TikTok -v- Data Protection Commissioner (Fines) — Court examines calculation methodology for €480-550 million GDPR fines; considers referring questions to CJEU

Case
TikTok Technology Limited and TikTok Information Technologies UK Limited v. Data Protection Commission
Court
High Court (Ireland)
Date Decided
30 June 2026
Citation
[2026] IEHC 419
Topics
GDPR Administrative Fines; Data Protection; Corporate Group Liability; Supervisory Authority Powers
Source
Read the full opinion

Background

The Data Protection Commission (DPC) found that TikTok Ireland violated GDPR Article 46(1) by transferring personal data of EU users to China without adequate safeguards, and Article 13(1)(f) by failing to provide transparent information about those transfers. Following these findings, the DPC proposed administrative fines totaling €480–550 million: €450–500 million for the Article 46(1) breach and €30–50 million for the Article 13(1)(f) breach. In calculating these fines, the DPC had regard to the turnover of ByteDance, TikTok’s ultimate parent company, rather than TikTok Ireland’s own turnover. TikTok appealed the fines to the High Court.

The High Court had previously issued a main judgment on 3 June 2026 upholding the DPC’s findings that TikTok Ireland committed the alleged GDPR infringements and that those infringements were negligent in character. This judgment addresses the remaining issues concerning the calculation and amount of the fines themselves, specifically whether the DPC properly applied Article 83 GDPR.

The Court’s Holding

Justice Mulcahy reserved judgment on three remaining grounds of appeal: (1) whether the DPC impermissibly had regard to ByteDance’s turnover in determining the fining caps and actual fine amounts (Ground 7); (2) whether the DPC failed to provide adequate reasons for the fining decision (Ground 8); and (3) whether the DPC made errors in its interpretation and application of Article 83 GDPR (Ground 9). The court is examining whether Article 83(5) of the GDPR—which references the “total worldwide annual turnover of the preceding financial year”—permits reliance on a parent company’s turnover when the parent is deemed to exercise “decisive influence” over the subsidiary controller.

The judgment sets out the DPC’s reasoning: the DPC had treated TikTok and ByteDance as a single “undertaking” under the GDPR by applying competition law concepts of “decisive influence” derived from Articles 101–102 TFEU. By reference to the EDPB’s binding decision in the WhatsApp case, the DPC concluded that the parent company’s turnover was properly used both to set the fining cap and to calculate the quantum of the fine. TikTok disputes this interpretation, arguing that fines can only be imposed on the actual controller or processor and that parent turnover cannot be considered without a finding that the parent is jointly liable for the infringement itself.

The court is contemplating whether to refer questions to the Court of Justice of the European Union (CJEU) regarding the proper interpretation of Article 83 GDPR and the concepts of “undertaking” and “decisive influence” in the fining context, signaling that the resolution of these issues requires clarification of EU law.

Key Takeaways

  • The fining provisions of GDPR Article 83 raise unsettled questions about how to apply Article 83(5)’s reference to “turnover” when a controller is part of a corporate group with a parent company exercising decisive influence.
  • The DPC relied on the EDPB’s WhatsApp decision to support using parent company turnover for both the fining cap and the fine calculation itself, but TikTok argues this conflates concepts drawn from EU competition law with data protection fining principles.
  • A High Court in an EU member state has signaled readiness to refer the interpretation of Article 83 GDPR to the CJEU, suggesting the provision’s application to multinational groups remains judicially unsettled.

Why It Matters

This judgment addresses a critical gap in GDPR enforcement: how supervisory authorities calculate fines for data controllers that are subsidiaries of larger corporate groups. The €480–550 million fine against TikTok represents one of the largest GDPR penalties to date, and its legitimacy hinges partly on whether the DPC may look to the financial resources of the entire corporate group. If the CJEU rules that only the subsidiary’s turnover may be considered, supervisory authorities across Europe would be constrained in fining large technology companies. Conversely, if parent turnover is permissible, multinational entities face significantly larger potential fines—making the question material to corporate risk assessment globally.

The judgment also implicates the rule of law: TikTok has argued that applying fines on the basis of parent company turnover without making the parent a formal party to the proceedings, or without giving it the right to be heard, violates procedural fairness. The court’s approach to these fairness concerns will influence how supervisory authorities conduct multinational investigations and structure their enforcement decisions going forward.

⬇ Download the original opinion (PDF)Archived from the court's official source.
✉️ Get tomorrow’s cases before your first coffee
Daily Case Law is our free morning digest — the most substantive new decisions, filtered to your jurisdictions and topics, each linking back here for the full analysis.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top