TikTok data transfer fine
Deputy Lowry asked why TikTok was fined €530 million for improper data transfers from Ireland and the EU to China, what data was involved, and whether there was any threat. The Minister defended the Data Protection Commission's independence and noted its major role in EU enforcement.
The Minister mentioned TikTok. Recently, the data protection commissioner fined it €530 million for the improper personal data transfer from Ireland and the EU to China. The most common question people are asking since this news broke is why such data would be sent to China. Is it that we do not have the capacity to store it here ourselves? Why was the transfer deemed inappropriate and improper? What was the reasoning and logic behind the €530 million fine? Did the transfer of this information pose a threat? What was the reason for it?
People are also asking what this personal data includes. What kind of personal data is being sent to China for storage? Will the transfer of personal data from Ireland to other countries and continents be an ongoing occurrence? How will that be monitored?
Comment on this
The Data Protection Commission, DPC, plays a critical role as one of the largest EU data protection authorities and the Government acknowledges its strong track record in carrying out its duties. As the lead supervising authority across many cross-border cases, Ireland is generally the first point of response for new and emerging data protection issues across the EU. By law, it is entirely independent of the Department of Justice and Government.
It leads the EU on the quantum of monetary fines imposed on draft decisions and the number of corrective measures enforced against online platforms. Its decisions have been approved by fellow data protection authorities in more than 90% of cases.
I am aware, as the Deputy referenced, relating to the announcement that the data protection commissioner found TikTok infringed the GDPR regarding its transfers of EEA user data to China as well as its transparency requirements. I note the decision was also reached in consultation with its peer regulators across Europe, as required under the GDPR and no objections were raised to this decision. Government is conscious of the commitment to deliver effective data protection regulation and privacy rights in the context of the DPC's role in the EU.