-26/22, SCHUFA, a case concerning
the scope of the judicial remedy required by the GDPR.
146.Judgment in the LinkedIn case was delivered on 20April 2026.147.As appears from the detailed judgment in that case, the court (Cahill J) was asked to
consider four preliminary issues in an appeal by LinkedIn from a decision of the DPC.
Following a careful and comprehensive review of the issues arising in respect of each of
these questions, Cahill J summarised her conclusions in relation to each of the issues as
follows (at §452):
“Issue 1: Is the Appellant entitled to appeal the decision of the Respondent dated 22
October 2024 (the "Decision") under section 142 of the Data Protection Act 2018 or
are there aspects of the within appeal which can only proceed as an appeal under
section 150 of the 2018 Act?
Section 142 of the 2018 Act provides solely for an appeal from a decision to impose a
fine. A decision that there was an infringement or infringements of the GDPR or a
decision as to the exercise of other corrective powers under the 2018 Act cannot be
appealed under section 142.
Issue 2: What type of appeal does section 142 of the Data Protection Act 2018 provide
for and what is the standard of review/assessment to be applied by the Court in an
appeal under section 142?
The form of appeal provided for in section 142 of the 2018 Act is an appeal on the
record, with the possibility of new evidence or argument being admitted. Deference
may be appropriate in respect of issues which are within the sphere of the DPC’s
technical expertise.
Issue 3: If there are aspects of the Appellant’s appeal which can only proceed as an
appeal under section 150 of the Data Protection Act 2018, is the standard of
review/assessment to be applied by the Court the same under sections 142 and 150 of
the2018Act or does a different standardof review/assessment applyin anappeal under
section 150 of the 2018 Act?
The answer to Issue 2 applies equally to an appeal under section 150(5).
Issue 4: Having regard to the answers to the foregoing questions, is the Appellant
entitled to rely on evidence adduced and/or arguments made in the Appeal which were
not already adduced or made to the Respondent during the inquiry process? It is matter within the discretion of the court to determine whether to admit new
evidence or argument in an appeal under section 150(5), with the burden being
possibly lighter when such an application is made in an appeal under section 142.”
* emphasis in original
148.TikTok initially indicated that it did not consider it necessary to deliver further
submissions in light of the judgment, albeit it sought an entitlement to reply to any
submissions which the DPC might wish to make. However, I indicated that it would be
helpful for it to address the consequence for its various grounds of appeal, in particular, its
fair procedures arguments, in light of the LinkedIn judgment and it duly delivered
supplemental submissions to which the DPC replied.
149.In its supplemental submissions, TikTok highlighted the following passages from the
judgment:
“Third, as LinkedInpoints out, theLinkedInDecisionsets theparametersof theappeal.
It seems clear that the appeal will be run on the basis of, and by way of challenge to,
the LinkedIn Decision. Indeed, the right of appeal in section 142 is wholly premised on
“the decision” and the orders that may be made are orders to confirm, replace or annul
“the decision”. No form of appeal under that provision could be heard or determined
wholly without regard to the underlying decision. A similar point was made in an
authority cited by LinkedIn, Competition and Markets Authority v. Flynn Pharma
[2020] 4 All E.R. 934 (“Flynn”). There the UK Court of Appeal considered the scope
of the appeal from a decision of the UK Competition and Markets Authority to the
Competition Appeals Tribunal. The Court noted that, while Article 6(1) ECHR was
applicable,
“… the jurisdiction of the Tribunal is not unfettered. This flows primarily from
the fact that the appeal is not a de novo hearing but takes the decision as its
starting, middle and end point. Under s 46 CA 1998 the appeal is ‘against, or
with respect to,’ the decision and includes ‘whether’ there has been an
infringement. That focus upon the impugned decision is reflected in the
procedural rules of the Tribunal. The appellant must identify the decision under
appeal and set out why it is in error” (at [141])”150.Since the Decision is the starting point of the Court’s assessment, says TikTok, a
material breach of fair procedures is capable of invalidating the decision. It notes that the
DPC never contended to the contrary and refers to a letter dated 3 December 2025 from the
DPC’s solicitors in which it was stated that “our client will not raise an objection to any of
thegrounds of appeal pleaded therein onthebasis that it should properlyhavebeen pursued
by way of judicial review.”
151.TikTok refers to the decision in Stefan v Minister for Justice [2001] 4 IR 203 and the
observation by Denham CJ (at p. 218) that:
“An applicant is entitled to a primary decision in accordance with fair procedures and
an appeal from that decision. A fair appeal does not cure an unfair hearing.”
152.It also refers to the observation in Fitzgibbon v Law Society that, in conferring a right
of appeal, the Oireachtas must have intended some greater degree of review than in judicial
review and refer more generally to its entitlement to an effective remedy. The submissions
state as follows:
The DPC cannot be permitted to benefit from the incompleteness of a record which its
own breaches of fair procedures have caused. The Court is obliged to have regard to
the fact that the record could, and would, have been materially different and more
comprehensive had the DPC discharged its fair procedures obligations. This is
centrally relevant to the Court’s assessment of whether the DPC’s findings are
sustainable, reasonable and rational on the evidence “on the record” and whether the
conclusions drawn by the DPC can properly be upheld where TikTok was denied the
opportunity to address the actual basis of the Decision.
153.Itmakes a furtherpoint that by referenceto the refinement ofthe Okunadetest in TikTok
v DPC [2026] IESC 27 that it is “inconceivable” that a breach of fair procedures cannot be
relied on to vitiate a decision.
154.TheDPC’s supplemental submissions pointto cases in whichthecourtshave concluded
that defects in an earlier process can be cured by appeal.155.Both parties made submissions regarding the degree of deference which should be
afforded to the DPC’s decision by reference to the particular grounds of appeal.
156.I have considerable reservations about TikTok’s submission that a breach of fair
procedures by a decision-maker results necessarily in the decision being invalidated in an
appeal. It overlooks a number of material considerations. Its reliance on Stefan, and cases
to similar effect is, in my view, wholly misplaced. I confess that I simply do not understand
TikTok’s argument by reference to the Supreme Court’s refinement of the test in Okunade.
157.The decision in Stefan was a decision in judicial review proceedings challenging the
decision of the respondent to refuse the applicant refugee status. The High Court granted
certiorari, and one of the issues for the Supreme Court in the appeal was whether, in its
discretion, the High Court should have refused relief on the grounds that an adequate
alternative remedy was available, as it then was, an appeal to the Asylum Appeals Unit of
the Department of Justice. In other words, the issue was whether, when both judicial review
and an appeal are available, an applicant is not entitled to pursuea remedyin judicial review.
The Supreme Court refused to overturn the order of certiorari on the grounds that, in the
particular circumstance of that case, where relevant information was not before the decision
maker, an appeal was not an adequate remedy.
158.Stefan, therefore, does not provide any support for a conclusion that where a party has
available remedies by way of appeal and judicial review and elects to pursue an appeal, the
appeal must be regarded as incapable of curing a breach of fair procedures. Indeed, Stefan,
and the cases discussed therein, illustrate that there are many cases where an appeal will be
capable of rectifying an error at first instance and is, therefore, a more appropriate form of
appeal. An appeal on the record, where the court can consider the merits of the underlying
decision and hear new evidence, is manifestly at least capable of curing a breach of fair
procedures.
159.Though TikTok claim that the record is “incomplete”, it is clear in light of the decision
in LinkedIn (and as TikTok has always contended) that it was open to TikTok to correct the
record, by seeking to adduce additional evidence. It did not seek to do so.160.In addition to ignoring this obviously relevant consideration, TikTok disregards one of
the key differences between the appeal provided for by the 2018Act and judicial review. In
LinkedIn, one of the factors relied on by the appellant and the court in concluding that the
appeal provided for under section 142 and 150 was an appeal on the record was the absence
of any express provision for remittal. Cahill J, correctly in my view, interpreted this as an
indicator that the statutory scheme contemplated that the High Court should determine an
appeal on its merits, not merely correct errors by the decision-maker.
161.If one were to take it to be the position that the court is precluded from remitting a
decision to the DPC, then the consequence of TikTok’s submission would be quite
extraordinary. In judicial reviewproceedings,aconclusionthatadecisionmakerhad arrived
at a decision in breach of fair procedures would, typically, lead to a decision being quashed
and then remitted to the decision-maker for further assessment. By succeeding in the same
type of argument in an appeal, on TikTok’s theory, it would be left in a far better position,
the decision would be annulled, but not returned to the decision-maker. I do not accept that
an appellant can put themselves in a better position by pursuing a judicial review-type
argument in an appeal on the record than had they pursued the same argument in judicial
review proceedings.
162.Where an appellant opts to pursue an appeal where it has the entitlement to adduce new
evidence and pursue new arguments, it is difficult to understand how a complaint about how
the process before the decision-maker was conducted could, by itself, justify an annulment
oftheoriginal decision.This is notto suggest thatabreach offairprocedures at first instance
is without consequence in an appeal on the record, but it cannot lead to an automatic
annulment.
163.During the course of oral argument, I queried with the parties whether the court did, in
fact, have an inherent or implied power to remit. TikTok’s initial position was that the court
could not remit an appeal to the DPC for further consideration, though it moderated that
position somewhat following further engagement. Its initial position was a reflection of the
statutory language of sections 142 and 150 which are framed in mandatory terms and do
not reference remittal as an option available to a court.164.TikTok accepts that there is an inherent power to remit in judicial review proceedings,
which pre-dates the power contained in Order 84 of the Rules of the Superior Courts (see
Sheehan v Judge Reilly [1993] 2 IR 81). It contended, however, that the issue had to be
considered by reference to the jurisdiction conferred on the court by the 2018 Act and
whether an implied power to remit could be found in the Act. It notes, in this regard, that
there are statutory appeals to the High Court where there is an express power to remit (see,
for instance, section 64 Financial Services and Pensions OmbudsmanAct, 2017).
165.TikTok referred to the decision of Simons J in O’Sheehan v Residential Tenancies
Board [2024] IEHC 521, a statutory appeal on a point of law. In that case, Simons J
concluded that there was an implied power to remit, as the absence of such a power “would
undermine the effectiveness of the statutory appeal.”
166.Reference was also made to the decision in NzN v Minister for Justice [2014] IEHC 31,
an appeal against a revocation of a declaration of refugee status. The relevant provision of
the Refugee Act 1996, section 21(5) provides that on an appeal from a decision of the
Minister, the High Court may “as it thinks proper, on the hearing of the appeal, confirm the
decision of the Minister or direct the Minister to withdraw the revocation of the
declaration”. The court described the function of the court in such an appeal (at §31 and
§32):
“The powers of the Court on an appeal against a revocation of refugee status is to
determine whether the decision to revoke the declaration was correctly made and
should be confirmed, or whether the decision was wrong and should be withdrawn. The
Court can consider all the evidence which was before the Minister and hear oral
evidence from the appellant and any witnesses called by either party in determining the
appeal. The Court can come to its own view as to whether the decision to revoke is
appropriate or should be withdrawn…
… The Court is not empowered to ask the Minister to re-consider the decision and the
Court must come to its own decision confirming the Minister’s original decision to
revoke the appellant’s refugee status or restoring the appellant’s status by directing the
Minister to withdraw the revocation of the declaration. The Court does this on the evidence which was before the Minister and any additional evidence presented on the
appeal.”
167.In its oral submissions, the DPC highlighted a number of statutory appeals in which a
court had remitted decisions to the decision-maker absent an express statutory power to
remit, including a decision under the precursor to the 2018 Act, the Data Protection Act
1992, Director of Corporate Enforcement v Data Protection Commission, unreported,
Circuit Court, 1April 2022. Cases referenced included Minister for Communications v The
Information Commissioner [2022] 1 IR 1 and Minch v Commissioner for Environmental
Information [2017] IECA 223. It does not appear that any of those remittal decisions were
made following a dispute as to the entitlement to remit.
168.In An Bord Bainistíochta, Gaelscoil Moshíológ v Labour Court [2024] IESC 38,
O’Donnell CJ examined the function of a court in an appeal on a point of law. The case
concerned an appeal from the Labour Court under section 46 of the Workplace Relations
Act 2015 which provides for an appeal on a point of law. TheAct provides that the decision
of the High Court on such an appeal shall be “final and conclusive”. At §64, O’Donnell CJ
observed:
“Where the High Court concludes that there is an error of law, the order it may make
depends upon the error identified, in the same way as the order this Court or the Court
of Appeal may make in an appeal. In some cases, if the court concludes that there has
been an erroneous finding of primaryfactwhichledto aconclusionin favour of aparty,
then the court may allow the appeal and set aside the order made and substitute the
order which follows from that conclusion. Similarly, if there is an error of law and the
correctunderstandingandapplicationofthelawwouldleadtothecontraryconclusion,
then the court is entitled to allow the appeal and substitute that conclusion. There may,
however, be circumstances where the error identified cannot lead to the substitution of
a final order by the court, and may mean that the case has to be remitted to the primary
decision-maker. None of this however, expands the court's jurisdiction to substitute an
order it considers appropriate for that made by the primary decision-maker. The order
which the court makes on an appeal on a point of law, is still constrained because it is
an appeal on a point of law.”169.Although addressing an appeal on a point of law, where the Court stressed that the
merits of the underlying dispute were not a relevant consideration, it appears to me that the
Court’s identification of a power to remit in a case where the error identified cannot lead to
the substitution of a final order by the court must apply equally where that situation arises
in an appeal on the record. This is consistent with the reasoning of Simons J in O’Sheehan
where he identified an implied power to remit where that was necessary in order to avoid
undermining the statutory scheme.
170.Insofar as the decision in NzN might suggest otherwise, I think that must now be re-
considered in light of the observations of the Supreme Court and O’Sheehan. It may be, of
course, that the situation will rarely arise in an appeal on the record, where a court has the
power to review the evidence before the decision-maker – and any new evidence admitted
– and form its own view on the merits. But the statutory scheme clearly envisages that any
appeal to the High Court will follow an inquiry by the DPC and the exercise by the DPC of
its expertise in determining the issues in that inquiry. Where the appeal is from a decision
of an expert body such as the DPC, there may be circumstances where it would be unsafe
for the court to form a final view on matters requiring expertise without the benefit of the
expert body’s decision made in light of all relevant evidence. To do so could undermine the
statutory scheme.
171.Inotethat theDPC through its solicitorsindicatedthattheywouldn’t object to any point
being pursued in the appeal which was more properly a matter for judicial review, and it did
not advance any argument that TikTok’s breach of fair procedures claims were irrelevant in
this appeal.
172. In the circumstances, it appears to me that if TikTok identifies a breach of fair
procedures which could, had it been pursued in judicial review proceedings, have entitled it
to a remedy, I should consider whether that is a matter which can be fairly addressed within
the framework of this appeal in accordance with the statutory scheme. If not, I will consider
whether, notwithstanding the absence of an express statutory power, the matter should be
remitted to the DPC for further consideration.Nature of the Inquiry
173.In addition to the dispute regarding the scope of the appeal, the parties dispute whether
the Inquiry itself should be characterised as civil or criminal in nature. TikTok contends that
by reference to the criteria in the European Court of Human Rights decision in Engel,App
No 5100/71, that, having regard to the financial penalties to which it is exposed, the Inquiry
must be regarded as criminal in nature.Accordingly, it argues, that the rights of the defence
guaranteed under Article 48 of the Charter must be observed. For the purpose of these
proceedings, the main focus of this argument was TikTok’s contention that, having regard
to the criminal nature of the Inquiry, the DPC had impermissibly reversed the burden of
proof.
174.Article 48(1) of the Charter provides that “everyone who has been charged shall be
presumed innocent until proved guilty according to law.” It mirrors Article 6(2) of the
European Convention on Human Rights (“ECHR”).
175.TikTok accepts that the enforcement mechanisms oftheGDPR could not all necessarily
be regarded as criminal in nature, noting that there are civil remedies for breach of
provisions of the GDPR (Transcript Day 3, p. 158). But it argues that the possibility of the
imposition of very significant criminal sanctions renders those penalties criminal in nature
and, accordingly, the rights of the defence protected by the Charter must be observed before
making a finding which might lead to the imposition of such a penalty.
176.The three criteria in Engel are summarised as followed in TikTok’s submissions:
(a) whether national law defines the offence as criminal, disciplinary or both –
although this “provides no more than a starting point”;
(b) the nature of the offence, which is a factor of greater import; and
(c) the degree of severity of the penalty that the person concerned risks incurring.
177.In circumstances where national law does not define breaches of the GDPR as criminal,
TikTok’s emphasis is on the third of these criteria, severity of the penalties. It notes that the
criteria are not cumulative. TikTok identifies a number of decisions of the CJEU in which
the criteria identified in Engel are applied. Case C-481/19, Consob concerned a preliminaryreference in which the Italian national court queried whether it was permissible to impose
fines for refusal to answer questions in relation to insider trading allegations, where the
questions might establish liability for an offence which is criminal in nature. The Court
noted that the protections afforded by the ECHR were also provided by the Charter (at §36):
“Furthermore, while the questions referred mention Articles 47 and 48 of the Charter,
which enshrine, inter alia, the right to a fair trial and the presumption of innocence,
the request for a preliminary ruling also refers to the rights guaranteed in Article 6 of
the ECHR. Whilst the ECHR does not constitute, for as long as the European Union
has not acceded to it, a legal instrument which has been formally incorporated into the
EU legal order, it must nevertheless be recalled that, as Article 6(3) TEU confirms,
fundamental rights recognised by the ECHR constitute general principles of EU law.
Furthermore, Article 52(3) of the Charter, which provides that the rights contained in
the Charter which correspond to rights guaranteed by the ECHR are to have the same
meaning and scopeas thoselaiddownbytheECHR,is intendedto ensurethenecessary
consistency between those respective rights without adversely affecting the autonomy
of EU law and that of the Court of Justice (see, to that effect, judgment of 20 March
2018, Garlsson Real Estate and Others, C-537/16, EU:C:2018:193, paragraphs 24 and
25).”
178. It summarised the three criteria, mirroring Engels (at §42):
“… Three criteria are relevant to assess whether penalties are criminal in nature. The
first criterion is the legal classification of the offence under national law, the second is
the intrinsic nature of the offence, and the third is the degree of severity of the penalty
that the person concerned is liable to incur (judgment of 20 March 2018, Garlsson Real
Estate and Others, C-537/16, EU:C:2018:193, paragraph 28).”
179.While stipulating that it was a matter for the national court to determine whether the
sanctions were criminal in nature, the court observed that the fines which could be imposed
in that case, between €10,000 and €5,000,000, “… appear to pursue a punitive purpose and
topresentahighdegreeofseveritysuchthattheyareliabletoberegardedasbeingcriminal
in nature.”180.Applying the same criteria, the CJEU determined in Case C-544/19, Ecotex, that fines
imposed for breaches of a law governing restrictions of cash payments in Bulgaria, an anti-
money laundering law, were criminal in nature.
181.Of most relevance for the purpose of these proceedings are the observations of the
Advocate General in Case C-683/21, NVSC, a case concerning alleged breaches of the
GDPR in connection with a Covid mobile phone application in Lithuania. The decision is
discussed below in relation to whether there is a requirement for “fault” for the imposition
of an administrative sanction under the GDPR. In discussing that issue, the Advocate
General commented as follows:
“73. Third, I note that the fines imposed in application of Article 83 of the GDPR can
result in severe punishment. Indeed, the first tier, which is covered by Article 83(4) of
that regulation, can lead to the imposition of fines of up to EUR 10 000 000 or, in the
case of an undertaking, up to 2% of the total worldwide annual turnover of the
preceding financial year, whichever is higher. The second tier provides for fines up to
EUR 20 000 000 or, in the case of an undertaking, up to 4% of the total worldwide
annual turnover of the preceding financial year (again, whichever is higher).
74. Consequently, it would seem to me that the fines imposed in application of Article
83 of the GDPR pursue a punitive purpose, at least in some situations,39 and present
a high degree of severity such that they are liable to be regarded as being criminal in
natureand, thus, as falling within thescopeof Article49of theCharter of Fundamental
Rights of the European Union (‘the Charter’).”
182.TheAdvocate General in Case C-768/21, TR v Land Hessen made similar observations
(at §77).
183.As noted, TikTok claims that the characterisation of the administrative fines which can
beimposed undertheGDPR is relevant to its argumentthattheDPC impermissibly reversed
the burden of proof. It also suggested that it had a bearing on its fair procedures grounds
(Transcript Day 4, p. 19), but no particular argument was advanced that the fair proceduresnecessitated in GDPR inquiries were more extensive than suggested by the case law on
which TikTok itself relied.
184.The DPC did not engage in detail on TikTok’s argument that the GDPR sanctions are
criminal in nature. In its Statement of Opposition, it denied that they were criminal, a fact
which TikTok suggests meant that they approached the Inquiry on a mistaken basis. In its
written submissions, it noted that there was no authority for the proposition that the GDPR
fines should be regarded as criminal, still less that the DPC’s ‘non-fine’ analysis should be
assessed by some criminal standard.
185.In oral submissions, the DPC did not make further submissions on the question of
whether the fines could be regarded as criminal in nature, but noted that there was no
absolute prohibition on a reversal of the burden of proof. Counsel referred to Council of
Europe guidance, submitted by TikTok, which noted, by reference to case law of the
European Court of Human Rights that “presumptions of fact or of law operate in every
criminal-law system and are not prohibited by the Convention”. The document concludes
with a reference to the decision in Janosevic v Sweden, Application No. 34619/97 (at §101):
“In Salabiaku, cited above, the Court pointed out (p. 15, § 28):
“Article 6 § 2 does not ... regard presumptions of fact or of law provided for in
the criminal law with indifference. It requires States to confine them within
reasonable limits which take into account the importance of what is at stake and
maintain the rights of the defence.”
Thus, in employing presumptions in criminal law, the Contracting States are required
to strike a balance between the importance of what is at stake and the rights of the
defence; in other words, the means employed have to be reasonably proportionate to
the legitimate aim sought to be achieved.”
186. Having regard to the size of the administrative fines which can be imposed under the
GDPR – I note that in this particular case, the fines imposed on TikTok were less than 1%
of the maximum which could have been imposed – and the observations of the Advocates
General in NVSC and TR v Land Hessen, it would appear that the imposition of such fines
should be regarded as the imposition of a criminal sanction. The DPC did not identify a basis for contending otherwise. I will, accordingly, consider TikTok’s arguments, in
particular its argument that there has been an impermissible reversible of the burden of
proof, through that prism.
Grounds of appeal
187.TikTok has appealed the Decision on a variety of grounds. In its written submissions, it
provides the following helpful summary of those grounds:
1) The Decision was made in breach of TTI’s right to fair procedures and legitimate
expectations, where the DPC:
(a) made new and materially different adverse findings in the Decision without
putting them to TTI and affording it a right to be heard in response;
(b) failed to have adequate regard to the submissions made and evidence
adduced by TTI during the Inquiry;
(c) failed to communicate its provisional view on Clover during the Inquiry, or
provide TTI with any right to be heard in respect of same;
(d)altered thetemporal scopeof theInquiry(“Temporal Scope”)without notice
or explanation;
(e) refused TTI access to the Inquiry file.
2) The DPC committed a manifest error of assessment in finding that TTI had failed to
assess the application of Relevant Chinese Laws to the Temporary Data.
3) In finding an infringement of Article 46 and making the Suspension Order, the DPC
erred by failing to carry out the assessment mandated by the CJEU in Schrems II, and
relying instead on a negative finding based upon an alleged accountability failure.
4) The DPC erred in engaging in a hypothetical assessment of TTI’s entitlement to rely
on Article 49 derogations.
5) The DPC misinterpreted Article 13(1)(f) and wrongly found TTI’s October 2021
privacy policy to be non‑compliant with this provision. 6) The DPC acted ultra vires the Act and Article 83 by imposing administrative fines
on TTI where it failed to establish that the infringements found were committed
negligently.
7) The DPC acted ultra vires the Act and Article 83, misinterpreted Article 83, and
infringed general principles of EU law by imposing administrative fines by reference
to the turnover of ByteDance Limited (“ByteDance”).
8) The reasons for the fining decision were wholly inadequate.
9) The DPC made significant errors in its interpretation and application of Article
83.
10) The Decision contains manifest errors of assessment.
11)TheDPCmisinterpretedArticles46(1)and58(2)(i)in makingtheSuspensionOrder
and erred in making Corrective Orders which are impermissibly vague and provide for
an unreasonably short compliance period.
188.During oral submissions, it was confirmed that TikTok was not pursuing Ground 4,
relating to Article 49 derogations. It was also stated that it was relying solely on its written
submissions in relation to Ground 5, the only appeal ground relating to the finding of a
breach ofArticle 13(1)(f) of the GDPR.
189.In oral submissions some of the remaining grounds were, in broad terms, argued
together. In particular, Grounds 1 and 2 were dealt with together, as were Grounds 6, 7, 8
and 9 (relating to the administrative fines). There was some overlap between Grounds 10
and 11 and the other grounds, in particular Ground 3. I propose to address the grounds of
appeal directed to the Article 46 infringement and the corrective orders before addressing
the sole ground of appeal directed to the Article 13(1)(f) infringement. I will then address
Ground 6, one of the grounds of appeal relating to the imposition of the administrative fines.
190.In light of the conclusions in LinkedIn regarding the scope of the appeal, careful
consideration needs to be given to how the court approaches each ground of appeal. In an
appeal on the record pursuant to section 142 and /or 150 of the 2018Act, the court is entitled
to reach its own conclusion in light of the evidence which was before the decision maker,
or such additional evidence as the appellant is given leave to adduce. In this case, no application was made to adduce additional evidence. Some deference may be given to the
view of the decision-maker, the DPC, on matters within the sphere of the DPC’s technical
expertise.
191.In brief terms, Grounds 1 and 2 concern alleged breaches of fair procedures and errors
of assessment, whereas Ground 3 pleads errors of law, in effect, that the DPC approached
the Inquiry on a misunderstanding of TikTok’s, and its own, obligations pursuant to the
GDPR. If TikTok is correct about this ground of appeal, then the DPC erred in finding that
there was an infringement ofArticle 46, and, more pertinently, this court could not but find
that there had been no breach of Article 46: TikTok’s other grounds of appeal against the
Article 46 infringement finding and sanction simply would not arise.TikTok also allege that
the DPC approached the question of whether to make a corrective order on the basis of a
misunderstanding of its legal obligations. The role of the court on this ground of appeal is
straightforward, simply deciding which of the parties is correct as a matter of law. For that
reason, it seems to me that that is the ground of appeal which should be dealt with first.
Ground 3 – Errors of law
192.TikTok’s pleaded complaint under this heading is as follows:
[The] DPC misinterpreted and misapplied Articles 5, 24 and 46 [GDPR], with the
result that it erred in law and failed to fulfil its statutory function as LSA.
193.TikTok’s overarching complaint under this ground is that the DPC has misunderstood
the nature of the obligation imposed on controllers of data by Article 46 of the GDPR. In
simple terms, although TikTok accepts that Article 46 imposes on data controllers an
obligation not to transfer personal data outside the EU without first verifying that the
personal data is subject to the equivalent protection guaranteed within the EU, it contends
that there is no obligation on data controllers to be able to demonstrate that that is so, i.e. to
stand over its verification. The DPC’s decision is clearly framed as a failure by TikTok to
“verify, guarantee and demonstrate” that the data transferred to China was afforded an
equivalent level of protection. It does not, therefore, dispute that it has interpreted Article46 as imposing such an obligation, rather it argues that this is the correct interpretation. Both
parties rely heavily on the decision of the CJEU in Schrems II.
194.TikTok advances its general point by reference to four separate arguments. It alleges
that the DPC failed to carry out the assessment mandated by the decision of the CJEU in
Schrems II. Second, it contends that the DPC impermissibly reversed the burden of proof in
the Inquiry. Third, it contends that the DPC misapplied the accountability obligation
contained inArticles 5(2) and 24(1) of the GDPR.And fourth, it argues that the DPC failed
to carry out an adequate risk assessment when analysing the transfers the subject of the
Inquiry. In its written legal submissions, it also includes an argument under this heading that
the DPC failed to have regard to the supplementary measures in finding an infringement of
Article 46(1). However, it seems to me that this is an issue which falls to be considered
under Grounds 1 and 10, where it was addressed during oral submissions.
195.The first of the arguments, relating to the decision in Schrems II, is central to the
complaints TikTok advances in these proceedings and is inter-linked with the second and
third arguments. The dispute between the parties can be expressed in simple terms. TikTok
contends that in order for the DPC (or any supervising authority) to establish a breach of
Article 46 of the GDPR, it must prove that data transferred to a third country is in fact not
afforded an essentially equivalent level of protection to that guaranteed in the EU. It says
that there was no such finding here, indeed no investigation of the level of protection
afforded to the personal data transferred to China, other than by reference to the information
TikTok provided, and therefore no basis for the finding of a breach ofArticle 46.
196.TheDPCcontendsthatArticle46imposesapositiveobligationonacontrollertoensure
that essentially equivalent protection is afforded in the third country before it can transfer
personal data from the EU to that county. Accordingly, if a controller cannot demonstrate,
when called upon to do so, that there is such equivalent protection, it is not entitled to
transfer data to that third country, and if, as here, it has transferred or is transferring data,
that constitutes a breach ofArticle 46.
