TikTok vs. The Data Protection Commissioner: A high court ruling with billion-dollar implications for EU data transfers

The Irish High Court has temporarily paused an order from the Irish Data Protection Commission (DPC) that would have forced TikTok to suspend transfers of its European Economic Area (EEA) users’ data to China. While this decision follows a staggering €530 million fine for GDPR infringements, the ruling’s true importance lies not in the temporary stay itself, but in the legal standard the court confirmed it will use to balance business continuity against regulatory enforcement in Ireland. For any organisation transferring personal data outside the European Union, this judgment provides a crucial analysis of risk, precedent, and the strategic importance of demonstrating unrecoverable business harm when challenging a regulator.

The Regulator’s verdict: Why the DPC took action against TikTok

The DPC’s action stems from an inquiry it began on September 14, 2021, into TikTok’s data transfer practices. In its final decision, issued on April 30, 2025, the DPC identified two significant GDPR infringements based on its investigation into data transfers between 29 July 2020 and 17 May 2023:

• GDPR Infringement 1: A breach of Article 46(1) of the GDPR. The DPC’s core finding was that TikTok had “failed to verify, guarantee and demonstrate” that personal data of its 159 million EEA users, when accessed remotely by personnel in China, was afforded a level of protection “essentially equivalent” to that within the EU.

• GDPR Infringement 2: A breach of Article 13(1)(f) of the GDPR. The DPC also concluded that for a portion of the inquiry period (29 July 2020 to 1 December 2022), TikTok had failed to provide its users with the required information about these international data transfers.
As a result of these findings, the DPC imposed a series of corrective measures designed to be among the most stringent in its history: • An administrative fine totaling €530 million.• A Suspension Order requiring TikTok to halt the data transfers to China.• A Corrective Order requiring TikTok to bring its overall data processing operations into compliance with the GDPR.

The Court Application: Why TikTok fought for a ‘stay’

While TikTok’s appeal of the decision automatically paused the €530 million fine, the Suspension and Corrective Orders were set to take effect. To prevent this, TikTok made an urgent application to the Irish High Court to “stay” (i.e., pause) these orders until its full appeal against the DPC’s decision could be heard. The core of the legal debate centered on two competing arguments:

TikTok’s argument for a stay

Implementing the suspension would cause massive, unrecoverable harm, including billions of euros in expenditure, severe disruption to its business and workforce, and a diminished experience for its stakeholders.

The DPC’s argument against a stay

The fundamental rights of TikTok’s 159 million monthly EEA users would be at risk if the data transfers were allowed to continue while the DPC’s decision was being appealed.

The High Court’s decision: paused, but with conditions

In a judgment delivered on November 13, 2025, the High Court granted TikTok’s request for a stay. The court’s decision-making process provides a masterclass in judicial risk assessment, beginning with a pivotal choice of legal framework.

Choosing the Battleground: Okunade vs. Zuckerfabrik Before weighing the arguments, the court first had to decide which legal test to apply. The DPC argued for the strict, EU-level Zuckerfabrik test, typically used when challenging the validity of an EU regulation. This test places a very high bar on applicants, making it difficult to pause a regulator’s decision. TikTok, conversely, argued for the Irish national law standard from Okunade v Minister for Justice, which focuses on finding the “least risk of injustice” through a more holistic balancing of interests.

Secret Link