While it faces an imminent ban in the US, TikTok is now facing potential GDPR fines in the EU alongside five other Chinese tech companies.
It’s been a rocky start of the year for TikTok, as the social media website faces a ban in the US that has users running toward alternatives, and the company’s only saving grace in the country may be a reversal of the ban by Donald Trump, the convicted felon who will return to the office of the US President on Monday.
Now, TikTok, along with AliExpress Shein, Temu, WeChat and Xiaomi are facing GDPR violation allegations from Noyb, the European Centre for Digital Rights which typically leads to the charge against major GDPR violators.
The advocacy group claims that these companies send European’s personal data outside of the EU, specifically back to China, which is in violation of GDPR.
Following EU complainants filing access requests to the six companies to see if their data was transferred outside of the EU, and the companies failing to respond, Noyb filed their complaints.
Organisations operating within the EU are not allowed to transfer EU citizens’ data outside of the EU unless they are explicitly allowed to, and even then, the organisations and the countries they transfer to must meet stringent data protection requirements.
Shein, AliExpress, Xiaomi, and TikTok all do explicitly mention data transfers to China in their terms and conditions, while WeChat and Temu simply note unspecified “third countries.”
Organisations can transfer data outside of the EU if they employ Standard Contractual Clauses (SCCs), in which the non-EU entity agrees to abide by EU data protections.
However, this process is only possible when the EU can verify that European data will be secure in the foreign country, and that the SCCs will not conflict or be overwritten by any national laws that call for access to the personal data.
With these matters in mind, Noyb did not mince its words or cloud its concerns: “Given that China ia an authoritarian surveillance state, it is crystal clear that China doesn’t offer the same level of data protection as the EU,” one of Noyb’s data protection lawyers, Kleanthi Sardeli, said.
And this fear of unrestricted government data access is not unfounded – taking a look at Xiaomi’s transparancy reports, Noyb was able to view unfettered access to its private data by the Chinese government.
Recommended reading
- US Calls for ByteDance Divestment from TikTok
- TikTok Faces US Ban After Losing Appeal
- Demystifying GDPR & AI: Safeguarding Personal Data in the Age of LLMs
The advocacy group found that Xiaomi complied on almost every occasion the Chinese government requested access to its customer data.
Further, Noyb also warns that China lacks an organisations that citizens can turn to for concerns on government surveillance, leaving it impossible for foreigners to exert their data rights in the nation.
The Noyb filing’s reasoning is awfully similar to why TikTok is currently facing a ban in the US, which has left US users scrambling to find an alternative.
US officials claim to be protecting citizens from the possibility of Chinese-state surveillance, as China’s data policies would allow the government access to any data it requests.
However, the founding nature of Noyb should wrinkle some noses due to the slight stench of hypocrisy. The EU severed its data adequacy agreements with the US for similar reasons, after Edward Snowden revealed that the US is surveillance of its own citizens, and Max Shrems of Noyb pointed out that this would be true of EU citizen data that is transferred to the country as well.
Only last year did the EU renew its data adequacy agreement with the US, making it easier for companies to transfer data to the nation, though a clause in the agreement has garnered much controversy. The data agreement, which was ratified by executive order by then-President Joe Biden, said that the US would refrain from requesting or accessing EU citizen data unless it is required for national security – the benchmarks of which can change at the drop of a hat.
It is important to also note that, even with the GDPR fines and the TikTok ban, the main issue revolves around where personal data ends up and who can see it – it already surrenders the fact that these corporations are harvesting personal data and often selling it for capital gain.