197.The starting point for this argument is, of course, the GDPR itself, but the parties’
arguments were largely focussed on the decision in Schrems II, and what the CJEU had said
about the obligations on controllers and supervising authorities imposed by Article 46. Before addressing the parties’ arguments, it is worthwhile, therefore, to consider that
decision in a little detail.
The decision in Schrems II
198.It is important to recall the context for Schrems II. As set out above, per Article 45 of
the GDPR, personal data can be transferred to a third country where the Commission has
made an adequacy decision that the data transferred to that country is afforded an equivalent
level of protection to that guaranteed in the EU. The applicant, Mr Schrems complained to
the DPC that Facebook Ireland was transferring his data to the United States in reliance on
aCommission adequacy decision in respect of personal datatransferred to theUnitedStates,
Commission Decision 2000/520/EC (“the Safe Harbour Decision”), but that his data was
not, in fact, afforded equivalent protection to that guaranteed in the EU. The DPC refused
to entertain the complaint, considering that it was bound by the Safe Harbour Decision. Mr
Schrems challenged this refusal in High Court proceedings, and the court referred questions
to the CJEU regarding, inter alia, whether the DPC was “absolutely bound” by an adequacy
decision or whether it was required to investigate the matter in the light of factual
circumstances since the making of the Safe Harbour Decision.
199.In Schrems I, the CJEU concluded that the DPC was not precluded from considering
the complaint. Importantly, it also concluded that the Safe Harbour Decision was invalid.
Mr Schrems’complaint was thus remitted to the DPC for further consideration.
200.Following the declaration by the CJEU in the judgment in Schrems I that the Safe
Harbour Decision was invalid, transfers of personal data to the United States continued on
the basis of other legal provisions. In particular, data-exporting companies made use of
contracts with data importers, incorporating standard contractual clauses drawn up by the
Commission in Decision 2010/87/EU (“the SCC Decision”). The SCC Decision was made
under the equivalent ofArticle 46(2)(c) of the GDPR, which allows for the Commission to
adopt standard data protection clauses which provide a mechanism for transfers where there
is no adequacy decision. Accordingly, the DPC asked Mr Schrems to reformulate his
complaint, which he did.201.In addition, the Commission made a further adequacy decision, Implementing Decision
(EU) 2016/1250 (“the Privacy Shield Decision”), which provided a set of rules, oversight
mechanisms, and redress procedures intended to safeguard EU citizens’ data when
processed in the US.
202.Before the DPC, Mr Schrems argued that these decisions were also invalid having
regard to the level of protection actually afforded to personal data in the US, focussing, in
particular, on the possibility of public authority surveillance of the data enabled by US laws.
203.Following adetailedinvestigationbytheDPC,in which it considered provisionallythat
US law does not offer effective remedies in accordance with Article 47 of the Charter to
Union citizens, it issued High Court proceedings for the purpose of securing a reference to
the CJEU on the validity of the SCC Decision, considering that it was otherwise impossible
to adjudicate on Mr Schrems’complaint. Following a further hearing by the High Court, in
which it heard detailed evidence in order to determine whether it shared the concerns of the
DPC (as required by Schrems I), the court, having concluded that it did share the DPC’s
concerns, referred further questions to the CJEU regarding the validity, in particular, of
Decision 2010/87/EU. This led to the decision in Schrems II. In that decision, the CJEU
considered the validity of both the SCC Decision and the Privacy Shield Decision. The
CJEU found that the SCC Decision was valid but declared the Privacy Shield Decision
invalid. However, it is what the court had to say regarding the duties on controllers and
supervising authorities when transferring data to a third country pursuant to Chapter V of
the GDPR which was the focus of the parties’attention in these proceedings.
204.The parties both referred to the opinion of the Advocate General. The sixth question
referred queried the level of protection which required to be afforded to personal data
transferred to a third country. TheAdvocate General observed (at §115):
“Like the DPC, Mr Schrems and Ireland, I consider that the ‘appropriate safeguards’
provided by the controller or processor to which Article 46(1) of the GDPR refers must
ensurethat therights of thepersons whosedata aretransferredbenefit, as in thecontext
of a transfer based on an adequacy decision, from a level of protection essentially
equivalent to that which follows from the GDPR, read in the light of the Charter.”205.He continued (at §117):
“Articles 45 and 46 of the GDPR are aimed at ensuring the continuity of the high level
of protection of personal data ensured by that regulation when they are transferred
outside the European Union. In fact, Article 44 of the GDPR, entitled ‘General
principlefor transfers’, opens Chapter V,ontransfersto thirdcountries,by announcing
that all the provisions in that chapter are to be applied in order to ensure that the level
of protection guaranteed by the GDPR is not undermined where data are transferred to
a third State. That rule is designed to ensure that the standards of protection resulting
from EU law are not circumvented by transfers of personal data to a third country for
the purpose of being processed there. Having regard to that objective, it is immaterial
that the transfer is based on an adequacy decision or on guarantees provided by the
controllerorprocessor,inparticularbymeansofcontractualclauses.Therequirements
of protection of fundamental rights guaranteed by the Charter do not differ according
to the legal basis for a specific transfer.”
And at §126 and §127
“In those circumstances, as Mr Schrems and the Commission have observed, the
contractual mechanism set out in Article 46(2)(c) of the GDPR is based on
responsibility being placed on the exporter and, in the alternative, the supervisory
authorities. It is on a case-by-case basis, for each specific transfer, that the controller
or, failing that, the supervisory authority will examine whether the law of the third
country of destination constitutes an obstacle to the implementation of the standard
clauses and, therefore, to an adequate protection of the transferred data, so that the
transfers must be prohibited or suspended.
In the light of those observations, I consider that the fact that Decision 2010/87 and the
standard contractual clauses which it sets out are not binding on the authorities of the
third country of destination does not in itself render that decision invalid. The
compatibility of Decision 2010/87 with Articles 7, 8 and 47 of the Charter depends, in
my view, on whether there are sufficiently sound mechanisms to ensure that transfers based on the standard contractual clauses are suspended or prohibited where those
clauses are breached or impossible to honour.”
206.Accordingly, the focus was on whether there was a risk that transfers would not be
suspended even though the SCCs were breached or impossible to honour. If so, that would
render the SCC Decision invalid.
207.When considering the eighth question referred, whether a supervisory authority is
required to use its powers to suspend transfers where it considers that an equivalent level of
protection is not guaranteed, theAdvocate General concluded that it was. Because there was
such an obligation, he concluded that the SCC Decision was valid. He considered first the
obligation on controllers:
“134. I believe it is necessary to make a few points here about the content of the
examination which the parties to the contract should carry out in order to determine,
in the light of the footnote referring to Clause 5, whether the obligations which the law
of the third State imposes on the importer entail a breach of the standard clauses and
thuspreventthetransferfrombeingaccompaniedbyappropriatesafeguards.Thatissue
has been raised, in essence, in the context of the second part of the sixth question.
135. Such an examination entails in my view a consideration of all of the circumstances
characterising each transfer, whichmayinclude thenatureof thedata and whetherthey
are sensitive, the mechanisms employed by the exporter and/or the importer to ensure
its security, the nature and the purpose of the processing by the public authorities of the
third country which the data will undergo, the details of such processing and the
limitations and safeguards ensured by that third country. The factors characterising the
processing activitiescarriedout bythepublicauthoritiesandthesafeguards applicable
in the legal order of that third country may, in my view, overlap with those set out in
Article 45(2) of the GDPR.”
208.He then turned to the obligations on supervisory authorities:
“140. The following reasons lead me to consider that, as Mr Schrems, Ireland, the
German, Austrian, Belgian, Netherlands and Portuguese Governments and the EDPBsubmit, under Article 58(2) of the GDPR the supervisory authorities are required, when
they consider following a diligent examination that data transferred to a third country
do not benefit from appropriate protection because the contractual clauses agreed are
not complied with, to take adequate measures to remedy that illegality, if necessary by
ordering suspension of the transfer.
…
144. In the second place, contrary to a further submission of the DPC, the exercise of
the powers to suspend and prohibit transfers set out in Article 58(2)(f) and (j) of the
GDPR is no longer merely an option left to the supervisory authorities’discretion. That
conclusion follows, in my view, from an interpretation of Article 58(2) of the GDPR in
the light of other provisions of that regulation and of the Charter, and also from the
general scheme and the objectives of Decision 2010/87.
145. In particular, Article 58(2) of the GDPR must be read in the light of Article 8(3) of
the Charter and Article 16(2) TFEU. In accordance with those provisions, compliance
with the requirements entailed by the fundamental right to protection of personal data
is subject to review by independent authorities. That task of monitoring compliance
with the requirements relating to the protection of personal data, which is also referred
to in Article 57(1)(a) of the GDPR, entails an obligation for the supervisory authorities
to act in such a way as to ensure the proper application of that regulation.
146. Thus, a supervisory authority must examine with all due diligence the complaint
lodgedbya person whose data are allegedto betransferredto a thirdcountryin breach
ofthestandardcontractualclausesapplicabletothetransfer.Article58(1)oftheGDPR
confers on the supervisory authorities, for that purpose, significant investigative
powers.
147. The competent supervisory authority is also required to react appropriately to any
infringements of the rights of the data subject which it has established following its
investigation. In that regard, each supervisory authority has, under Article 58(2) of the
GDPR,awiderangeofmeans—thevariouspowerstoadoptcorrectivemeasureslisted
in that provision — of carrying out the task entrusted to it.”209.In its judgment, the court confirmed the Advocate General’s view that the level of
protection afforded in a third country must be essentially equivalent to that guaranteed
within the EU by the GDPR read in light of the Charter. The assessment required byArticle
46(1) was also considered (at §104):
“The assessment required for that purpose in the context of such a transfer must, in
particular, take into consideration both the contractual clauses agreed between the
controller or processor established in the European Union and the recipient of the
transfer established in the third country concerned and, as regards any access by the
public authorities of that third country to the personal data transferred, the relevant
aspects of the legal system of that third country. As regards the latter, the factors to be
taken into consideration in the context of Article 46 of that regulation correspond to
those set out, in a non-exhaustive manner, in Article 45(2) of that regulation.”
210.The court also agreed that a supervisory authority was required to suspend transfers
where adequate protection cannot be guaranteed and where the controller or processor has
not itself put an end to the transfers (at §113 and §121).
211.In considering the validity of the SCC Decision, the court considered the obligations
on controllers and supervising authorities:
“133 It follows that the standard data protection clauses adopted by the Commission
on the basis of Article 46(2)(c) of the GDPR are solely intended to provide contractual
guarantees that apply uniformly in all third countries to controllers and processors
established in the European Union and, consequently, independently of the level of
protection guaranteed in each third country. In so far as those standard data protection
clauses cannot, having regard to their very nature, provide guarantees beyond a
contractual obligation to ensure compliance with the level of protection required under
EU law, they may require, depending on the prevailing position in a particular third
country, the adoption of supplementary measures by the controller in order to ensure
compliance with that level of protection.
134 In that regard, as the Advocate General stated in point 126 of his Opinion, the
contractual mechanism provided for in Article 46(2)(c) of the GDPR is based on the responsibility of the controller or his or her subcontractor established in the European
Union and, in the alternative, of the competent supervisory authority. It is therefore,
above all, for that controller or processor to verify, on a case-by-case basis and, where
appropriate, in collaboration with the recipient of the data, whether the law of the third
country of destination ensures adequate protection, under EU law, of personal data
transferred pursuant to standard data protection clauses, by providing, where
necessary, additional safeguards to those offered by those clauses.
135 Where the controller or a processor established in the European Union is not able
to take adequate additional measures to guarantee such protection, the controller or
processor or, failing that, the competent supervisory authority, are required to suspend
or end the transfer of personal data to the third country concerned. That is the case, in
particular, where the law of that third country imposes on the recipient of personal data
from the European Union obligations which are contrary to those clauses and are,
therefore, capable of impinging on the contractual guarantee of an adequate level of
protection against access by the public authorities of that third country to that data.
…
142 It follows that a controller established in the European Union and the recipient of
personaldataarerequiredtoverify,priortoanytransfer,whetherthelevelofprotection
required by EU law is respected in the third country concerned. The recipient is, where
appropriate, under an obligation, under Clause 5(b), to inform the controller of any
inability to comply with those clauses, the latter then being, in turn, obliged to suspend
the transfer of data and/or to terminate the contract.”
Alleged misinterpretation of the GDPR
Arguments
212.TikTok’s first and third arguments, both of which relate to the proper interpretation of
the GDPR, can conveniently be dealt with together.213.TikTok contends that it has fulfilled its obligation under Article 46 by carrying out the
various data transfer assessments. Even if the court accepts that the DPC was entitled to
conclude as a matter of fact that those assessments were inadequate, it contends, by
reference to Schrems II, that before the DPC could make any finding of infringement or
impose any sanction on it, it was required to carry out its own assessment of whether the
data the subject of the transfers being investigated was subject to essentially equivalent
levels of protection in the third country. It refers to this as “the assessment mandated by
Schrems II”. Since it is not in dispute that the DPC did not carry out such an inquiry, TikTok
argue that it erred in law in imposing the administrative fine and making the suspension
order.
214.TikTok contrasts the nature of the investigation in this case with that carried out by the
DPC which was the subject of the decision in Schrems II. In that instance, the DPC carried
out a detailed investigation into the level of protection afforded to personal data by US law.
In this case, the DPC did not carry out any independent assessment of Chinese law; indeed,
it expressly stated in the Decision that it was taking the information provided by TikTok
regarding the legal position in China “at its height, and at face value, with regard to its
veracity” in circumstances where TikTok had confirmed that the legal analysis contained in
Section 2 of the DTAs had been prepared by one of China’s leading independent law firms.
This, suggests TikTok, was an abdication by the DPC of its responsibility as supervising
authority.
215.TikTok highlights a number of features of Schrems II, which they characterise as “the
definitive decision in relation to data transfer and the requirements of Chapter V”
(Transcript, Day 10, p. 130). It highlights that, at paragraphs 134 and 142 of the CJEU’s
judgment, the court refers to the obligation on controllers (and processors) to “verify”
whether a third country provides adequate protection of data. It accepts, therefore, that it
was under an obligation to verify that there was an equivalent level of protection, which it
claims to have met by preparing its DTAs, but distinguishes this from an obligation to
demonstrate, which it argues is not imposed by the GDPR, as interpreted in Schrems II. It
notes that both ‘verify’ and ‘demonstrate’ are terms used within the GDPR and that they
must, accordingly, be afforded different meanings. It emphasises the passages in Schrems II
which refer to the obligation on a supervisory authority to suspend transfers where, having
carried out an examination, it concludes that essentially equivalent protection cannot be guaranteed. It concludes, therefore, that Schrems II is authority for the proposition that a
supervising authority can only suspend transfers, or make a finding of infringement, after it
has first reached such a conclusion.
216.TikTok also argues that the DPC erred by interpreting Article 46 of the GDPR in light
ofArticles5(2)and24(1)oftheGDPR.ItnotesthatArticle5(2)relatesonlytotheprinciples
set out in Article 5(1) and therefore has no general application. It describes the obligation
identified inArticle 24(1) as a “separate and distinct obligation” (Transcript Day 10, p. 129,
line 2) to that identified in Article 46. It notes that there is no reference to Articles 5 or 24
in Schrems II.
217.TheDPCalso relyon SchremsII.Thoughithighlightsthatthenatureoftheproceedings
in both Schrems I and Schrems II was quite different than these proceedings, and that the
judgments were addressed to different questions than at issue in the Inquiry, it argues that
Schrems II makes clear that the responsibility is on controllers (or processors) to ensure that
thereisan appropriatelevelofprotectionwhenpersonaldataistransferredto athirdcountry.
It contends that the obligation identified in Schrems II to verify adequate protection before
transferring data necessarily requires that a controller be able to demonstrate that level of
protection. It contends that there is no difference between these two concepts.
218.The DPC argues that the requirement to demonstrate compliance flows fromArticles 5
and 24 of the GDPR, and there was nothing improper in it having regard to those provisions
in interpreting the scope ofArticle 46.
Discussion
219.This ground of appeal concerns, in essence, the scope of the obligations imposed on
controllers by the GDPR. It also imposes obligations on processors, but since this appeal is
concerned only with TikTok’s position as controller of personal data, I will refer only to the
position of controllers hereafter. TikTok’s argument is first and foremost a question of
interpretation of the GDPR itself, though the parties both lean heavily on prior interpretation
of the GDPR by the CJEU in Schrems II.220.The GDPR is designed to guarantee certain rights for data users in respect of their
personal data. It does so by placing obligations on controllers of personal data and giving
supervising authorities powers of investigation and enforcement. The territorial scope of the
Regulation is the EEA. In order not to entirely undermine the protections afforded, the
GDPR prohibits controllers transferring personal data from within the EEA to third
countries, i.e. from within to outwith its territorial scope, unless the same level of protection
is guaranteed in those third countries (see Recital 101, quoted above). The purpose of this
prohibition is to ensure the high level of protection of personal data guaranteed by the
GDPR.
221.Article 5(1) of the GDPR sets out the principles on which the GDPR is based. These
include that all data is processed lawfully. Article 5(2) imposes an obligation on the
controllers of personal data to be able to demonstrate compliance with Article 5(1), i.e. to
beabletodemonstratethatdataisbeingprocessedlawfully.Therequirementthatcontrollers
be able to demonstrate that their processing of personal data is lawful is, accordingly, one
of the foundational principles of the GDPR.
222.Similarly, Article 24 of the GDPR imposes a “general obligation” on controllers to be
able to demonstrate that their processing of data is in accordance with the requirements of
the GDPR.
223.The general principle in relation to transfers to a third country, the subject of Chapter
V of the GDPR, is set out in Article 44 of the GDPR. It is expressed to be “subject to the
other provisions of this regulation”. It expressly provides that “all provisions in this Chapter
shall be applied in order to ensure that the level of protection of natural persons guaranteed
by this Regulation is not undermined.”
224.Article 45 provides for a general mechanism to enable transfers, the making of
adequacy decisions by the Commissions.As set out in Schrems II (at §162):
“In order for the Commission to adopt an adequacy decision pursuant to Article 45(3)
of the GDPR, it must find, duly stating reasons, that the third country concerned in fact
ensures, by reason of its domestic law or its international commitments, a level of
protection of fundamental rights essentially equivalent to that guaranteed in the EU
legal order.”225.As an alternative, a controller may transfer data in the absence of an adequacy decision
where the provisions of Article 46 are satisfied. Just as an adequacy decision can only be
made where there is an equivalent level of protection guaranteed, it is obvious that a transfer
can only be made pursuant to Article 46 where equivalent reassurance is ensured to that
provided by an adequacy decision. Schrems II makes clear that, irrespective of the
mechanism relied on for a transfer, the same level of protection, essentially equivalent to
that provided in the EEA, must be guaranteed.
226.TikTok accept that it was required to assess the level of protection afforded to data in
China and only transfer data where it had verified that effectively equivalent protection was
guaranteed. The nature of the assessment it was required to set out is described at §135 of
theAdvocate General’s opinion and §104 of the CJEU’s judgment, set out above.
227.Where the parties differ is in TikTok’s contention that once it had satisfied itself that
there was equivalent protection, it must be taken to have complied with Article 46 unless
the DPC proved that there was not, in fact, essentially equivalent protection. The DPC
contend that it was entitled to consider the adequacy of TikTok’s assessment. Where the
assessment was lacking, because it didn’t demonstrate that there was adequate protection
afforded to data transferred to China, the DPC was entitled to conclude that TikTok had
infringed Article 46. Both a literal and purposive interpretation of the GDPR support the
DPC’s interpretation. It is difficult to find anything in the wording of Chapter V, the GDPR
more generally, or Schrems II, which supports TikTok’s narrow interpretation .
228.Turning first to Schrems II, which was the focus of TikTok’s submissions on this point,
TikTok have, in my view, read far too much into what is said in Schrems II in relation to the
obligations on supervising authorities.
229.As noted above, Schrems II was addressed to an entirely different factual scenario than
that at issue here. There was no issue regarding the adequacy of any step taken by the
controller of data in that case, Facebook, only with the validity of Commission adequacy
decisions on which it relied. The examination of the role of controllers and supervising
authorities was carried out for the purpose of determining the validity of the SCC Decision,
not for the purpose of any issue arising from anArticle 46 assessment by Facebook.230.The eighth question referred in Schrems II concerned the question of the discretion
afforded to supervising authorities where, following an investigation, it had concluded that
essentially equivalent protection could not be guaranteed. As noted above, both the
Advocate General and the CJEU concluded that the SCC Decision was valid because if a
supervising authority, following an examination, concluded that essentially equivalent
protection could not be guaranteed, it would be required to suspend any transfers.
231.The parties agree that the conclusion is premised on a finding of infringement. TikTok
accuse the DPC of a “leap, not supported by logic” of saying that one can disregard what’s
said in response to question 8, because, it claims, the DPC ignores what is said by the CJEU
in response to question 8 simply because it is not addressing the question of whether there
must be a prior investigation by the DPC. With respect, it is TikTok’s reliance on the
response to question eight which is of questionable logic.
232.The CJEU determined that if a supervising authority carries out an investigation and
concludes that essentially equivalent protection cannot be guaranteed by the use of the
standard data protection clauses in the SCC Decision, it must suspend the transfers. It is
logical to infer that if for any reason, a supervising authority concludes that essentially
equivalent protection cannot be guaranteed, then the same obligation to suspend arises.
However, the corollary of that proposition is not that that is the only circumstance in which
a supervising authority can take any corrective action, still less that a supervising authority
must carry out its own assessment of the level of protection where a controller fails to
complete an adequate assessment. The fact that a supervising authority must act in a
particular way in one set of circumstances does not translate to that being the only
circumstanceinwhichthesupervisingauthoritycanactatall.Thereisnosupportin Schrems
II for TikTok’s overarching argument that a supervising authority cannot make a finding of
infringement without having first carried out an investigation and then concluded that there
is not equivalent protection in the third country to which data is being transferred.
233.As noted above, Schrems II does expressly state that a controller must verify, prior to
transfer, that the appropriate level of protection is available (see §134 and §142), and the
DPC seek to interpret that as confirming its view that a controller must be able to
demonstrate the adequacy of protection.Apart from the obvious point, that an obligation toverify would be rendered sterile if the obligation was not to carry out an adequate
verification, and if the adequacy of the verification could not be tested, the judgment does
not provide express guidance on the nature of that obligation or, more importantly, the role
of supervising authorities in policing it.
234.I accept what both parties say regarding the importance of Schrems II in understanding
the obligations imposed by the GDPR and certainly it provides assistance in addressing the
issues before this Court. But it does not directly answer the question at issue here for the
simple reason that neither that question, nor anything analogous to it was before the Court.
235.If the answer can’t be found in Schrems II as the parties suggest – because the issue
simply didn’t arise on the facts or on the basis of any of the questions referred – then it is to
the GDPR we must turn when considering TikTok’s argument.
236.First,itmustbeobservedthatthemechanismsinArticles45and46 facilitatecontrollers
to do that which would otherwise be impermissible. The starting point is that controllers of
personal data have certain obligations in relation to personal data under their control and are
simply not permitted to transfer personal data outside the EEA unless certain criteria are
met. It is, accordingly, entirely unsurprising that the GDPR imposes an obligation on
controllers to establish that they satisfy those criteria if they wish to do what would
otherwise be impermissible. It is difficult to understand how the GDPR could be effective
were it otherwise.
237.Such a requirement is built into Article 46, which expressly provides that a controller
can only transferdatawherethecontrollerhas providedappropriatesafeguardsandeffective
protection is available. Plainly this requires a prior assessment of the level of protection
afforded to personal data in the third country, as confirmed in Schrems II. Moreover, it is for
the controller to ensure that the safeguards are put in place.
238.There is nothing subjective about the requirement that essentially equivalent protection
be afforded. Again unsurprisingly, the GDPR does not provide that the controller’s
reasonable belief that there is essentially equivalent protection is sufficient to enable
transfers to third countries to take place; such would hardly provide the high levels of
protection guaranteed by the GDPR. Moreover, it is clear that the controller is, or should be,the party with the relevant means of knowledge regarding the transfers, i.e. the party in a
position to identify appropriate safeguards having regard to the nature and purpose of the
transfers it proposes to make.
239. Article 46 must also be read in the context of the general obligation identified inArticle
44. That provision is expressly stated to be “subject to the other provisions of the
Regulation.” Its purpose is to ensure that the protections afforded by the GDPR are not
undermined. In that context, in the Decision, the DPC concluded that Article 46 should be
readinlightofArticles5(2)and24(1)oftheGDPR,whichimposeobligationsoncontrollers
to be able to demonstrate the lawfulness of any data processing and their compliance with
the GDPR. TikTok argues either that these provisions are irrelevant for the purpose of
interpretingArticle 46 or, perhaps in the alternative, that the DPC erred by making a finding
of a breach ofArticle 46 when, in fact, its conclusion was that there was a breach ofArticle
24(1). For the purpose of addressing this ground of appeal, it is not necessary to address
TikTok’s argument that neither provision was, in fact, breached.As TikTok points out, there
is a significant legal implication to concluding that there was a breach of Article 46 rather
thanArticle 24, because the GDPR makes no provision for imposing administrative fines in
respect of a breach ofArticle 24.
240.It is very difficult to understand the basis upon which TikTok contends that Articles
5(2) and 24(1) are not relevant to the interpretation ofArticle 46. They manifestly are. The
first is described as a general principle, the second a general obligation. They should both
be understood, therefore, absent some very clear indication to the contrary, as applying to
all the provisions of the GDPR. Rather than an indication to the contrary, Article 44
expressly provides that the obligations in Chapter Vare subject to all other provisions of the
GDPR. Thus, on a plain reading of the Regulation, the specific obligation in relation to
transfers of personal data to third countries – not to do so unless there are adequate
protections in place in the third country – must be read in light of the general obligation on
a controller to be able to demonstrate compliance with the GDPR, and subject to the general
principle that a controller must be in a position to demonstrate the lawfulness of its
processing.
241.TikTok’s arguments to the contrary must be rejected. It says that Article 5(2) has no
relevance since it is confined to demonstrating compliance with Article 5(1). But thatdoesn’t assist TikTok at all: Article 5(1) requires that data be processed lawfully. A
requirement to be able to demonstrate compliance with Article 5(1) necessarily, therefore,
imports a requirement to be able to demonstrate that all personal data is processed lawfully,
regardless of how it is processed.TikTok does not dispute that the transfers to China involve
processing for the purpose of the GDPR, nor did it identify any plausible basis for
contending that the principle identified inArticle 5, that a controller be able to demonstrate
the lawfulness of its processing, does not apply to processing pursuant to Article 46.
242.TikTok described the obligation inArticle 24(1) as a “separate and distinct obligation”
(Transcript Day 10, p. 129, line 2) to the obligation inArticle 46.This is plainly not the case.
It is expressly stated to be a general obligation. There is nothing in the text ofArticle 24(1)
or Chapter V of the GDPR which suggests that the processing to which it relates somehow
excludes the processing regulated by Article 46. No reading or interpretation of the GDPR
supports such a conclusion.
243.If the specific obligation imposed byArticle 46 is read in light of the general obligation
imposed byArticle 24(1), this means thatArticle 46 incorporates an express obligation that
a controller be able to demonstrate compliance with the requirements of Chapter V, at least
when called upon to do so.An inability to demonstrate compliance is a breach ofArticle 46,
not simply a breach of Article 24(1). There was thus no error of law by the DPC in
concluding that there was a breach ofArticle 46 when read in light ofArticle 24(1).Article
24(1) is not a stand-alone obligation at all, rather it is an obligation which is read into all the
other relevant obligations in the GDPR, hence, perhaps, no provision is made for imposing
a fine for breach of that obligation.
244.TikTok also suggest thatArticles 5 and 24 must have no relevance because they are not
referenced in Schrems II. But as explained when considering TikTok’s first limb of
arguments, this is amply explained by fact that Facebook’s obligations were not in issue in
Schrems II. In that case, Facebook had relied on the SCC Decision and the Privacy Shield
Decision. There was simply no argument that even if these were valid, Facebook had
somehow fallen short in discharging its verification obligations when transferring data to
the United States. The fact that these provisions are not relied on in Schrems II is,
accordingly, of no significance.245.I note that guidance published by the EDPB, Recommendations 01/2020 on measures
that supplement transfer tools to ensure compliance with the EU level of protection of
personal data, Version 2.0 (“the EDPB Supplementary Measures Recommendations”)
also reads Article 46 in light of the accountability obligations in the GDPR (at §3 and §4):
The right to data protection has an active nature. It requires exporters and importers
(whether they are controllers and/or processors) to go beyond an acknowledgement or
passivecompliancewiththisright.Controllersandprocessorsmustseektocomplywith
the right to data protection in an active and continuous manner by implementing legal,
technical and organisational measures that ensure its effectiveness. Controllers and
processors must also be able to demonstrate these efforts to data subjects and data
protection supervisory authorities. This is the so called principle of accountability.
The principle of accountability, which is necessary to ensure the effective application
of the level of protection conferred by the GDPR also applies to data transfers to third
countries since they are a form of data processing in themselves. As the Court
underlined in its judgment, a level of protection essentially equivalent to that
guaranteed within the European Union by the GDPR read in the light of the Charter
must be guaranteed irrespective of the provision of that chapter on the basis of which
a transfer of personal data to a third country is carried out.
