After admitting that it stored some EU user data on Chinese servers, TikTok will now be facing a new data transfer investigation headed up by Ireland's Data Protection Commission.
Temu is facing a ₩1.37 billion ($982,420) fine in South Korea over its data transfers to other countries. The privacy law violations are due to failure to adhere to the terms of the PIPA, the law of the land that saw significant amendments come into force in 2023 that put it roughly on par with the protections provided by the GDPR.
China has not received an adequacy decision for international data transfers due to known and expected access by the government. The six apps that the noyb privacy complaints are targeting are TikTok, AliExpress, SHEIN, Temu, WeChat and Xiaomi.
The Dutch privacy watchdog has hit Uber with a considerable fine for sending EU driver data overseas. The Netherlands' Data Protection Authority (DPA) is fining Uber €290 million, or about $324 million.
Aimed at restricting the flow of sensitive American data to "countries of concern" like China and Russia, this new executive order, signed by President Biden in February, has been framed by some as a step toward safeguarding the personal data of U.S. citizens from foreign threats.
GDPR complaint points out that Fitbit forces EU users to accept international data transfers as a requirement to use the service, something that may not meet regulatory standards for free and informed consent.
A new record for GDPR fines has been set as the European Data Protection Board (EDPB) is requiring Meta to pay $1.3 billion for its international data transfers related to the dissolution of the Privacy Shield framework.
The EU and US have reached an agreement in principle on a Privacy Shield replacement, but details of the data transfer deal are not yet available to the public.
The immediate order to cease use of Google Analytics pertains to a particular French website that was the subject of a GDPR complaint over data transfers, but signs show it expanding to the rest of the EU before long.
A recent decision by the European Commission has granted the UK the "adequacy" status needed for international data transfers to be considered legal under the terms of the GDPR.