246.Standing back, it is immediately obvious that onTikTok’s argument, taken to its logical
conclusion, Article 46 places no real obligation on controllers at all, or at least none which
they could be found to have infringed, notwithstanding thatArticle 83 clearly provides that
administrative fines can be imposed for infringement ofArticle 46. Since controllers are not
entitled to process personal data other than in compliance with the GDPR, the obligation
not to transfer personal data to third countries where there is inadequate protection adds
nothing to a controller’s obligations if it is not under a prior duty to adequately ensure that
there is such protection. If the adequacy of its discharge of that obligation cannot be tested
to ensure that it has been complied with, then it is no obligation at all.
247.In an effort to avoid the logic of its own argument, TikTok accepts that a controller has
an obligation to verify adequate levels of protection: in oral argument, counsel noted that in
Schrems II, the controller’s obligation was “framed in terms of verifying and guaranteeing”(Transcript Day 3, pp. 109/110). It also accepted, in argument, that a failure to attempt to
verify would constitute a breach of article 46, but suggests that if a controller has “engaged
prima facie in the analysis” required to verify the level of protection, the controller will
have discharged its duty (Transcript Day 3, p. 113). On TikTok’s view, ‘verification’ is
entirely distinct from ‘demonstration’and all that is required to verify is for a controller to
satisfy itself that there are adequate levels of protection, althoughit accepts that it is required
to record this verification, which it does in its DTAs.
248.The difficulty forTikTok is that there is no support in Schrems II, still less in the GDPR
itself, for such an analysis. TikTok’s only argument is that by the use of the term “verify” in
Schrems II, the CJEU must be taken to have concluded that there was no obligation in the
GDPR to be able to demonstrate that it had verified. There is nothing in Schrems II which
suggests that that is what the court intended. Neither a literal, nor a purposive interpretation
of the GDPR supports such a proposition. TikTok’s argument that the terms verify and
demonstrate are both used in different contexts in the GDPR, suggesting that they must be
given different meanings, does not assist TikTok at all: neither are used in Article 46. The
words used inArticles 5(2) and 24 are ‘able to demonstrate’.
249.Once TikTok accepts, as it must, that there is an obligation imposed on it byArticle 46
to carry out an assessment in respect of transfers of personal data outside the EU, the
implausibility of its position becomes obvious. If there is a requirement to carry out such a
prior assessment, which there manifestly is, it must be a requirement to carry out an
adequate assessment. TikTok’s apparent view is that once a controller has satisfied itself
that its assessment is adequate, the only means by which a supervising authority can
establish a falling short on the part of the controller is, in effect, to carry out its own
assessment and show that the controller’s conclusion is wrong. It is true that a supervising
authority could establish a breach of Article 46 by showing that, in fact, essentially
equivalent protection is not guaranteed in the third country, but that it is not the only means
of so doing. It is also open to a supervising authority to examine the assessment carried out
by a controller and consider whether it was adequate, and whether it in fact demonstrates
what it purports to demonstrate. Where, as here, the supervising authority identifies a gap
or shortcoming in that assessment, it is entitled as a matter of law to conclude that the
controller has not complied with its obligations underArticle 46. Insofar as TikTok suggests
that this imposes an unfair burden on a controller, and exposes it to significant sanctions, I do not accept that this is so. As discussed below in relation to Ground 6, a supervising
authority will only be entitled to impose a fine where it concludes that any failing was
negligent or intentional. Insofar as a supervising authority may impose other forms of order,
such as the suspension order here, it must, as I conclude below, first carry out some
assessment of the proportionality of so doing. Where it concludes, based on all the
information providedby acontroller,thattheriskofinfringement of datausers’fundamental
rights warrants a suspension order, a controller can hardly rely on its own inadequate
assessment to complain that such suspension is unfair.
250.TikTok’s interpretation is also unworkable in practice. It would, in effect, require
supervising authorities to assess the level of protection provided to personal data in all third
countries to which personal data is transferred from the EU. Moreover, they would have to
do it in respect of every type of transfer which was taking place. This is an administrative
burden which would simply beoverwhelming, andall tofacilitatethosewhowish totransfer
personal data outside the region in which the protection afforded by the GDPR is available.
The result, inevitably, is that the purpose of the GDPR would be grossly undermined.
TikTok’s vision of the GDPR as imposing obligations on supervising authorities rather than
controllers must be rejected, on this ground at least.
Alleged reversal of burden of proof
Arguments
251.TikTok also argues that the DPC reversed the burden of proof by requiring it to prove
compliance withArticle 46, and, in effect, made a presumption of guilt in requiring TikTok
to demonstrate that the personal data transferred to China was subject to essentially
equivalent protection to that guaranteed in the EU. In this regard, TikTok relies on its
contention that, having regard to the severity of the sanctions imposed by the GDPR, it is
entitled to the benefit of the procedural rights guaranteed in criminal proceedings and that a
reversal of the burden of proof is impermissible.252.TikTok refers to Case T-141/08, E.On Energie v European Commission as an example
of a regulator impermissibly reversing the burden of proof. In that case, the Commission
carried out an inspection at the applicant’s premises for the purpose of investigating a
competition law complaint. It sealed the premises pending completion of the inspection, but
when it returned the seal had been broken. Following an investigation, the Commission
made a finding that the applicant had broken the seal and “at least negligently” infringed
the relevant Regulation. It imposed a fine of €38 million. The applicant sought to annul that
decision claiming, inter alia, that the Commission had failed to have regard to the burden
of proof. TikTok references the following from the General Court’s judgment (at §48):
“Under Article 2 of Regulation No 1/2003 and according to settled case-law relating to
the application ofArticles 81 EC and 82 EC, in thefield of competition law,where there
is a dispute as to the existence of an infringement, it is for the Commission to prove the
infringements found by it and to adduce evidence capable of demonstrating to the
requisite legal standard the existence of the circumstances constituting an
infringement... … For that purpose, it must gather sufficiently precise and consistent
evidence to support the firm conviction that the alleged infringement took place…”
253.And at §74 - §76:
“As was recalled in paragraph 48 above, in the field of competition law, it is for the
Commission to prove the infringements found by it and to adduce evidence capable of
demonstrating to the requisite legal standard the existence of the circumstances
constituting an infringement. For that purpose, it must gather sufficiently precise and
consistent evidence to support the firm conviction that the alleged infringement took
place.
It should also be noted that, for the purpose of complying with the principle of good
administration, the Commission must play its part, using the means available to it, in
ascertaining the relevant facts and circumstances …
The guarantees conferred by the Community legal order include, in particular, the duty
of thecompetent institution to examine carefullyandimpartiallyall therelevant aspects
of the individual case …” 254.The DPC argues that it was merely applying the GDPR as interpreted by Schrems II.
There was, therefore, no error of law by it in its approach to the Inquiry. Any complaint by
TikTok is a complaint about the GDPR, not the Decision. The DPC denies, in any event,
that there has been any reversal of the burden of proof. Consistent with E.On Energie, the
legal and evidential burden remained on the DPC to prove that TikTok’s assessment of the
level of protection afforded to personal data to be transferred to China was inadequate.
Discussion
255.In order to address this argument, it is necessary to understand whatTikTok’s complaint
actually is. It seems to argue that it was required to prove its innocence by demonstrating
that data transfers by it to a third country, China, were subject to an equivalent level of
protection to that guaranteed within the EU, and that this is impermissible having regard to
the criminal sanctions which can be imposed in the event of a finding of infringement. For
the purpose of this argument, I accept that the administrative fines which can be imposed
under the GDPR, having regard to their severity, should be regarded as criminal in nature.
256.Thefirst, and complete, answerto this complaint is that insofar asTikTok wererequired
to be able to demonstrate anything, that was not an obligation imposed by the DPC, but an
obligation imposed by the GDPR, for the reasons explained in the paragraphs immediately
above. There was no error by the DPC in interpreting the GDPR as it did. There is no
challenge to the GDPR in these proceedings, and therefore, no basis for impugning the
DPC’s decision on this ground.
257.The only viable argument TikTok could pursue by reference to a purported
impermissible reversal of the burden of proof is that such reversal is always impermissible
and, accordingly, the GDPR must be interpreted in such a way as to ensure that there is no
impermissible reversal of the burden of proof. There are a number of difficulties with this
argument.
258.First, insofar as I have concluded that the GDPR imposes an obligation on controllers
to be able to demonstrate that personal data transferred to third countries is subject toequivalent levels of protection, that is the only plausible interpretation of the GDPR
available. It is consistent with a literal and purposive interpretation of the GDPR, ensuring
a high level of protection for personal data. TikTok’s contrary interpretation, that it need
only satisfyitselfthat thereis sufficientprotection,andthatit is for thesupervising authority
to demonstrate that there isn’t equivalent levels of protection is inconsistent with the express
terms of the GDPR, requires the provisions ofArticles 5(2) and 24 to be disregarded, and is
at odds with the purpose of the GDPR, undermining some of its essential protections.
259.In any event, such reversal is not always impermissible. As discussed above,
presumptions of fact and law are a feature of all legal systems and, per Janosevic, states are
“required to strike a balance between the importance of what is at stake and the rights of
the defence; in other words, the means employed have to be reasonably proportionate to the
legitimate aim sought to be achieved.”
260.But second, and more importantly, I am not satisfied that the finding of an infringement
in this case involved a reversal of any burden of proof at all.Article 46 prohibits the transfer
of personal data outside the EEA unless certain conditions are met, i.e. the controller has
ensured or verified that there is essentially equivalent protection afforded to that data in the
third country to that guaranteed in the EEA, and is able to demonstrate that that is so. In
order for a supervising authority to find an infringement of the GDPR, the supervising
authority must prove that the controller has not verified that the data is adequately protected
and/or is unable to demonstrate that it is. The legal and evidential burden at all times
remained and remains on the DPC. In the case of an inadequate assessment, the DPC must
prove that it is inadequate, by showing that it contains errors or by showing that it is
incomplete.
261.Though TikTok relies on certain statements of principle in E.On Energie, it does not
refer to the following:
“55. However, in the same way as, where the Commission relies, in establishing an
infringement of Articles 81 EC and 82 EC, on documentary evidence, the burden is on
the undertakings concerned not only to put forward a plausible alternative to the
Commission’s view but also to allege that the evidence relied on in the contested
decision to establish the existence of the infringement is insufficient… it must be held
that, in a case such as this, where the Commission relies on direct evidence, it is for the undertakings concerned to demonstrate that the evidence relied on by the Commission
is insufficient. It has already been ruled that such a reversal of the burden of proof does
not infringe the principle of the presumption of innocence …”
262.Moreover, it ignores the court’s analysis of what the Commission had actually done and
the fact that it rejected the applicant’s complaints. At §85 of the judgment, the court noted
that it is was for the Commission to prove the breach of the seal, but it was “not its
responsibility to demonstrate that the room which had been sealed was actually entered or
that the documents stored there were tampered with.”
263.In this regard, it should be recalled that it is undisputed that personal data transferred to
China is, absent additional protections, not afforded equivalent protection to that guaranteed
within the EEA.That was and isTikTok’s unequivocal position. In those circumstances, two
key elements necessary to show an infringement of Article 46, that personal data had been
transferred outside the EEA to China, and that personal data is not afforded equivalent
protection in China had clearly been established. The only issue, as we will see, is whether,
having regard to the particular circumstances of the transfers and the additional measures
put in place by TikTok, it could be shown that these particular transfers were,
notwithstanding the general position, afforded equivalent protection. The DPC concluded
on the evidence that that had not been established. There is nothing impermissible about an
inquiry which examines TikTok’s purported verification of its contention that there was
equivalent protection and determines whether, as a matter of fact, it shows what TikTok
contends. The approach taken by the DPC was consistent with that adopted by the
Commission in E.On Energie, confirmed to have respected the rights of the defence by the
General Court.
264.I note that TikTok’s arguments were focussed on the burden of proof and were not
addressed to the standard of proof, whether on a controller in showing that it has adequately
assessed the level of protection on a third country, or on a supervising authority to prove
that it had not. In the circumstances of this case where the DPC’s conclusion that TikTok
had not, in effect, addressed at all the level of protection for personal data processed in
China, it was necessary for the DPC only to prove that there was a material gap in the
assessment. As I conclude below, there undoubtedly was. As we will see when discussing the third Xu opinion, more difficult issues will arise where a controller does appear to
address the level of protection available, but in a manner which is unclear or unconvincing.
Alleged requirement to carry out risk assessment
Arguments
265.The final argument advanced by TikTok under this heading relates to a purported
requirement on the DPC to carry out a risk assessment both in determining the measures
necessary in order to ensure equivalent protection (an argument revisited at Ground 11), and
also in determining whether there was an infringement. This plea, accordingly, is addressed
to both the infringement finding and the suspension order.
266.The necessity for a risk assessment is an issue which TikTok raised in its response to
the PDD. As set out therein, TikTok argue that the requirement for the DPC to assess the
risk to data users’ rights arises, firstly, from Article 24(1) of the GDPR which imposes a
requirement on a controller to put in place appropriate measures “[t]aking into account the
nature, scope, context and purposes of processing as well as the risks of varying likelihood
and severity for the rights and freedoms of natural persons”, also reflected in Recital 76 of
the GDPR. Implicit in this, argues TikTok, is that a controller is only required to put in place
measures which are proportionate to the risks posed, not to guarantee no risk whatsoever,
however theoretical or remote, and that the DPC was required to assess whether there had
been an infringement of Article 46 on that basis.
267.This is confirmed, it argues, bythe EDPB SupplementaryMeasures Recommendations,
which the DPC purported to follow.
268.§43.3 of that document sets out:
43.3 The assessment may reveal that relevant legislation in the third country may be
problematic and that the transferred data and/or the importer at hand fall or might
fall within the scope of this problematic legislation. Inlightofuncertaintiessurroundingthepotentialapplicationofproblematiclegislation
to your transfer, you may then decide to:
• Suspend the transfer;
• Implement supplementary measures to prevent the risk of potential application to
your importer and/or to your transferred data of laws and/or practices of the third
country of the data importer, which are capable of impinging on the transfer tool’s
contractual guarantees of an essentially equivalent level of protection to that
guaranteed in the EEA; or
• Alternatively, you may decide to proceed with the transfer without being required
to implement supplementary measures, if you consider that you have no reason to
believethat relevant and problematiclegislationwill beapplied,in practice,to your
transferred data and/or importer. You will need to have demonstrated and
documented through your assessment, where appropriate in collaboration with the
importer, that the law is not interpreted and/or applied in practice so as to cover
your transferred data and importer, also taking into account the experience of other
actors operating within the same sector and/or related to similar transferred
personal data and the additional sources of information described further below.
Therefore, you will need to have demonstrated and documented with a detailed report
that problematic legislation will not be applied in practice to your transferred data
and/or importer, and, consequently, that it will not prevent the importer from fulfilling
its obligations under the Article 46 GDPR transfer tool.
269.TikTok notes that the Decision refers, at §511, to the EDPB Supplementary Measures
Recommendations but fails to advert to the third bullet point above.
270.TikTok argues that the requirement for a risk-based approach is also supported by
Schrems II and points to various passages from the CJEU’s judgment.
271.In its response to the PDD, TikTok returns to the requirement for a risk-based approach
when addressing the corrective measures proposed by the DPC. It contends that the EDPB
Supplementary Measures provide that “where there is no reason to believe that potentiallyproblematic laws may be applied in the specific circumstances of a transfer, that transfer
may proceed in accordance with the GDPR”, again referring to §43.3 of that document.
272.It identifies a series of factors which it suggests means that there is no actual risk to
EEA user data and, accordingly, no basis for making a suspension order, including the
evidence from the various legal experts that Chinese authorities had never attempted to
access data from companies in a similar position to TikTok, i.e. which did not provide a
service within China, and that no request had ever been made of TikTok.
273.TikTok argues that the DPC misdirected itself at law by considering that, in the event
of an infringement finding, it was obliged to make the suspension order. It refers to the
following passage from the Decision (at §261):
In the context of this Inquiry, it is the responsibilityof the DPC to review the assessment
made by TikTok Ireland in the exercise of its powers under, inter alia, Article 57(1)(a)
GDPR, to ascertain whether the transfers the subject of this Inquiry comply with the
requirements laid down in the GDPR. The Schrems II judgment makes clear that if
TikTok Ireland is not able to guarantee a level of protection essentially equivalent to
that guaranteed within the European Union, then the DPC, as the competent
supervisory authority is required to suspend or end the transfers if TikTok Ireland has
itself failed to suspend or end them.
274.Asimilar statement is contained at §675 of the Decision.
275.In its written submissions, the DPC does not address this last point, but does contend
that it considered the risks to EEA user data in concluding that there was an infringement,
and when deciding to make the suspension order.Accordingly, notwithstanding its apparent
statements at §261 and §675 of the Decision that it was obliged to make the suspension
order having concluded that TikTok could not ensure the level of protection guaranteed
within the EU, it appears to accept that some form of assessment of whether such an order
was necessitated was required.Discussion
276.It is appropriate first to address the suggestion that the DPC erred in not carrying out a
risk assessment to determine whether there had been an infringement at all. In light of its
conclusion that TikTok had failed to assess whether there was equivalent protection
available, it is difficult to see how the DPC could have reached any conclusion other than
that this was an infringement. Where there is an inadequate consideration of the level of
protection afforded to personal data in the third country to which personal data is to be
transferred, any assessment of risk by the controller is necessarily compromised. I do not
rule out the possibility that a supervising authority might nonetheless conclude that there is,
in fact, no meaningful risk, but in a case where a controller is transferring very significant
amounts of personal data belonging to millions of users, it is very difficult to see any basis
upon which the DPC could have said that there was no breach of Article 46. Having
determined that there was an infringement, it was, of course, then required to consider
whether to impose an administrative fine or make a corrective order, but it could not but
have concluded that TikTok had infringed.
277.Despitedenying its relevanceto theinterpretation ofArticle46,TikTokrelies onArticle
24 of the GDPR. This provides, as we have seen that a controller take into account the risks
to the rights and freedoms of natural persons when designing technical and organisational
measures to ensure that processing is performed in accordance with the GDPR. TikTok,
correctly in my view, and consistent with the EDPB Supplementary Measures
Recommendations, interprets this as allowing a risk-based assessment by a controller in
determining what measures to put in place. It incorrectly interprets this as imposing an
obligation on a supervising authority to carry out that risk assessment where a controller has
not done so even for the purpose of finding an infringement. In truth, TikTok’s argument in
this regard is another manifestation of its complaint that a supervising authority can only
make a finding of infringement where it proves that data has been transferred which was not
afforded essentially equivalent protection.
278.The risk-based assessment to be conducted by the controller is, necessarily, a prior
assessment. By correctly identifying the level of protection available and the risks that any
deficit in protection might create for the rights and freedoms of data subjects, a controller
can design measures to ensure equivalent protection is guaranteed, decide not to transfer thedata, or decide to transfer the data without further protections where the risk is purely
theoretical. It is a necessary pre-requisite to proper decision-making by the controller that it
has, in fact, adequately assessed the level of protection. If there is a failure by the controller
to do what is required of it, adequately identify the level of protection available, then its risk
assessment and design of measures is necessarily compromised. That is sufficient for a
supervising authority to determine that there has been an infringement of the GDPR. For
that purpose, it is not necessary for a supervising authority to carry out its own risk
assessment to determine whether, notwithstanding the falling short by the controller, there
is no actual risk to data subjects’rights.
279.TikTok’s reliance on the EDPB Supplementary Measures Recommendations in this
respect is also misplaced. It is true that the Recommendations do envisage that a controller,
having correctly identified that there is a theoretical lack of equivalent protection could
decide to make a transfer without putting in place measures to address any deficit where
there is no reason to believe that there is in fact any risk, but only if this analysis is
demonstrated and documented. TikTok appears to suggest, that where a controller fails to
identify whether there is a lack of equivalent protection, and necessarily therefore fails to
assess the risk posed by an identified lack of protection and demonstrate and document why
it is nonetheless considered safe to proceed with a transfer, the DPC should have carried out
theanalysis thatTikTok failed to beforefinding an infringement.That is plainly not thecase.
280.In the particular circumstances of this case, somewhat different considerations arise for
the purpose of considering whether a corrective order requires to be made, or an
administrative fine should be imposed. Since controllers are not entitled to transfer personal
data to third countries unless effectively equivalent protection is guaranteed, where a
decision-maker finds that effectively equivalent protection is not guaranteed in a third
country, because there is no adequate assessment which establishes the level of protection
which is available, the further transfer of personal data will typically not be permitted.
281.In this regard, it is important to distinguish the position here, where the DPC found that
TikTok had failed to adequately assess the level of protection available, and that at issue in
Schrems II, where there had been such an assessment, and a conclusion that there was
inadequate protection available. In those latter circumstances, as Schrems II makes clear, the
supervising authority is obliged to suspend the transfer of data where the controller has notalready done so. In this instance, the DPC finding of infringement related to a failure of
assessment not a failure of protection.
282.Ofcourse,thereasonthattheCJEUconcludedthatitwasnecessarytosuspendtransfers
in the scenario considered in Schrems II was because essentially equivalent protection could
not, as required by the GDPR, be guaranteed. Where there has been a failure in assessment
of the level of protection actually available, then, necessarily, equivalent protection cannot
be guaranteed. In those circumstances, it would normally follow from a finding that a
controller had not assessed, or adequately assessed, the level of protection in a third country
that any further transfers should be suspended until an adequate assessment is completed,
and equivalent protection can be guaranteed.
283.However, in this instance, the DPC elected to fix the temporal scope of the Inquiry as
ending at 17 May 2023. Its finding of infringement was, accordingly, made on the basis of
a different factual scenario than that which existed at the time of its decision to make the
suspension order. Significant changes had been made byTikTok since that date, and detailed
additional information had been provided, all of which the DPC had repeatedly stated it
would have regard to for the purpose of the Inquiry. Though, as discussed below, it is
difficult to see howTikTok was prejudiced by the DPC’s decision in relation to the temporal
scope for the purpose of the infringement finding, it would clearly have been prejudiced if
the DPC did not consider that additional information in determining whether,
notwithstanding the infringement finding, it was appropriate to make a suspension order.
284.The infringement finding was a finding of historic non-compliance. There is nothing in
the GDPR or Schrems II which suggests that such a finding necessitates a prospective
suspension.
285.Moreover, Recital 129 of the GDPR provides that “each [corrective] measure should
be appropriate, necessary and proportionate in view of ensuring compliance with this
Regulation.”That must apply with particular force in this case where the corrective measure
was being imposed almost two years after the temporal scope of the Inquiry and, therefore,
of the infringement finding, and where the DPC acknowledged that significant changes had
been made to the manner in which the transfers took place. An automatic suspension of
transfers in those circumstances would not necessarily be proportionate. 286.Although the Decision refers to Schrems II and the obligation to suspend where
essentially equivalent protection is not guaranteed, it is plain that the DPC in fact carried
out a detailed assessment of whether a suspension order was appropriate in the
circumstances, as recorded in the Decision (at §682):
682. In order for any corrective measure be appropriate, necessary and
proportionate, where there is a choice between several appropriate measures, recourse
must be had to the least onerous. It is important to note that the appropriateness of the
relevant measures is determined by reference to the objective to be achieved. In this
instance, the objective is to ensure compliance with the GDPR following an
infringement of Article 46 GDPR.
287.As we will see, as part of that assessment, it concluded that TikTok still had not
adequately assessed the level of protection available in China. It also concluded that the
other supplementary measures relied on byTikTok did not overcome this failure.The merits
of those conclusions are addressed below, but TikTok has not identified any error of law in
the approach taken by the DPC.
Overall conclusion on Ground 3
288.In the circumstances, Ground 3 of the grounds of appeal is rejected.
289.The DPC did not misdirect itself in law, and did not misinterpret Schrems II. It had
appropriate regard to Article 5(1) and 24 of the GDPR when interpreting Article 46. There
was no impermissible reversal of the burden of proof in making the Decision. There was no
error in the Decision by reason of the DPC’s failure to carry out a risk assessment. No issue
ofrisk assessment arosein relation to its finding ofinfringement. Itappropriatelyconsidered
the proportionality of the suspension order before making it.Grounds 1 – Breach of fair procedures
290.At Ground 1 of its appeal, TikTok alleges various breaches of fair procedures.
291.Firstly, and perhaps fundamentally, at Ground 1(a) it argues that it was not notified of
the concern upon which the DPC relied to make its first finding, that TikTok had transferred
data in breach of Article 46(1), and therefore it was not in a position to address it directly.
This, claims TikTok, was a breach of the right of the defence, that a person must be put in a
position to know the case against them and be given an opportunity to respond. It referred
to a number of cases in support of this general proposition, including Case C-530/12, OHIM
v National Lottery in which the CJEU observed (at §54):
“The rule that the parties should be heard does not merely confer on each party to
proceedings the right to be apprised of the documents produced and observations made
to the Court by the otherparty and to discuss them. It also implies a right for the parties
to be apprised of the matters raised by those courts of their own motion, on which they
intend basing their decision, and to discuss them. In order to satisfy the requirements
relating to the right to a fair hearing, it is important for the parties to be apprised of,
and to be able to debate and be heard on, the matters of fact and of law which will
determine the outcome of the proceedings (Commission v Ireland and Others,
paragraphs 55 and 56, and Case C-472/11 Banif Plus Bank [2013] ECR, paragraph
30).”
292.In the alternative, it argues at Ground 1(b) that it had, in fact, provided information
which addressed the DPC’s concern, in particular, at footnote 113 of the July 2024 DTA,
and also in the second and third Xu opinions, and that the DPC failed to have adequate
regard to that information. This ground overlaps to a significant degree with Ground 2 of its
appeal by which TikTok contends that the DPC made a manifest error in concluding that the
issue of concern had not been addressed byTikTok. Put otherwise, TikTok claims that either
the DPC disregarded relevant information (the contents of the July 2024 DTA and the Xu
opinions), amounting to a breach of fair procedures, or if it did have regard to the relevant
information, it erred in its understanding of it.293.TikTok also pleads, at Ground 1(c), that the DPC erred in its assessment of the material
provided by the DPC regarding Project Clover. In particular, it contends that the DPC failed
to put its findings regarding Project Clover to TikTok and afford it an opportunity to address
them and, in any event, failed to have adequate regard to those submissions.At Ground 10,
TikTok alleges material errors in the assessment of the Project Clover information. There is
a clear overlap between these grounds.
294.TikTok pleads, at Ground 1(d), that the amendment of the temporal scope of the Inquiry
from “ongoing” to a scope concluding on 17 May 2023 (the date of the PDD) breached its
legitimate expectation and was in breach of fair procedures. In this regard, it contends that
the amendment of the temporal scope meant that the DPC did not assess, or assessed only
cursorily, information provided by TikTok after the PDD, contrary to assurances to the
contrary, and in any event, only considered that information insofar as it related to the
question of suspension and not in relation to the infringement.
295.Finally, TikTok pleads, at Ground 1(e), that it was unlawfully denied access to the
DPC’s file both during the Inquiry, when it requested the file after receipt of the Draft
Decision, and again following receipt of the Decision.
296.TikTok also makes a more generalised complaint, articulated in oral submissions
regarding the failure of the DPC to engage with it, in particular, its purported failure to seek
clarifications, to highlight areas which had not been addressed, or to meet with TikTok,
particularly having regard to the significance of the issue forTikTok. It refers to the decision
in Shatter v Guerin [2021] 2 IR 415 (at p. 520):
“... the level of fair procedures must relate to and be a proportionate engagement (i)
with the declared concerns of the decision-maker, which, if left at such level, would be
published in that form and (ii), with a reasonable appreciation, objectively realised, of
the imputations on character which such published concerns may give rise to.”
297.Before considering each of these alleged deficiencies in turn, it is important to recall
what is stated above regarding the scope of the appeal. In principle, breaches of fair
procedures are capable of being remedied by an appeal, where an appeal is available.Where
a breach of fair procedures is not capable of being remedied by an appeal, then the appropriate remedy is judicial review. Though TikTok has also issued judicial review
proceedings, it has elected to pursue its statutory entitlement to appeal. It seems to me,
therefore, that for the purpose of this appeal it is required to accept that the breaches of fair
procedure it identifies are at least capable of being remedied in this appeal. In an appeal, as
in this case, where an appellant is in principle entitled to adduce new evidence, the appeal
mechanism must be regarded as effective to address any procedural deficiency before the
DPC. I do not accept, therefore, the argument advanced in oral submissions and in its
supplemental written submissions that identifying a breach of fair procedures is necessarily
a basis for TikTok to succeed in its appeal. Rather the consequences of any breach must be
considered in the context of the appeal as a whole.
Failure to put adverse findings to TikTok
Arguments
298.The main complaint made by TikTok under this heading is that the DPC’s concerns
altered dramatically between the PDD and the Draft Decision. TikTok says that it addressed
the complaints identified in the PDD but was never given an opportunity to address “new”
concerns identified for the first time in the Draft Decision. In particular, TikTok argue that
the PDD identified, in paragraph 253, that “two key concerns” remained, and that these were
set out at paragraphs 254 to 257, quoted above, and reiterated at paragraphs 368 – 371.
TikTok’s position is that it fully addressed those concerns, but contends that it could not
have understood from the PDD that the DPC was concerned about the issue which led to its
finding of infringement, the extent of protection afforded to personal data while it was being
processed in China, which I will refer to as the “local processing concern” or the “local
processing issue”. TikTok argues that it was, therefore, prevented, in breach of fair
procedures, from having an opportunity to meet the case being made against it. When it
became aware of this new concern being relied on by the DPC, upon receipt of the Draft
Decision, it sought an opportunity to address this new concern and requested that the Draft
Decision be withdrawn. It supplied additional information, including the third Xu opinion,
but this request was rebuffed and the new information disregarded.
299.TikTok contends that it was a requirement of EU law that the DPC provide its
preliminary views to it, citing Case C-349/07, Sopropé at §36- 37, although that decisionsays no more than that the addressee of a decision which significantly affects its interests
must be put in a position where it can make known its views on the information on which
the authority intends to base its decision. As the parties note, the requirement to draft
preliminary findings is now included in Article 19(1) of the Procedural Regulation for
GDPR Enforcement (Regulation (EU) 2025/2518). Article 19(7) provides that those under
investigation shall be given an opportunity to reply. However, the parties agree that the
Regulations are not applicable to this Inquiry as they will only apply from 2April 2027 (per
Article 37).
300.In any event,TikTok argues that the same protections apply as a matter of domestic law,
citing Shatter v Guerin and Zalewski v Workplace Relations Commission [2022] 1 IR 421.
301.TikTok argued throughout the Inquiry that the DPC should issue a revised PDD where
circumstances changed, or it identified new concerns, or TikTok highlighted errors in its
analysis. Its pleaded case was that the DPC was under an obligation to do so, but in oral
argument, it appeared to accept that there was no particular form or procedure which the
DPC was required to adopt, rather what was essential was that TikTok be given an
opportunity to address any issue which the DPC might rely on for the purpose of making a
finding against it.
302.The DPC denies that it raised any new issue in the Draft Decision (or Decision) and
says that all of its concerns had been clearly flagged in the course of the Inquiry and in the
PDD. There was, accordingly, no breach of fair procedures. Though TikTok sought to
adduce additional information after delivery of the Draft Decision, the DPC says it was
under no obligation to consider it, having regard to the stage of the procedure at which it
was delivered. In any event, it argues, the additional information, in particular the third Xu
opinion, did not address the DPC’s concerns.
303.As regards the requirements of fair procedures generally, the DPC highlights the
observations of the court (Barniville J, as he then was) in Facebook Ireland Ltd v DPC
[2021] IEHC 336 (at §263):
“It is clear from the GDPR and from the judgment of the CJEU in Schrems II that it is
necessary for the supervisory authority to balance and attempt to reconcile the right to be heard and to fair procedures on the part of those who are the subject of an
investigation or inquiry conducted by a supervisory authority against the obligations
on the supervisory authority to act within a reasonable time and with due diligence in
determining whether the GDPR has been infringed and in determining what, if any,
corrective powers should be exercised. That can be a difficult balance for the
supervisory authority and, in this case, the DPC, to achieve, but both rights and
obligations must be properly taken into account by the supervisory authority in terms
of the procedures which it applies. One does not necessarily trump the other and
individual assessment will be required to be made by the supervisory authority in each
case.”
304.Insofar as the DPC did provide its preliminary findings to TikTok, it does not argue that
it was free to rely on entirely new issues in reaching the Decision, but argues that its final
findings were not required to “correspond precisely” with the provisional findings, and
references Cases T-194/06, SNIA at §80 and T-344/17, Latam Airlines Group at §210 and
§216. It argues that it did no more than “develop” the preliminary findings in response to
the submissions received and that there was no significant change to the fundamental issues
identified in the PDD.
305.The position in relation to the third Xu opinion is somewhat opaque. At §691 of the
Decision, as referred to above, it is stated that regard was had to material submitted after the
Draft Decision, including this report, but that it did not address the DPC’s concerns. In its
letter of 25 March 2025, it stated that “... even considering TikTok Ireland’s most recent
correspondence in the context of the ongoing transfers, it is clear that fundamental flaws
identified in the Draft Decision remain unaddressed and ongoing” which suggests that the
contents of TikTok’s correspondence, including the third Xu opinion, had been assessed,
albeit the reasons for concluding that flaws remained is not set out.
306.However, the various pleas in relation to this issue in the Statement of Opposition are
to the effect that the DPC was not required to have regard to that opinion, having regard to
the late stage at which it was submitted.At §109.5 of the Statement of Opposition, the DPC
seeks to “contextualise” the statement at §691 of the Decision: While the DPC had regard to the fact that TikTok Ireland had submitted the Third Xu
Opinion, in circumstances where the Third Xu Opinion was submitted three weeks after
the submission by the DPC of the Draft Decision to the Article 60 Process, it is evident
that the reasoning of theDraft Decision could not at that stage be altered having regard
to the content of the Third Xu Opinion, and it is not contended that the content of the
Third Xu Opinion is addressed in the Decision. The DPC did not consider that the Third
Xu Opinion required or justified the withdrawal of the Draft Decision from the Article
60 process by reason of the timing of its receipt and for the reasons identified in the
DPCs correspondence of 25 March 2025. In that respect, and for the avoidance of
doubt, it is not accepted that the Third Xu Opinion addresses the DPCs concerns with
respect to the application of the Relevant Chinese Laws to the Transfers or is such as
to require alteration of the DPCs conclusion with respect to the corrective measures
required.
307.The Statement of Opposition is verified by Mr Cian O’Brien, a deputy commissioner,
who is head of the unit within the DPC which had carriage of the Inquiry. He was not,
however, the decision-maker.
Discussion
308.It is, at first blush, surprising that TikTok would suggest that the DPC’s identification
in the Draft Decision of concern about the level of protection afforded to personal data
transferred to China while it is being processed in China was a new issue. The fact that data
was being transferred to China and processed there was, from the outset, the subject of the
Inquiry. It’s why there was an inquiry. More importantly, perhaps, it is the very issue which
Article 46 required TikTok to address. In fact, this is true even on TikTok’s narrow (and, as
I have concluded, mistaken) view of the scope of Article 46. Even if TikTok was only
requiredtosatisfyitselfthatequivalentprotectionwasavailableforpersonaldatatransferred
to China, without any obligation to be able to demonstrate that this was so, it was the data
actually transferred which required to be assessed.
309.To explain, the GDPR is primarily concerned with processing of personal data. This is
apparent fromArticles 5 and 24, discussedabove.Therearealso, ofcourse, rights associatedwith the retention of data by controllers and processors, albeit not at issue in this appeal.
Processing is defined broadly in the GDPR, inArticle 4(2), set out above.
310.Article 44 concerns transfers of personal data outside the EU, but it doesn’t define
transfers. It applies, however, to transfers which “are undergoing processing or are intended
for processing after transfer to a third country.” That, therefore, determines the scope of
Article 46. It is concerned with data which is actually transferred and is undergoing
processing or is to be processed in third countries. The focus of any inquiry into compliance
with Article 46, on whatever view one takes of that provision, must always be on the
personal data that is transferred and processed.
311.That this was so in this case was apparent from the outset. The Notice of
Commencement refers to the CGE personnel “accessing” personal data of TikTok users in
order to provide support services connected with the operation of the Platform. It states that
those transfers will be the subject of the Inquiry, i.e. the personal data which was being
accessed.
312.TikTok’s reply to the Notice highlighted the storage of data outside China and
significant access restrictions on those who could access the data from China. It updated its
DTAas described above.
313.The DPC’s second RFI raised detailed queries. It expressly asked what was the
technical means by which data was remotely accessed. In response, TikTok once again
referred to storage outside China, and referred back to the access restrictions described in
its first response. It did not explain in any detail the technical means by which data was
accessed, only the restrictions on how that data was accessed.
314.The DPC then issued a Statement of Issues in which, it stated, it was not expressing any
preliminary views. In its responses and DTAs, TikTok repeated its reliance on the fact that
remotely accessible data was stored outside China and therefore outside the jurisdiction of
the Chinese authorities.
315.At paragraph 74 of the PDD, the DPC stated: The concept of a “transfer to a third country” is not defined in the GDPR. However, the
EDPB has clarified that both “remote access from a third country (for example in
support situations) and/or storage in a cloud situated outside the EEA offered by a
service provider, is […] considered to be a transfer.” It is clear that remote access to
personal data of EEA users by personnel of the China Group Entities falls within the
concept of a “transfer” for the purpose of Chapter V of the GDPR.
316.This is accepted by TikTok. It is against that background one must consider TikTok’s
claim of breach of fair procedures having regard to the contents of the PDD. Insofar as the
PDD raises concerns about the ability of Chinese authorities to access data stored outside
China, it may be that the DPC was distracted by TikTok’s focus on the territoriality issue.
Data stored outside China and not accessed remotely from China was not data transferred
within the meaning of Chapter V (the DPC made clear that it was not concerned with any
transfers other than those to China for the purpose of the Inquiry). Data stored on servers
outside China does not give rise to any issue under Chapter V of the GDPR not because of
the territoriality principle, but because it is not data transferred to China at all: it is outside
the scope of Chapter V. The only data with which the DPC should or could have been
concerned was the data actually transferred to and processed in China. This is not to suggest
that no issue might arise under the GDPR where such data is accessible, only that no issue
appears to arise under Chapter V.
317.Although TikTok repeatedly stated that the DPC’s concerns were all about storage, in
truth it was TikTok who sought to make storage the issue. Where the data was stored is
relevant because of TikTok’s reliance on the territoriality principle. It, however, was never
the subject of the Inquiry. Rather, it was TikTok’s answer to the concerns raised.
318.Those concerns, as we have seen, were reduced to “two key concerns” in the PDD.
TikTok characterise the two concerns as the “extraterritorial application concern” and the
“foreign server concern”. In this regard, it says that the extraterritorial application concern,
expressed in §254 of the PDD, was whether the relevant Chinese laws applied extra-
territorially. It says that the foreign server concern, expressed in §255- 256 of the PDD, was
whether, in effect, the CGEs or their employees could be compelled to provide assistance in
accessing data stored outside China. As noted by TikTok in its oral submissions, this issueof compellability was the focus of the DPC’s concerns in its analysis of Issue 3 (§368 – 371
of the PDD).
319.The DPC’s characterisation of the two key concerns, in its written submissions, is that
the first concern related to the extraterritorial effect of the relevant Chinese laws, and,
therefore, it agrees with what TikTok contends was the first concern. It rejects TikTok’s
characterisation of the second concern, which it states related to the application of the
territoriality principle in the “specific factual context of the Data Transfers”.
320.Neither party’s characterisation reflects how the second concern was described in the
Decision, which does state (at §354) it was the application of the territoriality principle in
the specific factual context of the Data Transfers, but that this concern was based on two
issues, first, the compellability of CGEs and their employees, and second, vagueness as to
the exact contours of the territoriality principle.
321.The precise characterisation of the concerns identified in the PDD is less relevant than
is the question of whether TikTok was given a fair opportunity to address all the DPC’s
concerns, or whether, as it alleges, the findings in the Decision were based on new findings
and concerns not put to TikTok.
322.The specific objection made by TikTok is set out at paragraph 45 of its written
submissions. It says that the DPC “introduced new findings” that remote access results in
EEA User data being processed on computer systems in China as an “inevitable
consequence of any remote access solution” and that “arising from this”, the Draft Decision
introduced a new adverse finding, what it calls the “temporary processing finding”, that
TikTok had not addressed the application of the relevant Chinese laws to the processing
which occurs on computer information systems in China. It contends that this conclusion
was relied on for the purpose of additional adverse findings. It argues that in breach of fair
procedures, it was not given an opportunity to address this concern.
323.Given the emphasis placed by TikTok on the unfairness of the DPC’s reliance on this
“new” finding, it is important to emphasise that TikTok does not dispute the factual basis
underpinning that finding. In fact, in its 11 March 2024 response to the DPC’s fourth RFI,
it states: [The] transitory processing of data is an inevitable consequence of any remote access
solutioninorderforthedatatobeavailabletobedisplayedto,andusedby,therelevant
user on its device. Without this local transitory processing, remote access would not be
possible.
324.It made the same point in its first letter replying to the Draft Decision in which it
contended that the DPC had erred in concluding that the local processing issue had not been
addressed. Indeed, one of the errors of assessment claimed by TikTok in the appeal is that
the DPC failed to take into account that transient processing was inherent to the facilitation
of remote access (see §96(c) of TikTok’s written submissions).
325.Moreover, as I have indicated above, the processing of the personal data in China was
necessarily the subject matter of any inquiry into compliance with Article 46. In those
circumstances, it ought to have been no surprise to TikTok that that was the issue which it
was required to address in the Inquiry. TikTok’s complaint, in effect, is that it was led to
believe by the PDD that the only issues with which the DPC remained concerned were those
identified in the PDD as characterised by it, that the processing of data in China was not one
of those concerns, and that it was a breach of fair procedures for the DPC to rely on different
concerns to those identified in the PDD to ground a finding of infringement of the GDPR.
326.I agree with TikTok that, in line with the principles identified in the EU and domestic
case law relied on by it, and the rights of the defence, that it would have been a breach of
fair procedures for the DPC to rely on issues which were not put to TikTok when making
findings that TikTok had breached the GDPR. I do not, however, agree that this is what
occurred here.
327.The processing of the data in China was at all times the subject of the Inquiry and at all
times required to be addressed by TikTok. There is nothing in the PDD which could have
led TikTok to believe that no concerns remained regarding whether effectively equivalent
protection was guaranteed in relation to personal data being processed in China. While this
portion of the judgment is concerned with the allegation of breach of fair procedures, we
will see, when considering Ground 2 of the appeal, I agree with the DPC’s conclusion thatTikTok had not addressed this issue at the time of the PDD (or indeed at any time prior to
its submission of the third Xu opinion).
328.To step back for a moment, TikTok’s thesis is that the data accessed in China is stored
in data centres outside China, and that Chinese authorities have no jurisdiction to compel
access to data which is stored outside China. TikTok has treated this as a full answer to the
question of whether data actually being processed in China was also outside the jurisdiction
of Chinese authorities. It manifestly is not. The fact that Chinese authorities cannot access
data stored overseas, because it is stored overseas, without more, tells us little or nothing
about whether Chinese authorities can access data being processed in China.At the absolute
minimum, it would have been necessary for TikTok to show that there is nothing capable of
being accessed in China, notwithstanding the wholesale processing of data there by CGE
employees, or that as a matter of Chinese law data processed on computers in China but
permanently stored overseas is itself treated as overseas data.As we will see, TikTok never
asserted the former. The first time that anything like the latter was suggested was in the third
Xu opinion.
329. The distinction between where data was stored and where it was processed was
highlighted to TikTok in the second RFI, literally, since the words ‘stored’ and ‘processed’
were underlined in Query V(3). TikTok’s response said nothing about data processed in
China, only data stored outside China.
330.TikTok’s position, since it accepts that it was implicit that data was being processed on
computers in China, is that Chinese authorities would, in effect, accept that they could not
access data being processed in China under any of the relevant Chinese laws because it was
permanently stored overseas. The basis for that proposition was not explained. In any event,
it was the issue which was at the heart of the Inquiry and the DPC had made clear that it had
not been addressed by the time it delivered the second RFI. Since TikTok’s response to that
RFI, and in particular, queries about the technical means of accessing data and the
processing in China ignored the underlying premise of those questions, the fact of the matter
is that it had not been addressed by the time of the PDD.
331.Far from providing comfort to TikTok that this central issue had been adequately
addressed, a fair reading of §254 to §257 of the PDD makes clear that those concernsremained. §254 identifies that the DPC was not satisfied that the relevant Chinee laws did
not apply in the specific factual context of the transfers.The first concern articulated in §254
assumes that TikTok’s explanation of the territoriality principle is accurate but seeks clarity
on those laws which may, in fact, have extra-territorial effect. The second concern makes
clear that the DPC is not convinced that reliance on the territoriality principle is an answer:
The second concern relates to the basis for the premise that TikTok Ireland’s analysis
regarding the application of the territoriality principle in the specific factual context of
the transfers is accurate. The concern itself is that TikTok Ireland has furnished
insufficient information in the Inquiry to enable me to conclude that the territoriality
principle does in fact operate so as to prevent the application of problematic
surveillance laws, such as the Anti-Terrorism Law, Counter-Espionage Law,
Cybersecurity Law and National Intelligence Law, to the personal data of EEA users
the subject of the transfers, save in situations where those laws have extra-territorial
effect.
332.Put in simple terms, TikTok has not explained why the relevant Chinese laws would
need to have extra-territorial effect in order to be applied “in the specific factual context of
the transfers” to the “personal data of EEAusers the subject of the transfers”. Why, in other
words, do these laws not apply to the personal data being processed in China?
333.It identifies in the following paragraphs reasons why it wasn’t satisfied (primarily, the
compellability of CGEs and their employees).At §257, the PDD specifically concludes that
TikTok has been vague about the exact contours of the territoriality principle. In this regard,
it will be recalled that at that stage of the procedure, TikTok’s main basis for contending
compliance with Article 46 was the storage of data outside China and its interpretation of
the territoriality principle. The PDD went on to identify that TikTok had not identified legal
authorities which interpret the principle in the manner they contend for:
… in practice in a scenario that is analogous to the present one, concerning remote
access,usingtechnicalmeans,bypersonswithinthejurisdictionofChinatodatastored
on servers in a foreign jurisdiction.334.TikTokhadeveryopportunitytoadequatelyaddresstheprecisescenariodescribedhere.
At the hearing of the action, I expressly enquired ofTikTok why this wasn’t sufficient to put
it on notice regarding the issue which ultimately formed the basis of the DPC’s infringement
finding and it was suggested that in these paragraphs of the PDD, the DPC was talking about
“accessing the data in the servers” (Transcript, Day 1, p. 25). That may be so, but the
statement at §257 clearly identifies that the concern is with the access by technical means
within China.
335.If there were any doubt regarding whether the DPC was concerned with what was
actually happening in China, the fourth RFI put it up in lights, highlighting that, insofar as
TikTok relied on where data was stored as an answer to any concerns regarding the level of
protection for transferred data, TikTok had not explained how it is that they contended that
data being processed in China was not stored there. TikTok seeks to suggest that a request
for further information after the PDD was unusual and, at least implicitly, criticise the DPC
for raising this query (Transcript, Day 1, p. 21 and p. 87). Its position in this regard is wholly
inconsistent with its claim of its breach of fair procedures and that the DPC should have
issued a revised PDD. Having considered TikTok’s response to the PDD, it was entirely
appropriate for the DPC to have sought clarification on what TikTok was saying. It certainly
provided TikTok with a further opportunity to explain how its remote access solution
ensured essentially equivalent protection for data being processed in China.
336.TikTok’s response is enlightening for what it does and does not contain. It does contain
TikTok’s opinion that there is no storage in China, by reference to Oxford English Dictionary
and Collins Dictionary definitions of the word “storage”. The OED definition it provides is
“the action of storing or laying up in reserve” or store “a stock of anything… laid up for
future use”. It is curious that it did not use the definition provided by the OED relating to
computing “the retention of retrievable data on a computer or other relevant electronic
system”, but the more relevant issue is that it is difficult to see what possible relevance an
OED definition could have to the question of whether, as a matter of Chinese law, data
processed in China by remote access is not regarded as stored there. What is missing from
the response, of course, is any Chinese law analysis of whether the data processed in China
would be regarded as stored there, still less, any Chinese law analysis which suggests that
the relevant Chinese law could not be applied to the data being processed in China. 337.TikTok seek to compare the language in the Decision where it is concluded that the
issue of processing of EEAuser data on computer information systems in China hadn’t been
addressed, with the language used in the PDD to suggest that the Decision was addressed to
issues not raised in the PDD. I do not agree. When one understands that the focus of the
Inquiry was always data transferred to China, when it is accepted by all that processing on
computer systems in China is an inevitable consequence of the remote access solution, the
issues of concern identified in the PDD, and the subsequent RFI gave TikTok a more than
adequate opportunity to address the issue which ultimately led to the first finding of
infringement. If TikTok failed to do so, which I will consider when we turn to Ground 2, it
was not due to any lack of fair procedures.
338.Particularly when considered in context, there was no lack of fair procedures in the
procedure adopted by the DPC. This complaint does not provide any basis for interfering
with the DPC’s conclusion that there had been an infringement ofArticle 46 by TikTok.
Failure to have regard to submissions made
Arguments
339.TikTok’s alternative argument is that even though it was not aware that the processing
of personal data in China remained one of the DPC’s concerns, it did, in fact, address the
level of protection afforded to such processing, in the July 2024 DTA, at footnote 113, and
again in the third Xu opinion, provided after the Draft Decision. It suggests that it had also
implicitly addressed the issue in the second Xu opinion, and that this was expressly
confirmed in his later opinion.
340.The Decision is silent on footnote 113. Insofar as the claim in relation to footnote 113
is a fair procedures claim, it is a claim that the DPC failed to have regard to relevant
information or failed to engage with relevant information. TikTok refers to Balz v An Bord
Pleanála [2023] 3 IR 751 in its submissions to the effect that decision makers must address
relevantsubmissionsandprovideexplanationsforwhytheyarenotaccepted.Infact,TikTok
has not pleaded a claim that the DPC failed to provide reasons for its ‘rejection’of footnote
113 as an answer to the concerns raised in the PDD. The DPC says in response that it was
only required to engage with “significant submissions”, citing NECI v Labour Court [2022]3 IR 515. It argues that footnote 113 does not address its concerns regarding the application
of the territoriality principle to the data transferred to China and in its written and oral
submissions explains why this is so.
341.Theposition in relation to thethirdXu opinionis different.The Decision does reference
the opinion, though only for the purpose of saying it didn’t address the concerns identified
in theDraftDecision. It appeared, therefore,thattheDPC had hadregard to that submission,
but its formal position now, in response to the fair procedures claim, is that it did not address
it in the Decision, nor was it required to because it came so late in the day. In this regard,
the DPC argues that by the time the third Xu opinion was submitted, “the opportunity for
further comment must legitimately be considered to have ceased in all the circumstances”
(DPC legal submissions at §64).
342.In this regard, the DPC refers to the decision in The State (Haverty) vAn Bord Pleanála
[1987] IR 485, highlighting the emphasis placed by the court in that case on achieving
finalityinproceedings.Inthatcase,asuccessfulobjectortoadevelopmentbeforeaplanning
authority was not provided with an opportunity to comment on additional submissions
submitted by the developer in its appeal against the planning authority’s refusal. Though the
DPC is correct as to the court’s conclusion, the full analysis is worth setting out (at pp.
493/494):
“The essence of natural justice is that it requires the application of broad principles of
commonsense and fair play to a given set of circumstances in which a person is acting
judicially. What will be required must vary with the circumstances of the case. At one
end of the spectrum it will be sufficient to afford a party the right to make informal
observations and at the other constitutional justice may dictate that a party concerned
should have the right to be provided with legal aid and to cross-examine witnesses
supporting the case against him. I have no doubt that on an appeal to the planning
board therights ofan objector — as distinctfromadeveloperexercisingpropertyrights
— the requirements of natural justice fall within the former rather than the latter range
of the spectrum. This flows from the nature of the interest which is being protected, the
number of possibleobjectors, thenatureof thefunctionexercisedby theplanning board
and the limited criteria by which appeals are required to be judged and the practical
fact that in any proceedings whether oral or otherwise there must be finality. Some party must have the last word. The substantive reality of the present case is that the
prosecutrix and the Sefton residents' association put forward a detailed professional
argument before the planning authority in the first instance and the planning board in
relation to the appeal. I can appreciate their concern that they might have wished to
expand upon their argument or to raise counter-arguments to those made in reply by
the developers but I have no doubt that the real substance of their case was before An
Bord Pleanála and duly considered by it. If there was in fact a material conflict of
evidence that could not have been resolved by additional submissions or observations.
Disputes of that nature could only be adequately dealt with in an oral hearing.
To avoid misunderstandings perhaps I should make it clear that I do not accept and I
have not accepted any general proposition that An Bord Pleanála could discharge its
obligation to an interested party by delivering part only of the appellant's submission
to any person entitled to receive the same. I could imagine cases in which further
communications from the developer extended the original submission so radically as to
constitute a different or additional case and in that event natural justice might well
requireAnBordPleanála topostponeitsdecisionuntilithadaffordedinterestedparties
an opportunity of commenting upon the revised submission. However, as I say, in the
present case it seems to me that whilst the prosecutrix and her planning adviser do feel
strongly that they would wish to have had an opportunity of amplifying the arguments
which they had made I believe that the requirements of natural justice have been met
so that there are no grounds for granting the order sought. I would allow the cause
shown with no order as to costs.”
343.The DPC also refer to the decision in Klohn v An Bord Pleanála [2009] 1 IR 59 to
similar effect, and to the decision of Barniville J in Facebook Ireland v DPC, referred to
above, regarding the necessity to balance the right to be heard with the obligation on a
supervising authority to act within a reasonable time and with due diligence.Discussion
344.Thereis no real disputebetweentheparties regardingthelegal obligationtohaveregard
to submissions made: there is, of course, no inconsistency between Balz and NECI. Balz
makes clear that it is necessary “that relevant submissions should be addressed and an
explanation given why they are not accepted”. In NECI, MacMenamin J refers to Balz as
making clear that “a decision-maker must engage with significant submissions”.
345. In relation to footnote 113, the question of whether there was any breach of fair
procedures by the DPC in failing to refer to it largely depends, therefore, on whether it does
in fact address the issues raised in the PDD and which led to the findings of infringement,
an issue addressed when considering Ground 2, in other words whether it was relevant to
that issue. It is clear that it was not considered of sufficient relevance by the DPC to warrant
being addressed in its decision. The DPC is correct insofar as it says that the fact that it is
not referred to does not establish that it was not considered. TikTok submitted thousands of
pages of documents to the DPC. Necessarily, not all of that material is referred to in the
Decision. This does not mean that it was disregarded.
346.Footnote 113 is contained in a document which was not prepared as a response to the
PDD or indeed for the purpose of the Inquiry at all, the July 2024 DTA, although the
covering letter enclosing that DTA noted that TikTok expected that the DPC would wish to
haveregardtoitforthepurposeoftheInquiry.Itwascontainedinaportion ofthatdocument
ostensibly addressing a different issue than the local processing issue.Also, and obviously,
it is contained in a footnote, hardly the place where one might expect TikTok to provide an
answer to the DPC’s continuing concerns. Of course, since TikTok claim to have been
unaware of those concerns, it is, in effect, only by chance that TikTok purports to have
addressed them at all.
347.TikTok’s covering letter highlighted what it considered to be the “material” changes
between the July 2024 DTA and the previous DTA. It did not suggest that there was any
significance to the addition of footnote 113, which was a note added to identical text
contained within the previous DTA. Accordingly, the DPC cannot be criticised unduly for
failing to expressly address footnote 113 even if it does prove to have been significant. Be
that as it may, where it is not addressed at all, I do not think that the court should defer tothe DPC’s assessment of it for the purpose of this appeal, whether as to its significance or
its substance, rather it must be assessed solely on its merits. Its significance, or otherwise,
is addressed at Ground 2.
348.It is a little more difficult to understand why the third Xu opinion was not addressed,
or, for present purposes, why the DPC consider that there was no requirement to address it.
I accept that it came late in the day, but the DPC had made a rod for its own back by
reassuring TikTok that it would have regard to all information submitted. Moreover, the
consultation period with the SACs was still open, and the DPC has not argued that there was
a legal impediment to it considering the new information, whether the consultation period
remained open or not. Indeed, it expressly accepts that draft decisions may be withdrawn
from theArticle 60 process (DPC legal submissions at §61).
349.In circumstances where the obligation on TikTok was to confirm that equivalent levels
of protection were guaranteed in advance of transferring data, it would have been entirely
reasonable for the DPC to fix a point beyond which further material would not be accepted.
Haverty, Klohn and Facebook certainly suggest that they would have been so entitled.There
was certainly no general obligation on the DPC to have regard to a continuous stream of
information provided by TikTok for the purpose of addressing something which was
required to have been addressed before any transfer of data was made. However, the DPC
did not stipulate an end to the submission phase of its Inquiry, rather it assured TikTok that
it would consider any new material submitted. The fact that it had issued the Draft Decision
and circulated it pursuant to Article 60 may have led to an understandable reluctance by it
to consider new material or re-consider the Draft Decision, but this alone could not justify
a refusal to do so.
350.What is more, the DPC did consider material submitted by TikTok after the third Xu
Opinion, regarding its audited accounts for the purpose of calculating the fine, and, more
relevantly, regarding updates to Project Clover (see §691 of the Decision). When asked to
explain whyit had regardto theProject Clovermaterial but not thethirdXuopinion,counsel
for the DPC offered the suggestion that the third Xu opinion was more relevant to the
question of whether there was an infringement, whereas the Project Clover measures were
relevant to the question of whether to make a suspension order (Transcript Day 7, pp. 22 –
24). It is not clear that this is so. It may have been the Project Clover measures were notrelevanttotheinfringementfinding,butthethirdXuopinionwasclearlypotentiallyrelevant
to the question of whether the suspension order should be made.
351.Haverty suggests a common-sense approach to fair procedures. In the circumstances of
a planning appeal, where the rights of an objector were at the lower end of the spectrum of
rights engaged, there was no breachof fair procedures in not affordingthat objectora further
right to be heard. The interests of TikTok in the Inquiry are clearly at a different end of the
spectrum to that of the objector in Haverty. Moreover, the DPC had indicated that it would
consider further information received from TikTok and, critically, did consider information
received after the third Xu opinion. Its explanation for so doing was unconvincing since the
third Xu opinion was, at least potentially, as relevant to the proposed suspension order as
were the Project Clover updates. There must be some obligation on a decision-maker to act
consistently in such matters. Although the determination of when to bring an end to an
investigation clearly falls within the discretion of a decision-maker, it is doubtful whether,
consistent with its obligation to act fairly, it can determine that the time for submission of
some material has passed, but at the same time have regard to other material, though
submitted later.
352.In the particular circumstances of the third Xu opinion, the DPC ought, when having
regard to whether to make the supervision order, and consistently with its treatment of the
Project Clover updates, have engaged with the third Xu opinion for the purpose of
determining, at least, whether it added anything material to what had previously been
furnished.
353.The DPC’s letter of 25 March 2025 appears to suggest that the DPC considered that the
contents of the third Xu opinion did not address its concerns. However, it did not provide
any explanation for that view. If the DPC is correct, that the third Xu opinion adds nothing
to what had been submitted previously, then, as with footnote 113, it is difficult to see what
complaint TikTok might have in this appeal. However, if its contents are material, it will be
necessary to consider what the consequences may be for the Decision. I will, accordingly,
consider the opinion when considering Ground 2, the alleged errors made by the DPC.
354.Before considering the next ground concerning the treatment of Project Clover, it is
important to observe the following. The infringement finding of the DPC is confined to a finding that the DPC had infringedArticle 46 during the temporal scope, i.e., up to 17 May
2023. The grounds of challenge in relation to that will be addressed presently. But insofar
as TikTok rely on measures put in place after that date, TikTok faces an obvious challenge
in relying on that material to show that there had been no breach prior to that date. That that
is so in relation to the Project Clover measures is obvious, as these measures were not in
place prior to May 2023 (or at least there is no evidence that they were), and was accepted
by TikTok in oral submission (Transcript Day 1, p. 97).
355.But it is also the case with the material contained in the July 2024 DTA and the third
Xu opinion. Even if they describe the legal position which pertained earlier than May 2023
(and, as we will see, at least in the case of the third Xu opinion, it is not clear that this is so),
even onTikTok’s case, its obligation was to verify prior to transfer. If its own DTAand legal
opinions did not contain the material upon which TikTok now relies to say that it did verify,
then it is difficult to see howTikTok could contend that there had been no infringement prior
to its own verification, though they may, of course, be relevant to the determination of what
consequences flow from such a finding of infringement. I will return to this point when
addressing Ground 2.
Failure to adequately assess Project Clover
Arguments
356.TikTok’s fair procedures complaint in relation to Project Clover is in two parts. First, it
contends that the DPC did not adequately assess the material with which it was provided.
And second, it contends that the DPC should have put its provisional findings in relation to
the material to TikTok and afforded it an opportunity to respond.
357.The DPC says that it addressed the new measures introduced post-PDD in detail and
points to the lengthy discussion of same in the Decision. As regards the necessity to afford
TikTok an opportunity to respond, it contends that such an obligation would lead to a never-
ending process, and refers to the decision in IDA v Information Commissioner [2024] IEHC
649 at §123: “Likewise, in his judgment in McMonagail agus a Mhic Teoranta v. Ireland & A.G.,
Ferriter J. rejected the complaint made in that case on the basis that it came very close
to arguing for a right to a draft adverse decision with a right to make submissions on
such draft, notwithstanding that an earlier opportunity had been afforded to make
submissions, a proposition for which no Irish authority had been cited. Ferriter J.
observed that relevant context for the fair procedures question arising was the fact that
where a planning decision involving a quarry is concerned, the applicant must be taken
to know that the authorities are likely to have regard to publicly available maps and
photos when assessing issues of quarry use. In rejecting a fair procedures complaint in
that case, Ferriter J. attached importance to the fact that the material relied upon
without specific notice was publicly available material which could have been obtained
by the applicant. It was also material which could reasonably be envisaged as
potentially being relied upon in the decision-making process.”
Discussion
358.I do not consider that there was any breach of fair procedures by the DPC in its
assessment of the Project Clover measures. Although, I have concluded above that in the
particular circumstances of the Inquiry, the DPC ought to have at least considered the third
Xu opinion, this does not equate to the far more expansive entitlement for which TikTok
now contends.
359.The case law relied on by TikTok, both EU and domestic, establishes that it was entitled
to know the case against it and be afforded an opportunity to respond. The PDD afforded
TikTok that opportunity and it was entitled to respond. As part of that response, TikTok
indicated that it was introducing additional measures to address the underlying concern of
the Inquiry. There is simply no logic to TikTok’s contention that the DPC was obliged to
give it a preliminary view of those measures, relied on in response to the PDD, before
reaching a decision in the Inquiry.
360.First, and obviously, the Project Clover measures were introduced after transfers had
taken place and, indeed, it appears after the temporal scope of the Inquiry had ended. They
were first referenced in March 2023 and the first evidence of any implementation of thosemeasures was from September 2023. The measures, therefore, could have no relevance to
the question of whether TikTok had infringedArticle 46 during the temporal scope, only to
the question of whether to make a suspension order or impose an administrative fine.
361.Moreover, the DPC had indicated in the PDD that it proposed making a suspension
order. TikTok relied on the Project Clover measures to seek to argue that a suspension order
wasnotwarranted.TikTokhaditsopportunitytorespondtothePDDanditdidsobyrelying,
inter alia, on the new Project Clover measures. By introducing new measures in response
to the DPC’s proposed suspension order, TikTok cannot have created an obligation on the
DPC to give its preliminary views on those measures and, furthermore, an opportunity for
TikTok to respond to that. It is plain that this would have the potential to lead to a never-
ending process, as contended for by the DPC. The entitlement contended for by TikTok is
not supported by any authority, and I reject the suggestion that there was any unfairness in
the DPC not providing its preliminary views on the Project Clover measures prior to
finalising its decision.
362.Nor do I think that there is substance to TikTok’s contention that the DPC did not have
regard to the Project Clover material.
363.The DPC made clear that it would look at additional material which TikTok supplied.
There is no question, therefore, but that the DPC was under a duty to have regard to that
material.Thequestion is whetherit gavethematerialadequate consideration.The additional
material submitted by TikTok is described in detail in the Decision, at §617 – 644.At §683
– 691, the DPC sets out the reasons for its conclusions that the additional measures
introduced after the PDD do not demonstrate that the data transferred to China is subject to
essentially equivalent protection to that guaranteed within the EU.
364.Though TikTok disputes the merits of the DPC’s assessment, it cannot be said that the
DPC has not assessed the information. However, as discussed below in more detail at
Ground 10, I am concerned that the reasons for the DPC’s conclusion, in particular in
relation to the pseudonymisation and privacy measures employed by TikTok are not
adequately set out. In this regard, TikTok complains about the conclusion at §690 of the
Decision: TikTok Ireland has implemented privacy enhancing technologies that mean that the
main identifiers associated with EEA User Data subject to the remote access are
encrypted or redacted. This enables those employees to carry out work associated with
EEA User Data without having sight of those identifiers. However, following Project
Clover, the EEA User Data subject to the Data Transfers still constitutes personal data
as defined in Article 4 GDPR because the data in question can relate to an identifiable
person directly or indirectly. In particular, as set out above, the categories of data that
are not encrypted or redacted include personal data such as user generated content.
Furthermore, the DPC notes that pseudonymised personal data still constitutes
personal data after said pseudonymisation if that data combined with additional
information can identify a data subject. TikTok Ireland has not demonstrated that the
EEA User Data subject to the transfers cannot be directly or indirectly linked to those
data subjects, whether using that data alone or whether in combination with other
personal data.
365.As discussed below, the DPC appears to be correct in concluding in the second last
sentence that pseudonymised data still constitutes personal data if a data subject is
identifiable. Moreover, I have no doubt that the DPC was entitled in principle to reach a
conclusion that TikTok had not demonstrated that data subjects would not be identifiable.
Such a conclusion would clearly fall within the DPC’s technical expertise and be entitled to
deference. However, the DPC has given no explanation of why it reached that conclusion.
In the circumstances, it is difficult to see how the court could defer to the DPC’s expertise
on this issue. As we will see, having regard to the very significant complexity of the
information submitted by TikTok in relation to its privacy solution, the failure by the DPC
to give reasons for its conclusions on this issue gives rise to significant difficulties for the
court in resolving this appeal.
Impermissible amendment of temporal scope
Arguments
366.The allegation that the amendment of the temporal scope was prejudicial to TikTok is
closely related to the complaint about the assessment of Project Clover. The prejudice
identified is that by fixing of the temporal scope at a date before the additional supplementary measures were introduced, those measures were only assessed as relevant to
the suspension order, not the finding of infringement. In addition, they were not assessed
comprehensively, andTikTok was deprived of an opportunity to be provided with the DPC’s
preliminary views on those measures.
367.The DPC argue that limiting the scope of any finding of infringement could not have
prejudiced TikTok and that all material was dealt with appropriately.
Discussion
368.The reason that the DPC elected to define the temporal scope in the way that it did in
the Draft Decision and Decision has not been explained. It may have been a belated attempt
to address the somewhat open-ended nature of the Inquiry it had allowed to evolve by
undertaking to TikTok that it would consider all material submitted by TikTok.
369.Whatever the reason, it seems to me that TikTok’s allegation that it has been prejudiced
thereby would only have substance if there were substance to its other complaints about the
assessment of material submitted by TikTok after the PDD. It cannot have been prejudiced
by the DPC’s failure to consider additional measures put in place by TikTok when
concluding that there had been an infringement up to a date prior to the introduction of those
measures. Insofar as TikTok asserts that the change in the temporal scope led to the material
being disregarded, I do not see any evidence of that. I have already concluded that fair
procedures did not require that TikTok be given an opportunity to respond to the DPC’s
assessment of TikTok’s response to the DPC’s preliminary findings. It is true that the
information provided by TikTok in its response (and afterwards) was substantial, but the
fact that TikTok put in place additional measures after it started transferring data to China
cannot create an entitlement to an additional layer of fair procedures.
370.As noted above, I will consider the merits of the DPC’s assessment of the measures
introduced after the PDD when considering ground 10 of the appeal.Failure to make the file available
Arguments
371.Following the receipt of the Draft Decision, TikTok made a number of requests for a
“complete copy of the DPC’s file”. In particular, it looked for copies of the exchanges
between the DPC and SACs which were referred to in the DPC’s correspondence enclosing
the observations of the SACs. The DPC replied to the effect that TikTok had been furnished
with all that it was entitled to, and that it was not obliged to provide details of its
engagements with the SACs.
372.TikTok has not identified or suggested that there is anything with which it has not been
provided other than any exchanges between the DPC and SACs post-Draft Decision. It
argues, nonetheless, that it was entitled to this material and that the DPC’s failure to provide
it undermines the Decision and has undermined its appeal.
373.It refers to Case C-358/16, UBS Europe and Ors, a case concerning a refusal by the
Luxembourg financial supervisory authority (CSSF), to provide an individual with
documents relating to the decision requiring him to resign from positions as director of
bodies supervised by CSSF. The CJEU noted (at §67 – 68):
“As for the documents that must be included in the investigation file, it must be noted
that it is also apparent from the Court’s case-law that although it cannot be solely for
the authority who notifies any objections and adopts the decision imposing a penalty to
determine the documents of use in the defence of the person concerned, it is however
allowed to exclude from the administrative procedure evidence which has no relation
to the allegations of fact and of law in the statement of objections and which therefore
has no relevance to the investigation (see, to that effect, judgments of 7 January 2004,
Aalborg Portland and Others v Commission, C-204/00 P, C-205/00 P, C-211/00 P, C-
213/00 P, C-217/00 P and C-219/00 P, EU:C:2004:6, paragraph 126 and the case-law
cited).
Itfollowsfromtheforegoingconsiderationsthattherighttodisclosureofthedocuments
relevant to the defence is not unlimited and unfettered. On the contrary, as observed by the Advocate General in essence in point 90 of her Opinion, the protection of the
confidentiality of the information covered by the obligation of professional secrecy on
the competent authorities in accordance with Article 54(1) of Directive 2004/39 must
be guaranteed and implemented in such a way as to reconcile it with the rights of the
defence.”
374.The Court identified what was required in the event of a conflict between interests (at
§69):
“Accordingly, in the event of a conflict of, on the one hand, the interest of the person
who is the subject of a measure adversely affecting him in having access to the
information necessary for him to be in a position to exercise fully his rights of defence
and, on the other hand, the interests in connection with maintaining the confidentiality
of the information covered by the obligation of professional secrecy, it is for the
competent authorities or courts to seek to strike a balance between these opposing
interests in the light of the circumstances of each case (see, to that effect, judgment of
14 February 2008, Varec, C-450/06, EU:C:2008:91, paragraphs 51 and 52 and the
case-law cited.”
375.TikTok also refer to the decision in Case C-109/10P, Solvay SA v European
Commission, concerning access to the Commission’s file in a competition investigation. In
its judgment in that case, the court noted (at §55):
“Infringement of the right of access to the Commission’s file during the procedure prior
to adoption of adecisioncan, in principle,causethedecisionto beannulledif therights
of defence of the undertaking concerned have been infringed (Limburgse Vinyl
Maatschappij and Others v Commission, paragraph 317).”
376. Accordingly, argues TikTok, the failure to provide it with the exchanges between the
DPC and the SACs undermined its rights of defence and, therefore, vitiates the Decision.
377.The DPC contends that TikTok had no entitlement to any documents other than those
with which it has been provided and that it was entitled to refuse access to the exchanges between it and the SACs as it is entitled to engage confidentially with the SACs under its
duty of sincere co-operation. An obligation to disclose those details would undermine the
integrity of the Article 60 process. It stresses that UBS and Solvay indicate that an
entitlement to access to the file is not absolute and that UBS identifies that internal
documents of the authority and other confidential material can legitimately be withheld.
378.In oral argument, the DPC traversed the material from the SACs which was provided
in detail and highlighted the limited nature of the exchanges which had taken place with
other SACs which had not been included in the file.
Discussion
379.As noted during the hearing, there does not appear to be any basis upon which a refusal
to provide access to the file after a decision is made could, of itself, undermine a decision.
The file may be necessary for the purpose of advancing some aspect of legal proceedings
challenging a decision, but that is a matter for those proceedings. TikTok did not seek
discovery of any documents the subject of this complaint.
380.Having regard to the nature of the documents which were “withheld”, I do not think
that TikTok has established any entitlement to such documents. It appears to me that they
fall within the type of document which the case law identifies does not require to be made
available.Theengagement with SACs comesat astagein theprocess whenthosethesubject
of complaint could legitimately be excluded from further comment, at least where the
engagement does not necessitate any material amendment to the draft decision. The LSA
and SACs must be able to engage freely regarding the terms of a draft decision with a view
to reaching an agreed position, as envisaged by Article 60. That engagement would be
undermined if every aspect of that engagement was required to be made accessible.
381.Of course, any submissions made to which regard is had by the supervising authority
must be made available. It is clear that that occurred here. TikTok has not succeeded in
establishing any error by the DPC in how it made material available.
382.Even if I am wrong about that, TikTok would not be entitled to any remedy on this
ground. Although Solvay and UBS both identify that a refusal to provide access to a file could have a bearing on the validity of a decision, it is clear that this is only where the rights
of the defence have in fact been infringed. In truth, TikTok advanced no argument that its
rights could have been infringed by the refusal to provide material which it refused. It did
not engage with what was not made available at all, rather asked the court to intervene on
the basis of hypothetical or notional harm. In fact, it is almost impossible to imagine that
anything which was not disclosed could have had any bearing on TikTok’s rights. TikTok
was provided with full copies of the SACs observations. There were no reasoned objections
from any SAC. There were no material amendments to the Draft Decision in light of
observations received.Therewas, accordingly,avanishingly small possibility oftherebeing
anything material in any documentation withheld.
383.Had TikTok wished to assert its entitlements to the documents and then to show an
infringement of its rights of defence, it should have sought discovery of the documents. If it
was concluded that they were not entitled to them, then that would have been an end of the
matter. Had it been found to have been entitled to them, it could then have argued by
reference to those documents that its rights had been infringed. What it is not entitled to do
so is ask the court to hypothesise that its rights might have been infringed by reference to
documents which are not before the court and which prima facie could have no bearing on
its rights of defence.
Ground not pleaded
384.In addition to the issues pleaded above, TikTok advanced an additional complaint at the
hearing of the action that the DPC had not followed the procedure it had indicated it would
follow in the Notice of Commencement. In that regard, as pointed out by TikTok at the
hearing, the Notice of Commencement had indicated that the DPC would prepare a draft
decision for the purpose of theArticle 60 process which would be furnished to TikTok “for
its consideration and submissions before it is submitted to the Article 60 process”.
385.Leaving aside that this complaint was not pleaded, the procedure followed by the DPC
in substance afforded TikTok the opportunity it said it would, to respond to the DPC’s
provisional findings. I note, in addition, that in its letter of 21 June 2024, the DPC advised
TikTok that it would provide it with a copy of a draft decision after it had been circulated via theArticle 60 process. TikTok raised no objection. The complaint, therefore, is without
substance.
Overall conclusion on Ground 1
386.For the reasons set out above, most of TikTok’s complaints of breach of fair procedures
are rejected. However, I consider that the DPC erred in refusing to have regard to the third
Xu opinion, and in concluding that Project Clover measures were not sufficient to justify
not making a suspension order without explaining the basis for that conclusion.
387.As explained above, in judicial review proceedings, the possible consequence of these
failures would be that the decision to impose the suspension order would be quashed, and
that aspect of the Decision remitted to the DPC for further consideration. However, in an
appeal on the record, I consider that the court’s task is to consider whether it is possible to
remedy the DPC’s errors by assessing the information to which sufficient regard was not
had, or the failure to explain the DPC’s conclusions. I will, accordingly, now consider these
issues together to try and determine whether, in fact, any error occurred in the DPC’s
conclusions.
Grounds 2 and 10
Alleged errors in assessment
388.As noted above, there is a significant overlap between Ground 2 and Grounds 1(a) and
(b). It is TikTok’s position that it had assessed transient processing and that the DPC erred
in concluding that it had not. As noted in its submissions (at §98), this “error subtends all
the findings of infringement of Article 46”. Although TikTok’s ground of appeal refers to a
“manifest error of assessment” by the DPC, in light of the conclusions in LinkedIn regarding
the scope of an appeal under section 150 of the 2018Act, TikTok is now essentially inviting
this court to conclude that it had assessed the transient processing of data such that there
was no failure by it to assess whether the personal data transferred was subject to equivalentlevels of protection, or, at least, on the evidence, that the DPC erred in concluding that it
had not.
389.Ground 2 is concerned with purported errors in the assessment of the evidence
regarding the application of the territoriality principle to the transferred data. Ground 10
alleges errors in the assessment of the Project Clover measures.
390.In arguing that the DPC has erred in its assessment of the evidence regarding the
application of the relevant Chinese laws, TikTok points to three pieces of evidence which,
it contends, show that it assessed the local processing issue which ultimately led to the
finding of infringement against it. In this regard, it is important to recall that the obligation
under Article 46, even on TikTok’s analysis, is to verify the position in the third country to
which data is transferred prior to transferring the data. TikTok point to no assessment by it
of the local processing issue prior to 17 May 2023. The information it now relies on is
information submitted during the Inquiry (though not all directly in response to the Inquiry).
It has not sought to adduce additional evidence for the purpose of showing that the local
processing issue had been addressed by it prior to transfers taking place, or at any point
earlier than the submission of its response to the PDD in September 2023. On the basis of
the evidence before the court, therefore, the matters relied on by TikTok are incapable of
showing that the DPC erred in concluding that as of 17 May 2023, TikTok had failed to
address the local processing issue. I accept, however, that the material could be relevant to
the assessment of whether an infringement finding was warranted, or, whether there was a
basis for imposing an administrative fine, e.g. if the evidence showed that there was
equivalent protection in thethirdcountry,orthatanyfailureof assessment was insignificant.
This possibility appears to have been acknowledged by the DPC in the Decision (at 127):
TheDPChashadregard toallrelevantchangesforthepurposesofthisDecision.While
the temporal scope of the Inquiry ends on 17 May 2023, the DPC has had regard to all
information submitted by TikTok Ireland in respect of changes made after 17 May 2023,
including its implementation of Project Clover, when determining which corrective
powers are appropriate to exercise in this Decision. As set out below, the DPC has also
carefully considered additional information submitted by TikTok Ireland after the temporal scope of the Inquiry that is relevant to considering the operation of Chinese
law during the temporal scope of the Inquiry.
391.I should say that, as noted above, TikTok makes the argument that because temporary
or transient processing was inherent to the remote access solution, it should be taken to have
addressed the application of the relevant Chinese laws to that processing. There is, I am
afraid, no logic to that proposition. The inherent nature of the transient processing only
serves to highlight that it is an issue which TikTok were required to address, not that it must
have implicitly been addressed.
392.Similarly,theevidencerelied onbyTikTokinarguing that theDPC erred in its evidence
of the Project Clover measures necessarily relate to measures put in place and described
after 17 May 2023. In the circumstances, the complaints at Ground 10 do not relate to the
infringement finding, only the decision to make the corrective orders.
Arguments
393.In substance, TikTok’s claim is that both footnote 113 and the third Xu opinion make
clear that the territoriality principle means that the personal data the subject of the Inquiry,
i.e. the data being transferred to China, is outside the jurisdiction of the Chinese authorities.
The third Xu opinion also clarifies that the conclusions in the second Xu opinion about the
application of the territoriality principle apply to the data that is processed in China. It
contendsthat theDPC’s failureto accept theChineselawevidencecontainedin thismaterial
was inconsistent with its stated position that it was taking TikTok’s Chinese law evidence at
its height.
394.Inrelation to theProject Clovermeasures,TikTok expressly accepts thatthe description
of those measures at §617 - §644 of the Decision broadly reflect the material provided by
TikTok during the Inquiry (see §528 of the grounding affidavit of Elaine Fox) but complain
that the assessment of that material was cursory and highlight certain errors. It contends that
the DPC appears to have rejected the effectiveness of its measures, in particular in relation
to pseudonymisation, without providing reasons for so doing and has made other errors
relevant to the assessment of risk. 395.TheDPC denies that therewas any material errorin its assessment of theProject Clover
measures which, it contends, was comprehensive.
Discussion – errors in assessment of Chinese law evidence
396.In an appeal on the record, it falls to the court, insofar as it can, to assess the evidence
whichwasbeforethedecision-makerandformitsownviewonthatevidenceforthepurpose
of determining whether the decision-maker has erred. In circumstances where the only part
of that evidence with which the DPC engaged in detail was the second Xu opinion, no
particular deference should be afforded to the DPC’s view, expressed for the first time in
these proceedings, that the additional material relied on by TikTok does not adequately
address the level of protection afforded to the personal data the subject of the Inquiry in
China. In circumstances where it is evidence of Chinese law, it is open to question whether
any deference should be afforded to the DPC’s views. However, as the issue concerns the
application of Chinese law to a particular technical solution, then it seems to me that the
DPC’s expertise could have some bearing on the question of whether the Chinese law
evidence addressed its concerns.
397.Before turning to the material, I note that the DPC correctly concluded that the
interpretation ofChinese lawwas amatter forfactual evidence. Itdid not purportto interpret
Chinese law, only whether the evidence TikTok provided showed that its assessment of the
level of protection was adequate. I consider that the court’s task is the same. The DPC
expressly stated that it accepted TikTok’s evidence of Chinese law at its height. It did not
obtain its own evidence as to Chinese law as part of the Inquiry. In the absence of any
contrary evidence, the DPC’s decision to accept TikTok’s Chinese law evidence at its height
was appropriate, there being no basis not to do so.
398.Thus, the only Chinese law evidence which forms part of the record for the purpose of
this appeal is that provided byTikTok (I note that there was additional Chinese law evidence
before the court for the purpose of the stay application, but neither party has sought to rely
on that material in the appeal, and I have not had regard to it). Given the importance of the
correctness of TikTok’s interpretation of Chinese law to its contention that effectivelyequivalent protection was guaranteed, I am forced to question whether the DPC’s decision
to rely onTikTok’s expert evidence was wise. In the context of a lengthy and comprehensive
inquiry, I think it would have been prudent for the DPC to have obtained its own advice on
this vital issue. The decision not to do so narrowed the scope of the DPC’s inquiry to one
which, in effect, could only consider whether TikTok’s assessment was adequate, not
whether it was correct.As a result of the DPC’s approach, the court is similarly confined to
analysing the adequacy of TikTok’s assessment on the assumption that what TikTok and its
experts say about Chinese law is correct. Insofar, however, as TikTok and its experts draw
conclusions from their interpretation of Chinese law as to the level of protection afforded to
the personal data the subject of the inquiry, neither the DPC nor this court are bound to
accept those conclusions. Furthermore, the DPC was, and the court is, entitled to consider
whether the Chinese law evidence is, in fact, addressed to the issues the subject of the
Inquiry.
399.The second Xu opinion was provided as part of TikTok’s response to the PDD. In the
opinion, Professor Xu describes his qualifications:
I hold a PHD in law under the Joint Training of UIBE and University of California,
Berkeley. I am one of two initiators of China Personal Information Protection and Data
Governance Thirty Person Forum, member of World Data Governance and Cyber
Security ResearchAlliance Secretariat, and a director of China Cyber Information Law
Institute. I have published more than 60 papers in Chinese and/or English in reputable
law reviews in and outside China in fields such as cyber security, personal information
protection, financial technology and data governance. I, as a co-author, have also
published On Cyber Sovereignty (Social Science Academic Press, 2017), Big Data, AI
and People (Peking University Press, 2019), and other books.
400.He sets out that he was asked to give his opinion on two questions. First, whether
Chinese authorities have the power to compel CGEs or their employees to disclose remotely
accessible EEA user data that is stored on servers outside China, and second, whether the
statement of Chinese law in Section 2 of the December 2022 DTAis accurate. In this regard,
it will be recalled that Section 2 of the December 2022 DTAidentified divergences between
the levels of protection afforded to personal data in China from that guaranteed within the
EU but stated that as Chinese authorities were not authorised to compel disclosure of datathat was not stored in China, this did not undermine the effectiveness of the contractual
safeguards contained in the SCCs. Questions 1 and 2 were, accordingly, directed to the same
issue.
401.Professor Xu states that the opinion responds to the following concerns from the PDD:
(1) “there is a lack of clarity regarding the territoriality principle in Chinese law”, (2)
“TikTok Ireland’s submissions,andDataTransferAssessments, arevaguein describing
the exact contours of the territoriality principle” and that, as a result of the deficiencies
in (1) and (2), it is unclear (3) “how the surveillance laws in fact apply in the context
of the data transfers”.
402.Having analysed the relevant provisions of Chinese law, Professor Xu concluded that
the answer to the first question was that CGEs or their employees could not be compelled
to disclose remotely accessible data. In relation to question 2, he opined that section 2 of the
December 2022 DTA was an accurate statement of Chinese law as at that date and was
consistent with his answer to question 1. Having regard to the content of section 2 of the
December 2022 DTA, the response to both questions is to substantially the same effect.
403.Accepting, as I must in light of the evidence, that Chinese authorities cannot require
disclosure of personal data stored outside China, does it follow that TikTok has shown that
the data transfers the subject of the Inquiry are afforded adequate levels of protection, i.e.
does it address the local processing concern? In my view, the answer, clearly, is no. As
discussed when considering the fair procedures claims at Ground 1, the subject matter of
the Inquiry was not data when stored on servers outside China, but data transferred to China
by remote access for the purpose of processing. In this regard, the DPC in its submissions
correctly distinguished between remotely accessed data and remotely accessible data.
Though TikTok rejected this as a false dichotomy (Transcript Day 10, page 6) it seems to
me to be an appropriate, indeed necessary, distinction to make. Completely different
considerations arise, or at least could arise, in relation to data which is capable of being
accessed from China, but which is stored overseas, and data which is actually accessed from
China and processed there. Put otherwise, the fact that Chinese authorities may not be able
to compel access to the former does not necessarily mean that it could not compel access to
the latter.404.TikTok did not suggest that there was nothing in China which was technically capable
of being accessed by Chinese authorities. In oral argument, TikTok repeatedly argued that it
was the data stored in the overseas servers which was of interest, because, in effect, what
was being processed on the computers in China was so transient and piecemeal that it could
have no possible interest to Chinese authorities and that any application of the Chinese
surveillance laws could only be anticipated in respect of the data stored overseas. That was
not established on the record, and is certainly not obvious. It may be, as counsel for TikTok
suggest, that the limited form of data relating to an individual user being processed in China
would be of little value to the Chinese authorities, but that is beside the point. If Chinese
authorities could compel access to all the data being processed in China because, to take an
obvious example, they were investigating TikTok, that would give rise to concerns about
whether the protection afforded to personal data was equivalent to that available in the EEA.
405.An adequate assessment by TikTok of the level of protection afforded to data processed
or being processed in China was necessary in order for it to comply with its obligations
pursuant to Article 46. I can see no error by the DPC in concluding that the second Xu
opinion did not address that issue adequately, or indeed, at all.
406.Thenext material upon whichTikTokrelies in arguing thattheDPC erredin concluding
that it hadn’t addressed the local processing issue is the July 2024 DTA and, in particular,
footnote 113 thereof.Although set out above, for convenience, I will repeat it here:
We have been advised by Fangda and Professor Xu that the transient processing
inherent to the facilitation of remote access in China does not alter the above analysis.
This is because the relevant data is still stored outside of China (and only remotely
accessible from within China) and so is still subject to the requirements set out above.
In addition: (i) such transient processing is strictly protected by the constitutional right
to confidentiality of correspondence under Article 40 of the PRC Constitution and (ii)
such transiently processed data would in any event still be considered offshore data
when considering the scope of Chinese authorities jurisdiction (for example as a result
of the logic used in Article 4 of Provisions on Data Transfer, released on 22 March
2024).407.Thefactthattheinformationisinafootnote,towhichnoattentionwas calledbyTikTok
in its covering letter setting out the material changes in the assessment, tends to undermine
the weight which TikTok now seeks to place upon it.Afootnote would, I think, typically be
understood as providing additional, but not essential, clarification, information or context to
the content of the main text. It might also contain a caveat, limiting the apparent scope of
the statement footnoted. The content of a footnote should be interpreted in that light. One
could not reasonably expect that a footnote would address, by a sidewind, an entirely
separate issue than is addressed in the main text. I do not understand footnote 113 to have
addressed an entirely different issue here.
408.The footnote can be seen to comprise three separate statements. The first is that the
transient processing inherent to the remote access solution does not alter the analysis in the
main text. The analysis in the main text was that CGEs and their employees could not be
compelled to provide access to data stored overseas. This statement says nothing, therefore,
about the local processing issue.
409.The second two statements, (1) that transient processing is protected by Article 40 of
the PRC Constitution, and (2) that the data would be considered offshore data because of
Article4oftheProvisionsonDataTransfer,could beinterpretedasrelatingtothetransiently
processed data. However, they are presented as additional reasons why the above analysis –
about compellability in relation to data stored outside China – is unchanged, rather than as
a separate assessment of the level of protection afforded to the temporarily processed data.
410.Insofar as it can be argued, as TikTok now do, that the footnote addresses the level of
protection afforded to the temporarily processed data, I don’t think any fair reading of the
footnote supports that view. First, and most significantly, the second two statements only
tend to reinforce the DPC’s concerns that different considerations apply in relation to the
transiently processed data and the data stored outside China, i.e. they tend to confirm the
entire basis of the DPC’s remaining local processing concern: the fact that data stored
outside China is protected does not automatically translate into data processed inside China
being subject to the same protection. Insofar as the statements then purport to address the
different position of transiently processed data, there is no assessment equivalent to, or even
approaching the type of assessment carried out by TikTok in relation to the data stored
outside China. Neither statement is to the effect that the Chinese authorities are not entitledto access data being processed in China, rather they assert either that it has some level of
protection underArticle 40 of the PRC Constitution, and that it is regarded as offshore data
for the purpose ofArticle 4 of the Provisions on Data Transfer.
411.Neither statement could be said to provide any significant comfort and fall far short of
showing, or even, asserting that essentially equivalent protection is guaranteed. It has never
been suggested that personal data is afforded no protection in China, so the fact that
transiently processed data is protected under the PRC Constitution establishes nothing. As
the DPC points out in its written submissions, the July 2024 DTAitself notes thatArticle 40
is subject to an exception in “cases necessary for national security or criminal
investigation.” The second statement, referring to the classification of transiently processed
data as “offshore data” isn’t explained at all and appears speculative, relying as it does on
the “logic” ofArticle 4.At most, this statement provides a hint of a basis for contending that
the locally processed data falls outside the scope of the relevant Chinese laws. Although it
was stated on TikTok’s behalf during oral submissions that “offshore” only has one meaning
(Transcript Day 2, p. 47), it will be apparent when we review the third Xu opinion that, in
fact, as Professor Xu explains, in his view, it has a very particular meaning as a matter of
Chinese law.
412.Tellingly, neither in the footnote, or anywhere else until the third Xu opinion does
TikTok assert, still less explain, that data transiently processed in China is subject to
essentially equivalent protection to that guaranteed within the EU. No one could reasonably
be expected to accept that to be the case by reference to footnote 113 of the July 2024 DTA
and in those circumstances, I cannot conclude that the DPC erred in concluding that the
corrective orders were required in light of the July 2024 DTA(or any of the DTAs).
413.By contrast to the second Xu Opinion and footnote 113, the third Xu Opinion addresses
in terms the level of protection afforded to the transiently processed data, in particular
whether Chinese authoritiescould compelaccess tothatdata. Beforeturningto that opinion,
it is helpful to return to the DPC’s fourth RFI and the information provided by TikTok in
response thereto which is expressly referenced in the third Xu opinion.
414.It will be recalled that in its fourth RFI, the DPC requested details of the technical
mechanism by which TikTok gave effect to the remote access solution. In its response dated11 March 2024, TikTok provided additional detail of what was involved. This information
was not discussed in detail at the hearing of the action, indeed TikTok suggested that no
reliance was being placed on it. Much of it is subject to the confidentiality order made on
20 February 2026. I will refer to what appear to be significant features in outline terms here.
415.Of particular note is that there is a section headed ‘Storage and Processing’. In that
section, TikTok explain that making the remote access connection results in data being
“loaded” into the RAM (random access memory) of the devices of the CGE employees. The
data will also be processed on the CPU (central processing unit) and GPU (graphical
processing unit) of those devices, including any transitory processing within the cache
memory of those processing units. This is described as an “inevitable consequence of any
remote access solution”.
416.The response describes that RAM is for a transitory period, while needed for the
programme or process involved and is cleared when the programme or process ends. It is
overwritten when RAM is required for new processes. It is only retained when the devices
are powered and is “normally” lost when the devices are shut down. It is explained that
RAM is fragmentary and that even if directly accessible, it would be “unfeasibly complex”
to reconstruct the data in any coherent form.
417.It is stated that XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXxxxxxxxxx
xXXXXXXXXX. It refers back to a similar statement to this effect in the response to the
PDD in which this XXXXXXXXXXXXXX is described as one of the new measures
introduced by Project Clover “which did not form part of the pre-existing measures”.
418.I note that in the Decision (at §129), the DPC summarises this information as it being
TikTok’s position that theremoteaccess solution does not result “in thestorage, in anyform,
of that personal data in China.” The contents of the 11 March 2024 response to the fourth
RFI are not, in my view, nearly so unequivocal.
419.The next heading is ‘Temporary Storage and Caching’. The response suggests that
TikTok has considered whether “the temporary browser storage configurations that are
inherent in internet usage might result in the storage of EEA user data.” It identifies
‘temporary storage’ and ‘temporary cache’ as browser storage locations. The responsecontains a bald statement that TikTok has considered the temporary storage configurations
for the main applications used by the remote access solution and that these do not contain
EEA user data. It says that it is not aware of EEA user data being temporarily cached but it
is conceivable that some files might be. XXXXXXXXXXXXXXXXXXXXXXXXXXXX
xxXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXX..
420.The response expressly accepts that the processing of data in China is processing within
the meaning ofArticle 4 of the GDPR.
421.As noted in his third opinion, Professor Xu was asked to consider:
Whether, in the specific circumstances of the transfers the subject of the Inquiry,
Chinese authorities have the power to compel China Group Entities (or their personnel
in China) to disclose EEA User Data temporarily processed in the computer
information systems in China of the relevant China Group Entity personnel as a result
of remote access to EEA User Data stored on servers in Singapore, Malaysia and the
United States (“Question 1”).
422.He was also again asked to consider whether the statement of law in the most recent
DTA, the July 2024 DTA, was an accurate statement of Chinese law.
423.The question of whether disclosure of data being processed in China can be compelled
by the Chinese authorities is, therefore, directly addressed in the third Xu opinion. But his
the analysis, rather than showing that the DPC’s concerns that this issue had not been
addressed were misplaced, tends to confirm that the DPC was correct to consider that the
issue had not previously been addressed, and entirely justifies the DPC distinguishing
between remotely accessible and remotely accessed data. The reason for Professor Xu’s
conclusion that disclosure of remotely accessed data cannot be compelled requires an
entirely different analysis than did his conclusion that Chinese authorities couldn’t compel
access to data stored outside China and is not based on a straightforward application of the
territoriality principle. In particular, it requires Professor Xu to explain that as a matter of
general principle “Chinese law treats the data from a foreign State that is temporarily
processed within China as a result of a remote access solution as overseas data (i.e. as orin the same way as other data that is not stored in China”). Perhaps ironically, this
proposition is explained in a footnote:
In Chinese legal practice, data that originates outside China without introducing any
personal data originated in China is referred to as “offshore data”, a special type of
oversea data. Chinese authorities consider that PRC laws, particularly those related to
the security management of outbound data transfers, are not applicable to offshore
data. (See Yanqing Hong, The “Rebalancing” of China’s Data Export Security
Management System - A Perspective on Data Competition Strategies Between
Countries, 3 Chinese Legal Review.) As an example supporting this legal practice, the
Hainan Free Trade Port International Data Center Development Regulations (effective
on 1 December 2024) explicitly exempt from the PRC data export management regime
the processing of “offshore data” during offshore data centre business conducted in
China. The corresponding official statement from the PRC regulators stated that these
rules were formulated to support offshore data centre business and promotes cross-
border data flows. (See https://www.hainan.gov.cn/hainan/dfxfg/202411/
f6f58aed43374fe8afcd36ae68dc117 .shtml?ddtab=true and https://db.hainan.gov.cn/
jdhy/zxjd/202412/t20241203_3778885.htmL).
424.The remaining portion of the third Xu opinion which sets out Professor Xu’s basis for
concluding that the temporarily processed data will be treated in the same way as data stored
overseas is relatively brief and so can be set out here in full:
The scope of the jurisdiction of Chinese law in relation to overseas data, in light of the
territoriality principle, can be further understood by reference to an example. Article 4
of the Provisions on Promoting and Regulating the Cross-border Data Flow clarifies
that a data handler is not required to fulfill obligations under Chinese law applicable
to the cross-border transfer of data if the data is collected and generated outside China,
transmitted to China for processing, and then returned back outside China, provided
no personal information or critical data from China is introduced into the processing.
Because EEA User Data is collected and generated outside China and will only be
temporarily accessible and processed in China as part of the remote access solution
(for temporary processing by engineers independent of their other processing activities within China), it is categorized as overseas data according to these provisions. In other
words, the EEA User Data temporarily processed in the computer information systems
in China of the relevant China Group Entity personnel as a result of remote access to
EEA User Data is treated the same way as any other data stored outside China.
425.Having concluded that the data will be treated the same way as any other data stored
outside China, Professor Xu then, effectively, repeats his analysis of the relevant Chinese
laws contained in his second opinion, save that he adds in respect of each law, that just as
Chinese authorities have no jurisdiction over data stored overseas, they have no jurisdiction
over data temporarily processed in China because data “temporarily processed on computer
information systems in China as a result of the remote access qualifies as overseas data”.
426.He provides a summary of his opinions. In addition to concluding that the July 2024
DTA contains an accurate statement of Chinese law, he concludes in relation to the first
question he was asked that:
In response to Question 1, my opinion is that Chinese authorities do not have the power
to compel China Group Entities, or personnel in China working for them, to disclose
EEA User Data temporarily processed in the computer information systems in China
of the relevant China Group Entity personnel as a result of remote access to EEA User
Data stored on servers in Singapore, Malaysia and the United States, in the specific
circumstances of the transfers the subject of the Inquiry, as described above at Section
C and in the letter from TikTok to the DPC dated 11 March 2024.
427.This response confirms that Professor Xu is addressing the technical solution being
relied on by TikTok as described in its response to the fourth RFI.
428.It is worth highlighting some features of the opinion. First, on its face, it does appear to
address the very issue which the DPC said had not been addressed at any time by TikTok up
to the date of infringement and beyond and provides a clear statement that the data being
processed in China is not subject to the relevant Chinese laws and, therefore, essentially
equivalent protection is available.
429.Second, and critically, Professor Xu’s analysis is wholly at odds with TikTok’s
contention that the locally processed data had been addressed all along. The entire basis ofTikTok’s contention that the remote access solution (with other measures) guaranteed
equivalent protection is that the territoriality principle meant that the EEA user data fell
outside the jurisdiction of the Chinese authorities because it was stored overseas. The third
Xu opinion suggests that the EEAuser data processed in China is outside of the jurisdiction
of the Chinese authorities because Chinese law is, in effect, disapplied in relation to that
data.
430.Although the local processing issue is addressed in the opinion, the basis for Professor
Xu’s conclusions is farfrom compelling.Heidentifies thatdataprocessedin Chinais treated
as overseas data in a very limited context, notably a measure introduced after the July 2024
DTA which was not, therefore, capable of supporting a conclusion that for all purposes, or
more pertinently, for the purpose of the transfers the subject of the proceedings, i.e. the
transfers during the temporal scope, the data processed in China would be treated in the
same way as data stored outside China. Moreover, the measure relates to the export of data.
The main text refers to the treatment of overseas data, again by way of an example only,
Article 4 of the Provisions on Promoting and Regulating the Cross-border Data Flow, a
measure contingent on no “critical data” being introduced in China. It is far from clear
from these examples how TikTok, or Professor Xu, extrapolates that the comprehensive
form of protection which it contends applies toTikTok’s EEAuser data stored overseas, also
applies to its EEAuser data being processed in China.
431.I note that in the section of his opinion headed “Summary of my previous opinions”,
Professor Xu asserts that the “principles set out in my Second Opinion extend to such
temporary processing in China as a result of remote access.” However, nowhere in his
opinion does he provide any basis for contending that the underlying principle informing
his second opinion – that the data is stored overseas and therefore outside the jurisdiction of
the Chinese authorities – applies to the data being processed in China. Rather, he introduces
a new argument, that for the reasons he explains, Chinese authorities will treat the
temporarily processed data as if it were stored overseas.
432.It will be recalled that the main basis for TikTok’s contention that the EEA user data
transferred to China is afforded equivalent protection to that guaranteed within the EU is
that the data is not stored in China and, therefore, as a matter of Chinese law, it cannot be
accessed by Chinese authorities. That being so, in order for TikTok to rely on the sameprinciple to suggest that data actually processed in China is also guaranteed equivalent
protection, it would have been necessary for TikTok to assert that the data being processed
in China was not stored there as a matter of Chinese law.As noted above, English-language
dictionary definitions of what storage meant would have no relevance to such an analysis.
Such an analysis would no doubt require engagement with details of the particular technical
solution employed by TikTok and the details of the response to the fourth RFI.As an aside,
one might plausibly query whether any lawyer, irrespective of their technical knowledge,
could be regarded as qualified to provide such an opinion without the benefit of expert
technical opinion, though I do accept that Professor Xu appears to have significant
experience of such matters.
433.There is no need to consider whether Professor Xu was qualified to offer such an
opinion, because, critically, he doesn’t do so.As we have seen, having been briefed as to the
precise technical means by which the data transfers occur, he does not argue that the data
processed in China is outside the jurisdiction of Chinese authorities because the data isn’t
stored there, rather he argues that it is subject to special treatment pursuant to particular laws
and is treated as if it is stored overseas. TikTok’s argument, that all personal data is actually
stored overseas and therefore outside the jurisdiction of the Chinese authorities, does not,
therefore, providean answerat all forthedataprocessedin China.Inotethatthis only serves
to highlight the fallacy of TikTok’s assertion that because it had addressed the position of
data stored overseas, it should be taken to have implicitly addressed the position of the data
processed in China. The third Xu opinion illustrates that it had not.
434.I note that one of the other criticisms the DPC makes of the third Xu opinion, that it
focuses on the risk of compelled disclosure and does not “address other means by which
Chinese public authorities may secure access to EEAData” does not appear well made. The
opinion addresses the actual concerns articulated by the DPC in the PDD and in the
Decision. The DPC had not, before the Decision, specified any concern regarding “other
means”ofaccess. Inthis regard, therewas asuggestion at thehearingthat controllersshould
have known, in light of the decision in Schrems II, of the possibility of the type of State
surveillance at issue in that case and addressed that risk in their DTAs. That may be so, but
if there was any concern by the DPC thatTikTok’s DTAs did not address such risks, it failed
to articulate it, or at least failed to articulate it sufficiently that any failure could have justified a finding of infringement without affording TikTok a further opportunity to
comment.
435.Accordingly, on the evidence on the record by March 2025, TikTok had addressed the
issue which led to the finding of infringement, the absence of an assessment of the level of
protection afforded to EEA user data processed in China. The conclusion of the third Xu
opinion on this issue is unequivocal. The explanation for why that is so is, however, not
convincing. This is not to offer an interpretation of Chinese law, which is far beyond the
remit of this court, but rather an observation on whether the legal opinion advanced by
Professor Xu is adequately supported by logic and evidence.
436.TikTok seem to suggest (Transcript, Day 10, pp. 109/110) that, because the DPC had
indicated that it was takingTikTok’s Chinese law evidence at its height, thethird Xu opinion
must also be taken at its height. That does not follow. The Chinese law evidence is evidence
of fact. The DPC was entitled to consider that evidence and determine if it found it
persuasive,evenintheabsenceofcontraryevidence.Thefactthatitopted,perhapsunwisely
as I have suggested above, to accept the Chinese law evidence set out in the DTAs and in
the first and second Xu opinions without obtaining its own Chinese law advice, did not bind
the DPC to accept any subsequent evidence. More importantly, it does not require the court,
in an appeal on the record, when assessing the evidence, to uncritically accept it. There is
no principle that a court is required to accept opinion evidence as to foreign law which is
unconvincing or based on weak logic.
437.Before considering what the consequences of the foregoing are, I will consider the
assessment of the Project Clover measures the subject of the pleas at Ground 10
Discussion – errors in assessment of Project Clover
438.At Ground 10 of the grounds of appeal, TikTok allege, in effect, two errors by the DPC
in its assessment of the Project Clover measures.
439.First, it contends that the DPC erred in its identification of what “private and sensitive”
data is remotely accessible. Second, it contends that the DPC’s rejection of the
pseudonymisation measures adopted by TikTok as ineffective was based on an erroneousassumption that no data could remain in plaintext if pseudonymisation was to be effective
and that its conclusion in relation to pseudonymisation was otherwise unexplained.
440.In circumstances where TikTok accept that the DPC’s description of the Project Clover
measures at §617 - §644 of the Decision “broadly reflects” the material submitted (subject
to the errors identified), it is convenient to consider those measures by reference to how they
are described in the Decision.
441.At §618, the Decision describes the key goals of the Project Clover, as set out in the
Project Clover Report. These were:
i. Data localisation: Store EEA User Data by default in data centres in Ireland and
Norway.
ii. Access controls: Build security gateways and controls to monitor and prevent
unauthorised user access.
iii. Minimise data flows: Build security gateways and controls to monitor and prevent
unauthorised data transmission.
iv. Co-management solution with independent third party security provider: Work with
a third party security provider to operate security gateways and controls, perform
security monitoring, and validate data transmission and user access.
v. Auditability of the solutions: Provide a solution that is auditable and allows third
party oversight and review.
442.Andat §619, theDecision sets out whatTikTokclaimed was theeffect ofProject Clover
in its response to the PDD:
1. Protected Data in the European Enclave will not be accessible by China Group
Entities or their employees (TikTok has already implemented this step for New
Protected Data as part of its Current Measures, utilising the Temporary European
Enclave and the European DSM);
2. China Group Entities will only have access to Excepted Data in the Global Data
Centres;
3. Excepted Data in the Global Data Centres will be subject to access controls, as well
as privacy enhancing technologies, including differential privacy and pseudonymisation measures. TikTok will complete this step through the
implementation of its In-Progress Measures as described (and in accordance with
the timescales set out) in the Project Clover Technical Report.
4. TikTok will apply privacy enhancing technologies, including anonymisation
measures (differential privacy) and pseudonymisation measures (through
encryption-on-access and redaction of key identifiers), to Excepted Data upon
access by employees of China Group Entities.
5. Legacy Protected Data will be deleted from the Global Data Centres, with the result
that China Group Entities will not have access to any Protected Data.
443.The Decision expressly accepts that TikTok has made “significant changes” to the
manner in which it transferred data. It then summarises those changes.
444.First, all personal data is now stored on servers in what it calls the European Enclave,
i.e. outside China (there was some debate at the hearing about whether this process had been
completed, though nothing turns on this for present purposes).
445.Second, a distinction was made between “protected data”, which is not remotely
accessible, and “allowable data” which is. As set out above, allowable data is made up of
“public data”, “interoperable data”, and “aggregated data”. Measures are in place, which are
audited, to ensure that no protected data is accessed by the CGEs.
446.Third, the Decision then sets out the purposes for which data is accessed and fourth, the
categories of data which are accessed. The categories are set out in tables of public data,
interoperabledataand aggregateddata.Inrespect ofeach category,thetableidentified what,
if any, level of encryption is applied. The levels are identified as ‘encryption’, ‘redaction’,
‘encrypt city, outside of “information isolated island”’, and ‘none’.
447.Fifth, the Decision addresses the format of personal data accessed by CGE employees
(at §634):
The July 2024 Data Transfer Assessment records that the format of the personal data
the subject of the transfer and which may be remotely accessed by the China Group
Entities may be “Encrypted /Pseudonymised / Plain-text”... The Global Operations
Gateway controls how that data is made available to employees of the China Group Entities. When employees in China consult EEA User Data, TikTok Ireland stated that
it applies encryption or redaction to the main identifiers associated with a user. The list
of identifiers that are encrypted or redacted is set out above in the section setting out
the “Categories of personal data the subject of remote access following changes
implemented by TikTok Ireland after the Preliminary Draft Decision”. TikTok Ireland
submitted that, regarding data remotely accessed, this means that employees in China
see an encrypted value or data that is entirely blocked for these identifiers, which
enables those employees to carry out work without having sight of those identifiers.
448.Finally, the Decision outlines the additional controls on access implemented since the
date of the PDD.
449.The first error identified by TikTok relates to the categories of information which the
DPC concluded were accessible by remote access. At §689 of the Decision, the DPC sets
out the types of material which can be accessed:
The categories of EEA User Data subject to the Data Transfers on an ongoing basis
also includes personal data that maybeprivateandsensitiveto auser.Asset out above,
these categories include personal data such as: the age level of users; who those users
follow and are followed by; details concerning whether a user has been subject to
moderation; a record of the user’s behaviour on the TikTok platform, including
timestamps relating to same; user generated content, including their videos, images,
comments, and metrics relating to same, as well as moderation status of that content;
reports, bans, and penalties imposed further to User Support and User request; general
location; and their direct message content. TikTok Ireland’s European Transfer Matrix,
dated 6 December 2024, states in respect of the transferred data, that “It is generally
not the intention of TikTok to collect any Sensitive Data, however Sensitive Data may
becollectedincidentally or uploaded bytheUser”.TheDPC finds thatthesecategories
of EEA User Data on an ongoing basis include personal data that may be private and
sensitive to a data subject.
* emphasis added450.TikTok accepts that most of the categories of data identified by the DPC are accessible
by remoteaccess but argues that “not all ofthemappear to beof ahigh sensitivity” (affidavit
of Elaine Fox at §529). However, it says that the DPC has erred in concluding that the two
highlighted categories of data, general location and direct message content, which it accepts
may be “private and sensitive” are accessible. It contends that only “approximate” location
data was collected during the temporal scope of the Inquiry. It says that direct message
content was not available by remote access at all during the temporal scope.
451.The DPC accepts that precise location data is not remotely accessible, but disputes
TikTok’s contention that general location data is not capable of being sensitive in certain
circumstances. It accepts that it erred in referring to direct message content and pleads that
it should have referred to ‘direct message data’, though the distinction is not explained on
affidavit. The DPC argues, however, that it has identified significant categories of data
which were remotely accessible and which could be considered private and sensitive
depending on the circumstances.
452.Although the errors identified by TikTok and accepted by the DPC are unfortunate,
minor errors are perhaps inevitable in a process as complex and extended as was the Inquiry.
In an appeal, the onus of proof is on TikTok to establish that the errors identified were, or
were capable of, being material to the Decision. It has not discharged that onus. The errors
in identifying certain private and sensitive data as accessible by the remote access solution
certainly appear minor and must be considered in the context of the DPC identifying a
number of other categories of data which could be private and sensitive and which TikTok
does not dispute were accessible. The data which is accessible may be, as TikTok suggests
less sensitive than the categories of data which are not accessible, but it was certainly within
the expertise of the DPC to determine that the data which is transferred could be private and
sensitive, and any minor errors by the DPC in identifying all the categories of data so
transferred does not undermine its overall conclusion at §690 of the Decision.
453.The more substantial issue raised by TikTok relates to the DPC’s treatment of the
pseudonymisation measures now forming part of Project Clover. In this regard, it should be
noted that even prior to Project Clover, certain of the data transferred to China was
pseudonymised as detailed in TikTok’s early DTAs. Project Clover appears, therefore, tohave involved a development of those measures, and certainly, following the adoption of
the Project Clover measures, pseudonymisation is applied in a changed context.
454.The mechanisms are not described in detail in the Decision. A comprehensive
explanation of the pseudonymisation and differential privacy measures put in place by
TikTok are contained in the Project Clover Report submitted in response to the PDD.
Professor Mittal provided a report at the same time confirming the effectiveness ofTikTok’s
differential privacy policy.
455.The DPC did not raise any queries regarding this material following its receipt,
including in their fourth RFI dated 8 February 2024, and did not, despite request from
TikTok, meet with it for the purpose of discussing same.
456.As it had flagged in its letter of 14 February 2025, prior to the Draft Decision, TikTok
provided an update on Project Clover prior to the Decision, though it provided it on 11April
2025 rather than 10 March 2025 as indicated. The Decision states that the DPC had regard
to this update. Unlike the third Xu opinion, the DPC has not sought to “contextualise” that
statement.
457.The update is an almost 50-page document which explains in detail not only the steps
taken by TikTok in relation to the pseudonymisation of data transferred to China, but also
the role of NCC Group in monitoring the steps employed and identifying weaknesses. The
reportdoesnotdirectlyaddressthequestionofwhetherpersonaldataissubjecttoessentially
equivalent protection to that guaranteed in the EEA by virtue of the Project Clover or
pseudonymisation measures. That does not appear to have been asserted by TikTok in any
of the material submitted by it. It does however refer to the testing done by NCC:
NCC Group also assessed the likelihood of reidentification in the event an attacker is
abletoobtainadatasetcontainingalltheAllowableDataaccessiblebyCGEPersonnel
about a user. In particular, they considered the following scenarios, including how the
leaked dataset could be linked with external data:
1. Given a dataset, can a member of that dataset be directly re-identified?
2. Given a dataset, can it be inferred that a user is contained within that dataset? 3. Given a specific user in a dataset, can any additional non-public information be
learned about that user?
458.Notably, the testing assumes an “attacker” obtaining all the allowable data about a user,
thus all data whether encrypted or in plain text. The document, oddly, does not immediately
indicate the outcome of those assessments. However, later in the document, the following is
stated:
NCC Group's testing hasto date found that the solution does not enable reidentification
of an EEA User.
459.This conclusion appears consistent with that in the Mittal report. The Mittal report is
referred to but not addressed in the Decision in the assessment of the Project Clover
measures.
460.As set out above at Ground 1, TikTok’s complaint is about how all this information was
dealt with by theDPCat§690 oftheDecisionwhereit appearsto haveconcludedas amatter
of fact that TikTok had not established the effectiveness of the pseudonymisation measure
because pseudonymisation does not necessarily prevent re-identification.
461.As counsel for TikTok put it, this analysis simply begs the question. Of course, says
TikTok, pseudonymised data may still constitute personal data if the data combined with
additional data can identify a data subject. This follows from the definition of
pseudonymisation inArticle 4(5). The question the DPC should have addressed is whether,
in fact, data subjects can be identified. The DPC’s conclusion that TikTok has not
demonstrated that they cannot be identified is not explained.
462.The DPC identifies case law which refers to the high threshold for establishing that
pseudonymisation is effective. Case C-413/23P, European Data Protection Supervisor
(EDPS) v Single Resolution Board (SRB), a case concerning an equivalent Regulation to the
GDPR which applies to Union institutions. The case concerned the processing of personal
data by the SRB and, in particular, the question of whether pseudonymised data sent by the
SRB to a third party, Deloitte, for the purpose of carrying out an analysis should be regarded
as personal data.463.The SRB had placed a Spanish bank, Banco Popular Español SA, in resolution. A
question arose as to whether the creditors and shareholders of the bank were entitled to
compensation, and this depended on the question of whether they would have done better
in an ordinary insolvency. SRB engaged Deloitte to carry out the necessary analysis.
464.Aprocess of engagement with the shareholders and creditors to determine if they were
entitled to and wished to be heard took place. This was in two phases, a registration phase
in which the shareholders and creditors provided personal data for the purpose of
establishing their right to be heard, and a consultation phase in which those who had an
entitlement to participate had an opportunity to submit comments.
465.Only the comments, identified by alphanumeric codes, were transferred to Deloitte.
Only the SRB retained the information which would have enabled a particular comment to
be attributable to a particular person. The EDPS, nonetheless, concluded that Deloitte had
been the recipient of personal data and found a breach of Article 15(1) of the GDPR. The
SRB appealed to the General Court which annulled the decision of the EDPS concluding
that the information transferred to Deloitte was not personal data. The EDPS appealed in
turn to the CJEU. In particular, it challenged the General Court’s conclusion that the
comments transmitted did not relate to “identifiable” persons. In substance, the EDPS
argued that pseudonymised data should always be treated as relating to an identifiable
person.
466.The CJEU observed (at §69) that:
“... it must be borne in mind that, under Article 3(1) of Regulation 2018/1725,
information must relate to an ‘identified or identifiable’natural person in order to be
classified as personal data within the meaning of that provision. Accordingly, the
application of that regulation presupposes, in principle, an examination of whether the
data subject is identified or identifiable by the information in question.”
467.The CJEU noted that the definition of pseudonymisation presupposed the existence of
information which would enable the identification of data subjects. However, it stated (at
§74 and §75): “The fact remains that, in the third place, the requirement that the identifying
information be kept separately and that it be subject to technical and organisational
measures ‘to ensure that the personal data are not attributed to an identified or
identifiable natural person’, laid down in Article 3(6) of that regulation, indicates that
the objective of pseudonymisation is, among other things, to prevent the data subject
from being identified solely by means of pseudonymised data.
Accordingly, provided that such technical and organisational measures are actually put
in place and are such as to prevent the data in question from being attributed to the
data subject, in such a way that the data subject is not or is no longer identifiable,
pseudonymisation mayhaveanimpact onwhetheror notthosedataarepersonal within
the meaning of Article 3(1) of Regulation 2018/1725.”
468.The Court referred to the recital in the 2018 Regulation equivalent to Recital 26 quoted
above and observed (at §79):
“.... in order to determine whether a natural person is identifiable, account should be
taken of ‘all the means reasonably likely’ to be used by the controller or by ‘another
person’ to identify the natural person ‘directly or indirectly’. In addition, the fourth
sentence of that recital sets out that, to ascertain whether means are reasonably likely
to be used to identify the natural person, account should be taken of ‘all objective
factors, such as the costs of and the amount of time required for identification, taking
into consideration the available technology at the time of the processing and
technological developments.”
469.The Court concluded on this issue (at §85 and §86) that:
“Consequently, in the light of the case-law referred to in the preceding paragraph, the
EDPS is incorrect in so far as he submits that the fact that pseudonymised data are not,
as the case may be, personal in nature for persons to whom the controller transfers the
pseudonymised data makes it unduly possible to remove those data from the scope of
EU law on the protection of personal data. According to that case-law, that fact has no
bearing on the assessment of the personal nature of those data in the context, inter alia,
of a potential subsequent transfer of those data to third parties. Accordingly, in so far
as it cannot be ruled out that those third parties have means reasonably allowing them to attribute pseudonymised data to the data subject, such as cross-checking with other
data at their disposal, the data subject must be regarded as identifiable as regards both
that transferand any subsequent processing of those data by those third parties. In such
circumstances, pseudonymised data should be considered to be personal in nature.
It follows that, contrary to what the EDPS maintains, pseudonymised data must not be
regarded as constituting, in all cases and for every person, personal data for the
purposes of the application of Regulation 2018/1725, in so far as pseudonymisation
may, depending on the circumstances of the case, effectively prevent persons other than
the controller from identifying the data subject in such a way that, for them, the data
subject is not or is no longer identifiable.”
470.Notwithstanding that conclusion, the CJEU ultimately concluded that the data
transmittedto Deloittewas personal data because “theidentifiablenatureof thedata subject
must be assessed by putting oneself in the controller’s position. It is not disputed between
the parties that the SRB had, as controller, all the information necessary to identify the
authors of those comments. It follows from the foregoing that, contrary to the SRB’s
contention, the information at issue constitutes personal data.”
471.The DPC is correct insofar as the SRB Decision highlights the high threshold for
establishing that pseudonymisation is effective. However, it is also authority for the
proposition that pseudonymised data is not necessarily personal data.
472.The DPC’s consideration of pseudonymisation, and the Project Clover measures
generally, arose in its consideration of whether a suspension order was warranted. The DPC
acknowledged in the Decision that any corrective order had to be appropriate, necessary and
proportionate. Having regard to the two-year gap between the temporal scope of the Inquiry
(as fixed by the DPC) and the actual making of the corrective order, and the significant
changes which the DPC accepted that TikTok had made in relation to the data transfers in
that period, it was, in my view, not open to the DPC to summarily reject the effectiveness of
the pseudonymisation measures employed by TikTok in deciding that a suspension order
was necessary. This, unfortunately, is what it appears to have done. 473.It is worthwhile contrasting the explanation for the DPC’s conclusion that TikTok had
not demonstrated the effectiveness of the remote access solution in the context of the data
transfers with its explanation of its conclusion in relation to the differential privacy and
pseudonymisation measures. The former is explained repeatedly in the Decision, the latter,
not at all
474.I entirely accept that the DPC, in the exercise of its technical expertise, was entitled to
form the view that the pseudonymisation was ineffective, or that its effectiveness had not
been established byTikTok. Indeed, it may have been open to the DPC to conclude that even
if effective the suspension order was necessary in light of its conclusion regarding the failure
to assess the local processing issue, or, perhaps, because the pseudonymisation and
differential privacy solutions were not comprehensive. But it had to have reasons for so
doing, and, furthermore, to provide those reasons in the Decision. Its failure to do so was a
clear error on its part. It does not explain why it rejected the apparent conclusions of the
Mittal Report or the NCC report or, if it accepted them, why those conclusions were
immaterial to its consideration of whether to make the suspension order.
Overall conclusions on Ground 2 and 10
475.Ihave, accordingly, concludedthattherewereerrors by theDPCin themannerin which
it assessed the question of whether TikTok had addressed the local processing issue in light
of all the evidence which was available to it at the time that it made the Decision. There was
also an error by the DPC in the manner it addressed TikTok’s evidence regarding the
application of pseudonymisation measures.
476.As noted, the errors are clearly not relevant to the infringement finding in relation to
Article 46, or the decision to impose an administrative fine for that infringement, and can
have no bearing on that aspect of the DPC’s decision. Whether those errors are sufficient to
warrant the court substituting a different form corrective order to that imposed by the DPC
will be addressed in the final section of this judgment.Ground 11 – Error in making the corrective orders
477.As referred to above, in addition to the errors of law and fact relied on by TikTok, it
contends that the decision to make the corrective orders was not justified in this instance. It
also argues that the processing order was unclear and that the time for compliance was
inadequate.
Arguments – ground 11
478.TikTok advanced four arguments under this heading. As referred to above, it contends
thattheDPCmisinterpretedSchremsIIasimposinganobligationtosuspendtransferswhere
there has been a finding of non-compliance, which it says is incorrect in the context of a
finding that there has been an inadequate assessment as opposed to a finding that there was
ineffective protection in the third country. That issue has been addressed above under
Ground 3 where I concluded that notwithstanding the references in the Decision to a duty
to suspend by reference to Schrems II, the DPC in fact carried out an assessment of whether
a suspension order was proportionate in this instance.
479.Second, TikTok argues – in apparent acknowledgement of the fact that the DPC did
consider whether the suspension order was proportionate – that the DPC erred in its
conclusion that it was. It argues that the DPC should have ordered it to submit a new DTA
rather than make the suspension order.
480.Third, it argues that the DPC could not make a suspension order in the absence of a
finding that there was an ongoing infringement.
481.It argues that the processing order is uncertain in breach of the requirement for legal
certainty. In this regard, it refers to the decision in Case C-570/19, Irish Ferries (at §164):
It should be noted at the outset that the principle of legal certainty is a fundamental
principleof EUlawwhich requires, in particular,that rulesshouldbeclearandprecise,
so that individuals may ascertain unequivocally what their rights and obligations are
and may take steps accordingly…482.In the domestic context, it refers to the decision in Tallon v DPP [2023] IECA 125, a
case concerning the validity of a civil order made pursuant to s. 115 of the Criminal Justice
Act 2006, a provision which permits a District Judge to make orders to prohibit a person
from doing anything specified in the order. The order in question prohibited the applicant
from engaging in publicspeaking and recordingin theenvirons ofWexfordTown.Theorder
was quashed as uncertain. The court noted (at §115) that:
“Applying the principle that an order that imposes an obligation to abide by it on pain
of criminal sanction, must be clearly expressed and indicate precisely what the subject
of the order is required to do or refrain from doing, I am satisfied that this civil order
was correctly held by the High Court to violate the principle of legal certainty.”
483.TikTok accepts that it does not face a criminal prosecution for failing to comply with
the processing order, but says that it could face an administrative fine which should be
regarded as punitive in nature.
484.Reference was also made to the decision in Dundalk Town Council v Lawlor [2005] 2
ILRM 106, a case stated in which the High Court held that a planning enforcement notice
which required the respondent to “return site to its previous condition” within a period
“immediatelycommencing”onthedateofthenoticewasinvalid.Aswiththeorderin Tallon,
failure to comply with an enforcement notice could lead to criminal prosecution. The court
concluded that the time period was impossible to comply with and the terms of the notice
were insufficiently clear.
485.Finally, TikTok contends that six months does not afford it sufficient time for
compliance with the corrective orders.
486.The DPC denies all of these complaints. As already determined, it says it considered
the proportionality of the suspension order and in the absence of an assessment which
showed that the personal data being processed in China was subject to essentially equivalent
protection, thatthesuspension orderwas theleast onerousmeans ofachievingtheobjectives
of the GDPR. Insofar as TikTok argues that the DPC should have requested a fresh DTA,
the DPC is at pains to highlight that despite the offer of an updated DTA in May 2025
correspondence, TikTok still has not provided such an update. 487.It says that there is no uncertainty about what the processing order requires. Finally, it
says that six months to comply with thecorrective orderswas appropriate and proportionate.
Discussion – ground 11
488.As concluded above, it is clear that the DPC did assess whether to make a suspension
orderandtreateditselfas havingadiscretion. Havingregardtothegapbetweenthetemporal
scope and the suspension order, and the acknowledged changed in circumstances in that
period, that was, in my view, entirely appropriate.
489.Icannot seeany substanceto theargument that the DPC should haverequesteda further
DTA rather than make the suspension order. To reiterate, the default position is that the
transfer of personal data to third countries is impermissible unless equivalent protection can
beguaranteed.Itispossible,pertheSupplementaryMeasuresRecommendations,totransfer
data where such protection is not guaranteed, where it can be demonstrated that there is no
reason to believe that relevant laws will be applied in practice. However, it is an essential
prerequisite to that determination that the scope of the relevant laws is properly assessed.
490.The DPC had concluded that TikTok had not assessed the level of protection afforded
to data processed in China under the relevant Chinese laws. Even accepting TikTok’s
evidence that no requests for personal data had been made by Chinese authorities and that
the data would be of no use or interest to the Chinese authorities, unless and until there was
an adequate assessment of the application of those laws to the data processed in China, no
proper determination could be made of whether there was a risk of those laws being applied
in practice. TikTok had been given many opportunities to address the issue and had updated
its DTAfour times without so doing (as I have concluded above).The remedy for this failure
was not to permit TikTok to continue to transfer data and provide it with a further
opportunity to address the issue which it had failed to address. Requiring it to submit a fresh
DTAwould not have met the objectives of the GDPR.
491.Theargument that theDPC could not makeasuspension orderwithout makingafurther
finding of infringement is not well made for a variety of reasons. First, having determinedthat there was an infringement, the DPC was obliged by section 111 of the 2018 Act to
decide whether a corrective order should be made. These are necessarily sequential. To take
TikTok’s argument at its height would lead to some form of Zeno’s paradox, where the DPC
was never in fact permitted to reach a determination on corrective orders.
492.The position in this case was unusual, in large part because of the DPC’s decision to
limit the temporal scope of the Inquiry. However, the DPC addressed this complication by
considering whether the issues which led to the finding of infringement had been addressed
by the time the decision on whether to make a corrective order was made. It concluded that
they had not been. I can see no error by the DPC in this approach.
493.There is no ambiguity or vagueness about the processing order. The processing order
requires that TikTok bring its processing into compliance in the manner detailed in the
Decision. The Decision clearly explains that the processing which is non-compliant is the
transfer of personal data to China in the absence of an adequate assessment which confirms
that the data will be subject to essentially equivalent protection in China. There can have
been no doubt in TikTok’s mind how to comply with that order, or looked at from the
opposite perspective, what conduct would lead it to breach that order. The order does not
suffer from the same ambiguities as those in Tallon or Lawlor.
494.I note that following the Decision, TikTok sought to engage with the DPC regarding
what was required by the corrective orders, and TikTok criticises its failure to do so. The
DPC in turn criticises TikTok for not having submitted a revised DTA, suggesting it seems
that TikTok’s complaints ring somewhat hollow.
495.Although I have concluded that the processing order is not invalid for vagueness, I do
think that it would have been helpful had the DPC engaged with TikTok as requested in
correspondence to enable it to understand whether there were measures it could take which
would prevent the suspension order ‘biting’. I cannot see any legislative barrier to it so
doing, and such engagement appears consistent with theobligations imposed on supervisory
authorities imposed by Article 57 of the GDPR to promote awareness of controllers and
processors of their obligations under the GDPR. It might also have been helpful for TikTok
to submit the revised DTA which it had offered, notwithstanding the lack of engagement. Had both parties engaged constructively, it is possible that some of the issues in this appeal
may have fallen away.
496.The suggestion that the time period for compliance with the corrective orders is too
short is little more than a bald assertion by TikTok and is unsupported by evidence. The
issue is addressed at §568 to §578 of the affidavit of Elaine Fox, but her evidence is no more
than an assertion that the timeframe is “wholly unrealistic”. The context for the timeframe
is the DPC’s conclusion that TikTok has infringed Article 46 by transferring personal data
to China without first having ensured that equivalent protection to that available within the
EEA was guaranteed and that that shortcoming had not been addressed. Far from being
obliged in those circumstances to afford TikTok a generous period within which to re-
organise its affairs or address those failings, the DPC acted well within its margin of
discretion by affording a reasonable period within which transfers in the absence of an
adequate assessment were required to stop. TikTok has not identified any error in its so
doing. There is no inherent impossibility of compliance as in Lawlor.
497. I note as an aside that TikTok’s evidence in the stay application tends to undermine its
contention in this appeal that compliance with the corrective orders within six months was
unachievable. It may be, as the evidence there showed, that compliance is unduly onerous
for TikTok, but as I concluded in that judgment, TikTok cannot rely on the manner in which
it structures its business to justifyanentitlementto carryon that business without complying
with the GDPR (at §216 of the stay judgment).
Overall conclusion on Ground 11
498.TikTok has not identified any stand-alone ground of appeal by reference to the manner
in which the DPC made the corrective orders.
499.The DPC correctly considered whether corrective orders were appropriate and
proportionate in the circumstances of this case. In particular, it considered whether there
was any change between the finding of the infringement and the decision to make corrective
orders which meant that corrective orders were unnecessary. Having regard to the DPC’s
conclusions on those issues, the DPC’s decision that a suspension order rather than a request to submit a further DTAwas the least onerous means of securing the objectives of the GDPR
was entirely justified.
500.The corrective orders were neither vague nor impossible to comply with.
Ground 5 – misrepresentation and misapplication ofArticle 13(1)(f)
501.This is the only ground challenging the finding of infringement in relation to Article
13(1)(f) of the GDPR. Article 13(1) imposes transparency requirements on controllers of
personal data. It requires that controllers inform data subjects that it is intended to transfer
their personal data to a third country and to refer to the appropriate or suitable safeguards
which are in place.
502.Theadversefinding relates toTikTok’s 2021Privacy Policy, theDPC having concluded
that TikTok’s updated 2022 Privacy Policy complied with the requirements of Article
13(1)(f). The relevant wording of the 2021 Privacy Policy is as follows:
To support our global operations, we share your information with members of our
Corporate Group and other entities outside of your country of residence as described
in the “How We Share Your Information” section. These entities are committed to using
and storing information in compliance with applicable privacy laws and to
implementing appropriate security measures to protect your information.
When we transfer your information outside of the European Economic Area (EEA), the
United Kingdom, or Switzerland, we ensure it benefits from an adequate level of data
protection by:
• relying on European Commission adequacy decisions made under Article 45 of
the GDPR, finding that the third country to which the information is being
transferred offers an adequate level of data protection; or
• using European Commission approved standard contractual clauses under
Article 46 of the GDPR for the transfer of information to all other third countries. For a copy of these standard contractual clauses, please contact us
via the details provided in the “Contact us” section below.
503.As appears from the foregoing, the policy did not expressly reference any third country
to which data was being transferred, in particular, China. Nor was there any explanation of
the nature of processing operations. The DPC concluded that both were required byArticle
13(1)(f) and therefore the GDPR had been infringed (at §592 – 595):
First, the DPC finds that the October 2021 EEA Privacy Policy should have informed
EEA Users of the named third countries, including China, to which personal data was
transferred, and did not do so. The DPC does not agree with TikTok Ireland’s
submission that it was not necessary, under Article 13(1)(f) GDPR, for TikTok Ireland
to name the third countries to which personal data is transferred using SCCs. The DPC
considers that it is clear from the text and the context of Article 13(1)(f) GDPR that this
information ought to have been provided in the circumstances of the Data Transfers.
Where Article 13(1)(f) GDPR requires controllers to inform data subjects of whether,
for example, personal data is transferredin relianceonan adequacydecision,or SCCs,
or derogations under Article 49 GDPR, it is part of the necessary context for that
information regarding the transfer mechanism for that information to be linked to the
named third country in respect of which the transfer mechanism is being used. In this
regard, the wording of Article 13(1)(f) GDPR makes express reference to “a third
countryorinternational organisation”, ratherthan to adestination“outsideoftheEU”.
The specific third country or international organisation to which the data is transferred
is of obvious relevance to allow the data subject to know how and where their personal
data is processed, and, indeed, to verify at a very basic level that an appropriate
transfer mechanism is in place. This follows from the need, highlighted in recital 39
GDPR, for data subject “to be made aware of risks, rules, safeguards and rights in
relation to the processing of personal data and how to exercise their rights in relation to
such processing”. This concern is further highlighted by the Article 29 Working Party
as follows:
A central consideration of the principle of transparency […] is that the data
subjectshouldbeableto determineinadvancewhatthescopeandconsequences of the processing entails and that they should not be taken by surprise at a later
point about the ways in which their personal data has been used.
Having regard to the above, the DPC agrees with the view adopted by the Article 29
Working Party that for information provided under Article 13(1)(f) to be meaningful, it
must specify the named third countries to which the personal data of EEA users is
transferred unless this information is already available to data subjects, for example,
by reference to an adequacy decision relied upon. In this case, the DPC finds that the
October 2021 EEA Privacy Policy should have specified each of the third countries to
which EEA User Data was transferred by TikTok Ireland, including China.
Second, in circumstances where the concept of a“transfer”of personal data is not
expressly defined in the GDPR, and is capable, in this context, of consisting of more
than one single type of processing operation, the DPC finds that the information
required under Article 13(1)(f) GDPR included an explanation, using clear and plain
language, of the nature of the processing operations that constitute the transfer.
In this case, during the temporal scope, the processing concerned was remote access
to personal data stored in Singapore and the United States by personnel of the China
Group Entities based in China. The DPC considers that in order for the processing of
personal data to be fair and transparent in light of the obligations on TikTok Ireland
under Article 13(1)(f) read with Article 12(1) GDPR, a basic factual description of the
transfers should have been made available to EEA Users in the October 2021 EEA
Privacy Policy. The DPC considers, in this regard, recalling recital 60 GDPR, that this
information is “necessary to ensure fair and transparent processing taking into account
the specific circumstances and context in which the personal data are processed.”
504.For comparison, the relevant portion of the 2022 Privacy Policy is as follows:
OurGlobal Operations and DataTransfers:StorageandLimitedRemoteAccess within
our Corporate Group We explain below how EEA/UK user information benefits from
an adequate level of protection when certain entities in our Corporate Group provide
necessary services to support our Platform. Storage
We provide our Corporate Group entities located in the United States and Singapore
with the information described in What Information We Collect under standard
contractual clauses so that they can store it for us on secure servers.
Limited Remote Access
Adequacy decisions. Certain entities in our Corporate Group located in Canada, UK,
Israel, Japan and South Korea are granted limited remote access to information
described in What Information We Collect to provide important functions. We rely on
the European Commission adequacy decisions (or equivalent decisions under other
laws) to grant these entities remote access.
Standard contractual clauses. Certain entities in our Corporate Group located in
countries without an adequacy decision are granted, under standard contractual
clauses, limitedremoteaccess to informationdescribedin What InformationWeCollect
to provide important functions. These entities are located in Brazil, China, Malaysia,
Philippines, Singapore, and United States.
Arguments
505.Both parties rested on their written submissions. TikTok identify a number of alleged
errors in the DPC’s analysis. First, it observes that Article 13(1)(f) does not expressly state
that the third country to which data is being transferred must be identified, or that the nature
of the processing be explained, and that the DPC has, therefore, imposed obligations which
“[go] beyond the requirements of the text”. It argues that the DPC’s interpretation is
inconsistent with the text of Article 13(1)(f), “the context in which it occurs, and its
objectives”. Italso contends that therequirements contended forby theDPC areinconsistent
with the requirement in Article 12(1) that information provided under Article 13 be in a
“concise, transparent, intelligible and easily accessible form, using clear and plain
language.”506.It contends that the DPC erred by reading Article 13(1)(f) in light of Article 15(1)(c),
which confers on data subjects a right of access to information on recipients of personal
data, in particular recipients in third countries, which TikTok contends “operated in a
different context” to Article 13.
507.TikTok argues that the DPC’s reliance on the Working Party Guidelines on
Transparency under Regulation 2016/679 was misplaced as they are non-binding guidelines
and, in any event, do not require the nature of the processing to be explained.
508.Finally, TikTok contends that the DPC’s “expansive” interpretation of Article 13(1)(f)
is not in accordance with the requirements of legal certainty and that provisions giving rise
to potential penal sanctions should be strictly construed.
509.The DPC argues that the requirement to identify the third country to which data was
being transferred arose in this case in order to meet the requirements of transparency. It
argues that this is consistent with the requirement in Article 13(1)(f) to indicate whether or
not there is an adequacy decision – which necessarily presupposes identifying the country
to which the adequacy decision relates. It is also argued to be consistent with the necessity
to provide the identity of the recipients of data (seeArticle 13(1)(e)).
510.The DPC argues that its interpretation is consistent with a teleological interpretation of
the GDPR, necessary to ensure transparency and a high level of protection for personal data.
511.In relation to the requirements for a description of the type of processing, it contends
that its reading of the requirements ofArticle 13(1)(f) is consistent withArticle 13(2) which
indicates that the purpose of providing information is to ensure “fair and transparent
processing”. The DPC also relies on Recital 60 which refers to the “specific circumstances
and context in which the personal data are processed”. It suggests that the requirement that
the data subjects be informed of the appropriate safeguards imports a requirement to be told
the nature of the processing. It refers to The EU General Data Protection Regulation
(GDPR): A Commentary (ed. Kuner at al, Oxford University Press, 2020) at p. 416 which
notes, in relation toArticle 13, that as “far back as the 1980s, the right to information about
the processing operation was called ‘chief’among the rights of the data subject”. 512.The DPC argues that there is no inconsistency withArticle 12(1) and no error in having
regardtoArticle15(1). Nor, it says, is thereanybreach ofthe requirement forlegal certainty.
Discussion
513.It is clear from Article 12 of the GDPR that the purpose of providing the information
specified in Article 13(1) is to ensure fairness and transparency in order to enable data
subjects to exercise their rights under the GDPR. The provisions ofArticle 13(1), therefore,
fall to be interpreted as requiring the provision of the information which is sufficiently fair
and transparent to enable data subjects to exercise their rights.
514.On a plain reading of Article 13(1)(f), the obligation imposed is capable of being
interpreted as being confined to being an obligation merely to advise of the fact that data is
being transferred to a third country or international organisation, as the DPC seems to have
accepted. Such a reading is plausible, however, only if one disregards the purpose of
providing the information. When one considers that the information is required to enable
data subjects to exercise their rights, it is apparent, that those data subjects will, in almost
all cases, be required to be told to which country the data is being sent. The Working Party
Guidelines on Transparency suggests that in the interest of fairness, it will “generally” be
necessary to name the third country to which data is being transferred. In fact, it is difficult
to imagine any circumstance in which advising data subjects that their personal data had
been transferred to a third country without telling them what that country is could meet the
requirements of fairness or transparency. Where transfers to a third country are regulated by
an adequacy decision, there is an express requirement that the data subject is told. Unless
the data subjects are told which adequacy decision is being relied on, then the data subject
is not adequately informed about the transfer: the data subjects must necessarily, therefore,
be advised of what countries data is being transferred to on the basis of adequacy decisions.
Ifthat is so, it is almost inconceivablethattheyneednot also betold of whichthirdcountries
to which data is being sent that do not have the benefit of adequacy decisions.
515.Where data is transferred to a third country, it is required to be subject to an equivalent
level of protection to that guaranteed within the EU. Data subjects would be deprived of
their ability to consider for themselves whether their data is, in fact, afforded the requisite
level of protection, and to exercise their rights accordingly, if not adequately informed ofthe countries to which their data is transferred.A data subject must be entitled to raise with
a supervising authority the question of whether their data is adequately protected. Data
subjects’ rights would be seriously undermined if a controller could continue transferring
personal data without even identifying to those data subjects to what country that data was
being sent.
516.ThoughIthink it must almost always be necessary to identifythe thirdcountryto which
data is being transferred, Article 13(1)(f) can also properly be interpreted as imposing a
requirement to provide an indication of the nature of processing involved where that is
necessary to ensure fairness and transparency. Such an obligation may arise having regard
to the necessity to identify the appropriate or suitable safeguards. It seems to me that the
DPCwerecorrectto concludethatthisisacasein whichthatobligationarose.Asisapparent
from the discussion above, the fact that personal data was only remotely accessed, and was
stored outside China, was at the heart of TikTok’s argument that equivalent protection was
afforded to personal data transferred to China.The 2021 Privacy Policy in no way identified
the fundamental protection relied on by TikTok, or afforded data subjects a fair opportunity
to consider the nature of what TikTok was doing. Of course, since TikTok did not indicate
that it was transferring data to China at all, an explanation of the nature of those transfers
didn’t arise. Had it advised data subjects that data was being transferred to China, then, on
TikTok’s case, it was in TikTok’s interests that data subjects be made aware that personal
data was subject only to remote access, and was stored outside China, since this would have
highlighted the principle basis relied on by TikTok for asserting that those transfers were
GDPR compliant. That TikTok failed to advise its users of information which it was in
TikTok’s interest to share is not a basis for concluding that its Privacy Policy was compliant.
517.The requirement to identify third countries to which data is being transferred and to
give an indication of the nature of the processing is also entirely consistent with Recital 60
of the GDPR.
518.As the 2022 Privacy Policy amply demonstrates, this information could readily be
provided in clear language. TikTok’s argument regarding inconsistency with Article 12 is
without foundation.519.The complaint about reliance on Article 15(1)(c) of the GDPR does not assist TikTok.
As made clear above, the GDPR must be read as a whole, and as internally consistent. There
is no errorin having regardto otherprovisionsoftheGDPR wheninterpretinganyparticular
provision. In any event, the requirement to identify recipients of data contained in Article
15(1)(c) is also to be found in Article 13(1)(e). TikTok could not sensibly argue that it was
inappropriate to consider the provisions ofArticle 13(1)(e) when seeking to understand the
scope of the obligation imposed byArticle 13(1)(f).
520.No basis for arguing that the provisions of Article 13(1)(f) fail to meet the obligations
of legal certainty was identified: it was merely asserted by TikTok.Article 13(1)(f) imposes
obligations which must satisfy the requirements of fairness and transparency. There is
nothing opaque or uncertain about what was required, and the 2021 Privacy Policy fell short
of what was necessary.
521.In light of the foregoing, the DPC’s conclusion that the 2021 Privacy Policy did not
comply with Article 13(1)(f) of the GDPR was manifestly correct. It could not plausibly
have reached any other conclusion than that, in thecircumstances of the transfers the subject
of these proceedings, the privacy policy was required to identify the third countries to which
data was being transferred. The finding in relation to the requirement to indicate the nature
of the processing was also, in the particular circumstances of this case, correct.
522.In circumstances where TikTok has invited the court to substitute its view for that of
the DPC, I would add further that the 2021 Privacy Policy is, in my view, inadequate in two
further respects. First, there is a failure to expressly indicate to which countries data is
transferred in reliance on adequacy decisions, or those to which data is transferred, like
China, in the absence of an adequacy decision. Article 13(1)(f) expressly requires that the
existence or absence of an adequacy decision be identified. The 2021 Privacy Policy does
not identify any country or adequacy decision relied on. At no point does it expressly state
that data is transferred to countries with no adequacy decision, still less which countries
thoseare.True, the policy does refer to databeing transferred eitheronthebasis ofadequacy
decisions or standard contractual clauses, but the Policy completely fails to meet the
obligations of fairness and transparency in this respect. 523.Secondly, the suggestion that data is transferred on the basis of standard contractual
clauses is simply inaccurate. In the case of China at least, TikTok accepts that the standard
contractual clauses alone do not provide sufficient protection for the data transferred. This
last statement, which I note remains in the 2022 Privacy Policy, is, therefore, positively
misleading.Although I was told by TikTok in oral submissions that this was “commonplace
in privacy policies” (Transcript Day 4, page 122), this does not excuse the shortcomings in
TikTok’s transparency obligations.
Overall conclusion on Ground 5
524.TikTok has not established any error by the DPC in concluding that TikTok was
required to identify the third countries to which data was being transferred in its privacy
policy and to set out the nature of the processing involved.
525.In the circumstances, I reject TikTok’s fifth ground of appeal and, accordingly, confirm
the finding that TikTok’s 2021 Privacy Policy infringedArticle 13(1)(f) of the GDPR.
Appeal against fines
526.The conclusions above regarding errors in the assessment of whether to make a
corrective order have no bearing on my conclusion that the DPC was entitled to make the
findings of infringement which it did, and my rejection of all the grounds of appeal
impugning those findings. Accordingly, those conclusions have no bearing on TikTok’s
appeal against the fines imposed for those infringements.
527.TikTok make a number of complaints about the decision to impose administrative fines
and the manner in which the DPC calculated those fines. By way of summary only, TikTok
contends:
• The DPC was only entitled to impose a fine if it concluded that TikTok’s
infringement was negligent or intentional and it failed to establish that TikTok was
negligent (Ground 6); • The DPC impermissibly had regard to the turnover of ByteDance in determining the
fining caps and the amount of the actual fines (Ground 7);
• The DPC failed to provide adequate reasons for the fining decision (Ground 8); and
• The DPC made errors of fact in its interpretation and application of Article 83
(Ground 9).
528.As noted, the parties have requested that I refer various questions to the CJEU pursuant
to Article 267 of the TFEU on issues arising from TikTok’s grounds of appeal. A reference
to the CJEU could only arise if a question of EU law is raised in the proceedings and a
decision on that question is necessary to enable the court to give judgment. The first ground
of appeal against the decision to impose administrative fines disputes the DPC’s conclusion
that it was entitled to impose fines at all because there was no basis for its finding of
negligence. This is not an issue in the annulment proceedings, WhatsApp v EDPB.
529.If TikTok is correct that the necessary elements for a finding of negligence were not
present, then no fine could properly have been imposed and none of the other issues arise.
A decision on them would not then be “necessary” to enable me to deliver judgment. In
those circumstances, it seems to me to be convenient to deal with that threshold question
first, before, if necessary, returning to deal with the other grounds of appeal. I should note
that the parties have agreed a formulation of three questions addressing this issue for
potential referral to the CJEU. For the reasons set out below, I do not consider that a referral
on those questions is necessary or would be appropriate.
Ground 6 – failure by the DPC to establish that TikTok was negligent
530.Article 83(2) of the GDPR sets out the factors to which regard must be had by a
supervising authority when deciding whether to impose an administrative fine. Article
83(2)(b) identifies the “the intentional or negligent character of the infringement” as one
such factor. The parties agree that a supervising authority is not entitled to impose
administrative fines under the GDPR in the absence of a finding of fault, either negligence
or intention, on the part of the data controller or processor. This was not always apparent
but was confirmed in two cases decided at thesame time, NVSC, referenced above, and Case
C-807/21, Deutsche Wohnen.531.Thetestfornegligenceisthatwhichappliesinthecompetitionlawsphere.Asexpressed
in Deutsche Wohnen (at §76):
“In that regard, it must be clarified, as regards the question whether an infringement
has been committed intentionally or negligently and is, therefore, liable to be penalised
by an administrative fine pursuant to Article 83 of the GDPR, that a controller can be
penalised for conduct falling within the scope of the GDPR where that controller could
not be unaware of the infringing nature of its conduct, whether or not it is aware that it
is infringing the provisions of the GDPR.”
532. The formulation is, at first glance, a little difficult to understand, but if “could not be
unaware” is framed without the double negative, then the threshold for negligence (or
intentionality) can readily be understood as a controller being liable, whether or not it knew
it was infringing the GDPR if it could have been aware that its conduct was infringing. Put
otherwise, an infringement is not negligent or intentional if a controller could not have been
aware of the infringing nature of the conduct.
533.Thus framed, it is apparent that the threshold is a low one. This is reflected in the
observations of theAdvocate General in NVSC (at §80) :
“Fourth, and perhaps most importantly, I consider that, in practice, the threshold for a
negligent infringement of the GDPR, within the meaning of Article 83(2)(b) of that
regulation, is, in any case, so low that it is difficult to envisage situations where it will
be impossible to impose a fine for the mere reason that that element is not satisfied.”
534.A slightly different standard was at issue in a case on which TikTok relied in its
submissions to the DPC, Case C-308/06, Intertanko. The relevant portion of the judgment
relates to Article 4 of Directive 2005/35 which obliges states to punish ship-source
discharges of polluting substances if committed “with intent, recklessly or by serious
negligence”. The Court pointed out (at §73) that:
“It is, however, to be pointed out, first of all, that those various concepts, in particular
that of ‘serious negligence’referred to by the national court’s questions, correspond to tests for the incurring of liability which are to apply to an indeterminate number of
situations that it is impossible to envisage in advance and not to specific conduct
capable of being set out in detail in a legislative measure, of Community or of national
law.”
535.Noting that the concepts were “fully integrated into” the Member States’legal systems,
the Court stated (at §75 and §76):
“Inparticular, all those systems have recourseto theconcept of negligence whichrefers
to an unintentional act or omission by which the person responsible breaches his duty
of care.
Also, as provided by many national legal systems, the concept of ‘serious’negligence
can only refer to a patent breach of such a duty of care.”
536.In the PDD, the DPC provisionally concluded that the infringements were negligent
(see §479 - §486). In the response to the PDD, TikTok identified a series of facts which it
said showed that it was not negligent. Some of these facts amounted to claiming that it had
not infringed at all, but those directed to its level of fault included that it had prepared
detailed DTAs, and had confirmed its position in relation to Chinese law from a number of
experts, including Fangda Partners, Clifford Chance and Professor Xu, that this was a
“complicated area of law” as evidenced by the Milieu report. It characterised the PDD
findings as being that matters were insufficiently explained, and stated that there were no
“errors of assessment”. It noted its significant investment in the development of new
supplementary measures.
537.The DPC assessed Article 83(2)(b) at §738 to §748 of the Decision. It noted that the
GDPR does not identify the factors which need to be present for an infringement to be
classified as ‘intentional’ or ‘negligent’, but referred to the WP29 Guidelines on the
application and setting of administrative fines for the purpose of Regulation 2016/679 (“the
Administrative Fines Guidelines”) which provide: In general, “intent” includes both knowledge and wilfulness in relation to the
characteristics of an offence, whereas “unintentional” means that there was no
intention to cause the infringement although the controller/processor breached the duty
of care which is required in the law
538.TheAdministrative Fines Guidelines, the Decision records, provide that conclusions on
intent or negligence will be drawn on the basis of identifying objective elements of conduct
from the facts of the case. At §741, the DPC characterised the test as whether the objective
elements demonstrate that the controller “ought to have been aware” that it was falling short
of the duty owed.
539.The DPC concluded (at §742) that although TikTok had wilfully transferred data, it did
not know that it had failed to verify. Intent was not, therefore, made out. It concluded that
TikTok was negligent to “a high degree” because it ought to have been aware of the flaws
in its DTAs. The fact that it had carried out the DTAs did not mean that it was not negligent.
The DPC also concluded that TikTok was negligent in relation to the Article 13(1)(f)
infringement.
Arguments
540.In their submissions, TikTok complains that the DPC does not reference the decisions
in NVSC and Deutsche Wohnen in the Decision and implicitly criticise its reliance instead
on the Administrative Fines Guidelines. It identifies the following purported errors by the
DPC:
• The DPC failed to recognise that the identification of negligence was a threshold
issue and does not flow automatically from an infringement;
• It failed to identify the standard of care;
• It failed to find any objective basis for the finding of negligence and ignored
evidence inconsistent with negligence;
• It failed to provide adequate reasons supported by evidence. 541.In oral submissions, it was suggested that the test set out in the Administrative Fines
Guidelines was not the same as the NSVC and Deutsche Wohnen tests and that on one
reading the Guidelines could be read as saying “if you have infringed, that’s enough”
(Transcript, Day 5, p. 84). In articulating the threshold TikTok said that there must have
been some deficiency of which the controller ought to have been aware.
542.Counsel focused on thefinding ofnegligenceat §742 oftheDecision.Shecharacterised
it as saying nothing more than a conclusion without explanation, failing to identify the flaws
or why TikTok should have been aware of them. She makes similar criticisms of the
conclusion in relation to Article 13(1)(f).
543.The DPC point out that the Decision does, in fact, acknowledge that negligence (or
intention) finding is a prerequisite to a decision to impose an administrative fine and does
reference the judgment in NVSC (at §810). It emphasises that the standard for establishing
negligence is low. It says that it hasn’t ignored any of TikTok’s evidence as to why it wasn’t
negligent and that it has met the standard identified in Connelly v An Bord Pleanála [2021]
2 IR 752, in giving, as it puts it, the “main reasons on the main issues”. In oral submissions,
it stresses that its findings in relation to negligence must be read in the context of the
Decision as a whole and, in particular, the DPC’s conclusion thatTikTok had not adequately
assessed the data transfers the subject of the Inquiry.
544.It draws comparisons with the decisions of the CJEU referenced in Deutsche Wohnen
and NVSC which contain the test for negligence quoted above, including Case C-681/11,
Schenker, Case C-591/16P, Lundbeck, and Case C-601/16P, Arrow Group.
Discussion
545.I do not consider that there was any error by the DPC in concluding that TikTok was
negligent in infringing Articles 46 and 13(1)(f). Even if there were some error by the DPC
in the manner it reached or expressed that conclusion, in an appeal on the record, I would
not substitute any other conclusion for that of the DPC.TikTok was negligent in committing
the infringements of the GDPR.546.Subtending TikTok’s assertion that there was no basis for a finding of negligence is its
contention that it discharged its obligations by preparing detailed DTAs, which
comprehensively addressed the risks to personal data. TikTok is a major data controller,
seeking to transfer very significant amounts of data from the EEA to a third country. The
fact that it carried out detailed assessments to enable it to transfer data to China does not of
itselfdischargeitsduties undertheGDPR.I haveconcludedabovethattheDPCwasentitled
to conclude that, despite TikTok’s efforts, those assessments were inadequate, i.e. that there
was a falling short by TikTok. So the question is not, as TikTok appears to consider, did
TikTok attempt to discharge its duty, or did it make significant efforts to discharge its duty.
Rather, it is whether its failure to do so can be attributed to any fault on TikTok’s part.
However the negligence threshold in the GDPR is calibrated, it is clear that it was at fault.
547.TikTok criticise the DPC for failing to identify the standard of care. The DPC say that
it wasn’t required to do so, but the better point is that it did so throughout the Decision (and
the PDD) in identifying where TikTok had fallen short. The standard to be met is that set
out Schrems II, to verify that effectively equivalent protection to that available in the EEA
is guaranteed. The issue to be considered in determining intent or negligence was the level
of fault.
548.The threshold is articulated in Deutsche Wohnen and NVSC. Could the controller not
havebeenunawarethatitsconductwasinfringing?Couldithavebeenawarethatitsconduct
was infringing? On any view, that is a low threshold, as identified by theAdvocate General
in NVSC. At the hearing, TikTok contended for a threshold of whether it “ought to have
known”, which, arguably is higher than that identified in the case law. As noted, that is the
standard which the DPC purported to apply (see §741 of the Decision). But even taking that
as the standard, the answer in my view is that, yes, it ought to have known. Indeed, no other
conclusion is possible from TikTok’s own evidence. How could it not have known that it
was required to assess the level of protection afforded to personal data transferred to and
being processed in China?As is apparent from the decision in Schenker, the fact thatTikTok
may have engaged experienced lawyers to advise it on whether its conduct was in
accordance with the requirements of the GDPR does not relieve it of liability.
549.As noted above, the focus of Chapter V of the GDPR and, necessarily, the Inquiry is on
personal data transferred to third countries for processing: thus, in this case, the personaldata transferred by TikTok to China by remote access for processing. The question to be
addressed is what level of protection that data was given as a matter of Chinese law. As
appears from the analysis above, the protection afforded to locally processed data was not
directly addressed by TikTok until the third Xu opinion. TikTok’s case, at its height, is that
it was implicitly addressed in Professor Xu’s second opinion, supplied in September 2023,
i.e. after the temporal scope of the Inquiry, and expressly addressed in the July 2024 DTA.
550.TikTok does not argue that the local processing issue did not have to be addressed as
part of the verification process prior to transferring data. Its main complaint is that it did not
know that was the (or a) concern of the DPC and would have addressed it had it known. It
has provided no explanation for its failure to do so prior to, on its case, the second Xu
opinion (though this was only stated in the third Xu opinion). It does not identify any other
evidence where it says local processing was addressed, or even identified as an issue.
551.If TikTok had been correct that, because local processing was inevitable, it must be
taken to have addressed that processing in its DTAs’conclusions that the remote storage of
data (with other measures) guaranteed equivalent protection, then it might be able to argue
that its ‘fault’was no more than it failed to express that which was obvious. But even if that
proposition was not built on faulty logic,it is at odds withTikTok’s ownevidence, contained
in the third Xu opinion, that the locally processed data is afforded the necessary protection
by the application of Chinese laws which treat it as overseas data and, therefore, of the same
status as the data permanently stored overseas.
552.It is important to emphasise here that TikTok’s complaint that the Inquiry didn’t make
clear that the local processing issue was a particular concern is not relevant to the question
of whether TikTok was negligent. If the issue required to be addressed before data was
transferred, and as I have made clear above, it is the issue which should have been the focus
of any data transfer assessment by TikTok, then TikTok cannot avoid a conclusion of
negligence by suggesting that the Inquiry process did not highlight this falling short. And
the fact that TikTok did not actually know that it had not addressed an issue which required
to be addressed is not an answer either. If it did know, then that would render the
infringement intentional.
553.TikTok, accordingly, failed to verify that the locally processed data was subject to
essentially equivalent protection during the temporal scope. It does not argue that this was not an issue which required to be addressed prior to transferring data. This was, in fact, the
most obvious issue which required to be addressed. It provides no explanation for its failure
to do so. The first evidence it relies on to suggest that it was addressed post-dates the
temporal scope (the second Xu opinion). Its subsequent evidence (the third Xu opinion)
undermines that contention. Though TikTok trumpets the efforts it went to carry out its data
transfer assessments, and the measures that it put in place, it does not, when properly
analysed, proffer any argument that the requirement to assess the locally processed data was
not something it ought to have known, still less that it was something that it could not have
known should be addressed.
554.On the application of the test articulated in the CJEU authorities,TikTok could not have
been unaware that it was required to assess the local processing issue and, therefore, was
notpermittedtotransferpriortosodoing,i.e.thatitsconductwasinfringing. Itistheexpress
and obvious obligation imposed by Chapter V of the GDPR. By transferring large amounts
of data without carrying out that assessment, TikTok was clearly negligent.
555.TikTok does, at least, have an argument that it could not have been unaware that its
2021 Privacy Policy was not in breach of Article 13(1)(f) of the GDPR because the
requirement to tell data subjects that their data will be transferred to a third country does not
impose an express obligation to identify that country. However, as I have concluded above,
that is what the GDPR and its transparency obligations, properly interpreted, does require,
certainly in the circumstances of this case. TikTok cannot rely on a misunderstanding of its
obligations to excuse a failure to comply with them, certainly not in the absence of any
evidence of the efforts it went to understand those obligations.
Overall conclusion on Ground 6
556.There was no error by the DPC in its conclusion thatTikTok was negligent in infringing
bothArticle 46 andArticle 13(1)(f) of the GDPR.
557.TikTok failed to comply with an obvious obligation under Article 46, with no
explanation for such failure, and failed to understand its obligations underArticle 13(1)(f),
but has not identified any reason to justify its misunderstanding. In those circumstances, no conclusion other than that TikTok was negligent was open to the DPC and there is no basis
upon which the court could set aside its conclusion on this issue. Even had DPC erred in it
assessment of the question of whetherTikTok hadbeen negligent, on the evidence available,
there is no basis to interfere with its conclusion that it had been.
558.In the particular factual circumstances of this case, there is no legal uncertainty about
this conclusion such that a reference to the CJEU might be required.
Summary of conclusions
559.As confirmed in LinkedIn v DPC, the appeal provided for in both sections 142 and 150
of the 2018Act is an appeal on the record. In such an appeal, the court is entitled to consider
all the evidence which was before the DPC on its merits, and any additional evidence which
may be admitted. Where an error is identified in the DPC’s decision, the court is entitled to
substitute its own order for that of the DPC where it considers this appropriate. In assessing
the evidence of the DPC, the court should afford deference to its views on matters falling
within the sphere of its expertise.
560.Having regard to the very significant fines which may be imposed for infringements of
the GDPR, the sanctions should be considered punitive or criminal in nature such that the
rights of the defence protected by Article 48 of the Charter and Article 6 of the ECHR are
engaged.
561.There was no error of law by the DPC in its interpretation and application of the GDPR.
The GDPR places an obligation on controllers to verify that the level of protection afforded
to personal data transferred to third countries is essentially equivalent to that guaranteed
within the EEA. Where controllers transfer data to third countries they must be in a position
to demonstrate when called upon to do so that they have adequately verified the level of
protection. A supervisory authority is entitled to assess the adequacy of a controller’s
verification in order to determine whether it has complied with the GDPR and find an
infringement where the verification is not adequate.
562.This is consistent with the principles of accountability inArticles 5 and 24 of the GDPR
and the decision of the CJEU in Schrems II.563.There was no impermissible reversal of the burden of proof by the DPC in finding an
infringement of Article 46 of the GDPR. Having regard to its conclusion that TikTok had
not adequately assessed the level of protection afforded to personal data transferred to
China, there was no error by the DPC in its approach to the risk of such transfers. The DPC
considered whether a suspension order was necessary, appropriate and proportionate.
564.There was no breach of fair procedures by the DPC when concluding that TikTok had
failed to assess the level of protection afforded to data being processed in China. That issue
was at the heart of the Inquiry and was central to TikTok’s obligations under Article 46.
TikTokhadmorethansufficientnoticethatthiswasanissuewhichitwasrequiredtoaddress
and more than adequate opportunity to address it.
565.There was no breach of fair procedures in fixing the temporal scope of the Inquiry, or
at least no breach independent of its complaint that material submitted after the temporal
scope was not adequately considered. The DPC could not, by limiting the temporal scope
of the Inquiry, gives less consideration to material submitted during the Inquiry outside the
temporal scope, to which it had agreed to have regard.
566.No breach of fair procedures has been identified by reason of the DPC’s refusal to
provide very limited material toTikTok concerning its interactions with other SACs.TikTok
had no entitlement to that material and, even if it did, has failed to show that there was
anything in the material which had a bearing on its rights of defence.
567.There was no error by the DPC in its assessment of TikTok’s evidence regarding the
relevant Chinese laws up to the delivery by TikTok of the third Xu opinion. The DPC’s
conclusion that the evidence did not address the level of protection afforded to personal data
transferred to and being processed in China was amply supported by the evidence. There
was, accordingly, no breach of fair procedures by the DPC in failing to engage with footnote
113 of the July 2024 DTAin the Decision.
568.Having regard to the necessity to balance the rights of the defence with the obligation
to complete inquiries within a reasonable time and with due diligence, the DPC would have
been entitled to fix a time beyond which no further material from TikTok would be accepted
or considered. It did not do so. In circumstances where the DPC had not fixed a time beyondwhich further material would not be considered, and where it, in fact, accepted and
considered material submitted at an even later date, in the very particular circumstances of
this case, fair procedures required that the DPC have regard to the third Xu opinion to the
extent that it was relevant to the issues in the Inquiry, and in particular, to the question of
whether to make a suspension order.
569.The third Xu opinion is, on its face, relevant to the question of whether a suspension
order was necessary, appropriate and proportionate. In circumstances where the DPC did
not have regard to the opinion, the court is required to have regard to it when considering
whether to substitute any order for the suspension order made by the DPC.
570.The DPC had regard to the Project Clover measures implemented by TikTok after the
temporal scope and, as it was entitled to in the exercise of its technical expertise, concluded
that a suspension order was still warranted. In the ordinary course, the court would defer to
the DPC’s expertise on this matter. However, in breach of fair procedures, the DPC has
failed to give any or any adequate explanation for the apparent rejection of the adequacy of
the measures introduced by TikTok.
571.The Project Clover measures are clearly relevant to the question of whether a
suspension order was necessitated in this case. The court is required to have regard to those
measures in considering TikTok’s appeal against the suspension order and whether to
substitute an alternative order. In the absence of any reasons having been given by the DPC
for rejecting the measures, it is not possible to afford deference to the exercise by it of its
technical expertise when assessing this evidence.
572.There was no error of law by the DPC in its approach to the making of the corrective
orders. It was not required to make a further finding of infringement before so doing, it was
not required to instead request a further DTA from TikTok, there was no vagueness or
ambiguity in the processing order and the time given for compliance with the corrective
orders has not been shown to be unreasonably short.
573.Noerroroflaworfact has beenidentifiedbyTikTok in relation totheDPC’s conclusion
that TikTok’s 2021 Privacy Policy breached Article 13(1)(f) of the GDPR. Consistent with
the obligation of transparency, TikTok was required to identify in that policy the countries to which it was transferring data. It was also required to identify the nature of the processing
involved. It failed to do so.
574.There was no error by the DPC in concluding that TikTok’s infringements ofArticle 46
and Article 13(1)(f) were negligent in character. Those conclusions were amply supported
by the evidence. The DPC was thus entitled to impose administrative fines for those
infringements.
Proposed Order
575.As noted at the outset, the Decision had four component parts: the finding of
infringement of Article 46; the finding of infringement of Article 13(1)(f); the decision to
impose administrative fines for those infringements; and the decision to impose the
corrective orders in light of the finding of infringement ofArticle 46.
576.I have rejected above all the grounds of appeal directed at the first two components of
the Decision, the infringement findings. I propose, therefore, to dismiss all the grounds of
appeal against those infringement findings.
577.I have, in addition, concluded that there was no error by the DPC in concluding that
both infringements were negligent in character within the meaning ofArticle 83(2)(b) of the
GDPR and that that necessary prerequisite to the imposition of an administrative fine was
met. I propose accordingly to dismiss the appeal against the decision to impose
administrative fines. For the reasons explained above, I will leave over for further decision
TikTok’s appeal against the amount of the fines imposed.
578.Although I have concluded that there was no error of law by the DPC in the approach
it took to the question of whether to impose corrective orders, I have also concluded that
there were errors in its actual assessment of the information relevant to the question of
whether to impose, in particular, the suspension order.
579.I have rejected the contention by TikTok that an identification of any error by it
automatically leads to the annulment of the Decision (or part of it). This is not consistent
with a statutory scheme in which the court is entitled to consider the merits of the DPC’sdecision, hear new evidence and substitute its own requirements in place of those required
by the DPC. The role of the court is to attempt, if possible, to determine the appropriate
order in light of the evidence. The fact that there may have been errors of assessment by the
DPC does not lead to the inevitable consequence that its ultimate conclusion was in error.
580.This is consistent with the case law of the CJEU. In Case C-297/23P, Harley Davidson
Europe Ltd concerned an appeal against the revocation of binding origin information (BOI)
decisions relating to the importation of motorcycles. The General Court, despite finding that
the Commission had erred by failing to hear from the appellant before adopting its decision,
concluded that that was not sufficient to result in the annulment of the decision. The CJEU
concluded that there was no error by the General Court in so doing (at §104):
“Second, in order to have a contested measure annulled on the basis of Article 263
TFEU, it is for the person alleging an infringement of his or her rights of defence to
show thatthereis a possibilitythattheadministrativeprocedureleadingto theadoption
of that measure might have led to a different outcome … In that regard, although a
person who relies on such an irregularity cannot be required to show that, in its
absence, the act concerned would have been more favourable to his or her interests, he
or she must nevertheless prove, in a concrete manner, that such a possibility is not
entirely excluded ...”
581.Although TikTok has succeeded in establishing errors in the DPC’s assessment, it is not
clear to me at this juncture that it has established that a different form of order than that
imposed by the DPC is appropriate.
582. It is necessary to consider the two identified errors of assessment in turn, but also
together.
583.The first error concerns the consideration of the third Xu opinion. As noted, there is
some ambiguity about how the DPC dealt with this opinion, it either disregarded it entirely,
or it considered that it was not material to the issues of concern that it had raised and
therefore did not need to be addressed. Whichever of those views it took, it was in my view
in error.Although the opinion was submitted very late in the day, for the reasons explained,
it should not have been disregarded for that reason alone.584.Once the opinion is considered, it does at least raise the possibility that TikTok had,
belatedly, adequately assessed the level of protection afforded to personal data being
processed in China, clearly a relevant consideration in determining whether a suspension
order was appropriate, necessary and proportionate.
585.Though the DPC did not consider that possibility, the court can or can attempt to do so.
I have some doubt about whether the third Xu opinion could, by itself, be regarded as
discharging TikTok’s obligation to verify that equivalent protection to that available in the
EEA was guaranteed for the data transferred, and for that purpose to carry out an adequate
assessment of the protection available. Though Professor Xu does conclude that equivalent
protection is guaranteed, his reasons for doing so appear somewhat speculative. It is a bold
conclusion based on apparently slim legal foundations. Given the centrality of the issue to
the Inquiry, the DPC could not have been obliged to simply accept Professor Xu’s
conclusion on its face, especially where it appears to represent a departure from his second
opinion, or at least a different analysis. Were I in the shoes of the DPC assessing that
evidence, I would, at the very least, wish to interrogate TikTok about the third Xu opinion
before accepting that it represented an adequate assessment of the legal position such that a
suspension order was no longer appropriate or necessary. Of course, the opinion would have
to be considered in light of the other information relied on by TikTok in relation to the
suspension order, the Project Clover measures.
586.The position with the assessment of the pseudonymisation and privacy solutions is far
more complex. It is clear from the Decision that the DPC did have regard to the evidence
submitted. The Project Clover measures are described in detail, the Mittal Report is
referenced, as are the Project Clover updates. It is also clear that the DPC considered,
correctly, whether in light of that evidence, a suspension order was necessary, appropriate
and proportionate. The DPC concluded that it was.
587.What is not at all clear is why it so concluded? It would appear from the fact that it
carried out the assessment at all that the DPC considered that it was possible that the various
privacy measures adopted by TikTok could have persuaded it that a suspension order was
not required, though I accept that this may not be the case. If it was possible, then the DPC
clearly was not persuaded, but the court and TikTok are at a loss to understand why. TikTok
requested meetings with the DPC to discuss and explain its new measures, but no meetingtook place. Indeed, because of the time when this information was introduced by TikTok,
post-PDD, there was no engagement between TikTok and the DPC on those measures at all,
and nothing, accordingly, in the record which enables the court to understand how the DPC
assessed them.
588.The question, in substance, for the court is whether the DPC should have been
persuaded. However, to answer that question would require a deep understanding of
enormously complex technical data, the subject of various expert reports submitted to the
DPC, an expert body, in the Inquiry. The statutory scheme anticipates that it is the expert
body which will first assess that information, not the court. Though the information was
referred to during the course of the hearing, it was not interrogated in any detail, still less
was it the subject of expert evidence for the purpose of explaining its significance.
589.On one view, I could determine that absent proving that the material does or could
address the DPC’s concerns, TikTok has failed to establish an error in the DPC’s decision
and that its appeal should, accordingly fail. However, where TikTok has not been informed
of the reason that its material fell short, this would clearly be an unfair outcome. By the
same token, a conclusion that because TikTok has identified an error in assessment, without
establishing that the error may have been operative, it is nonetheless entitled to an order
annulling the suspension order would plainly not be appropriate and would undermine the
high level of protection of personal data demanded by the GDPR.
590.The statutory scheme envisages that the court should, accordingly, assess the evidence
and determine the ‘correct’ outcome. However, the assessment of the evidence relevant to
the pseudonymisation and privacy solutions employed by TikTok are matters which require
considerable expertise.Although the courts can and do regularly assess expert evidence, this
typically occurs with the help of expert witnesses to assist in explaining that evidence. Such
assistance would be essential in understanding the evidence at issue in this case. I do not see
how I could safely assess the evidence without it.
591.Moreover, the statutory scheme envisages that the court carry out the task of assessing
technical evidence with the benefit of the DPC’s prior assessment of that evidence, and its
assessment of what if any a corrective order is appropriate, to which assessment the court isrequired to afford deference. The statutory scheme would be frustrated if the court did not
have the benefit of that assessment, and the reasons for the DPC’s conclusions.
592.In the circumstances, it appears to me that in the very particular circumstances of this
case, the appropriate order to make in substitution for the corrective orders is an order
vacating the corrective orders and remitting the question of what corrective orders to make
in light of theArticle 46 infringement finding to the DPC for further consideration. Subject
to hearing further from the parties on the final form of order, that is what I propose to do.
593.I will accordingly list these proceedings on 11 June 2026 at 10 am for the purpose of
making final orders. I encourage the parties to engage with each other in advance of that
date with a view to agreeing the form of order.




