Article 46 GDPR Requires Demonstrable Transfer Compliance: Inadequate DTAs Can Ground Infringement Without a Supervisory Authority Re‑trying Third‑Country Law

1. Introduction

In Tiktok Technology Ltd and Anor v Data Protection Commission (Approved) [2026] IEHC 347, the High Court (Mulcahy J) determined a major statutory appeal under sections 142 and 150 of the Data Protection Act 2018 arising from the Data Protection Commission’s (“DPC”) own-volition inquiry into TikTok’s EEA-user data transfers to China via a “remote access” model (i.e. data stored outside China but made available to personnel in China).

The appeal primarily tested what Article 46 GDPR requires of controllers when relying on SCCs plus supplementary measures, and what the DPC must establish to find an infringement and impose corrective orders and administrative fines. A secondary but practically important strand concerned procedural fairness and adequacy of reasons where the DPC imposes a suspension order in a highly technical setting, and the High Court’s powers on a statutory “appeal on the record”.

The appellants (collectively “TikTok”) challenged: (i) infringement findings under Article 46(1) (international transfers) and Article 13(1)(f) (transparency), (ii) corrective orders (including a suspension of transfers), and (iii) the DPC’s entitlement to impose administrative fines (with fine quantum left for a later judgment).

2. Summary of the Judgment

  • Article 46(1) infringement upheld: The Court rejected TikTok’s core legal submission that the DPC had to independently prove (by its own third-country-law assessment) that protection in China was not essentially equivalent before finding infringement. Controllers must be able to demonstrate compliance when transferring data.
  • No impermissible reversal of burden of proof: The Court held the legal/evidential burden remained on the DPC; scrutinising the adequacy of TikTok’s verification and identifying material gaps was not a presumption of guilt.
  • Article 13(1)(f) infringement upheld: The Court agreed TikTok’s 2021 privacy policy had to identify the third countries (including China) and provide a basic factual description of the transfer mechanism (remote access).
  • Fines – entitlement upheld: The DPC was entitled to impose fines because the infringements were negligent; fine calculation issues were deferred to a second judgment.
  • Corrective orders (notably suspension) vacated and remitted: While the DPC applied the correct legal framework for proportionality, it failed (in the particular circumstances) to adequately address late but relevant expert material and failed to give adequate reasons for rejecting complex technical mitigation evidence (notably pseudonymisation/differential privacy under “Project Clover”). The Court proposed remitting the corrective-orders question to the DPC.

3. Analysis

3.1 The central doctrinal holding: “verify” entails “demonstrate” (Article 46 read with accountability)

TikTok argued that under Case C-311/18, DPC v Facebook Ireland (“Schrems II”), the DPC could only find an Article 46 breach after conducting its own assessment that Chinese law in fact prevented SCC compliance and that supplementary measures could not ensure essentially equivalent protection. The Court rejected that characterisation as an over-reading of Schrems II’s context (validity of EU transfer tools and supervisory authority duties once inadequacy is established), holding instead:

  • Article 46 is a permission structure: transfers are prohibited unless the controller can show the Article 46 conditions are met.
  • Accountability applies to transfers: Article 46 must be read with Articles 5(2) and 24(1), so a controller must be able to demonstrate compliant processing, including compliant transfers.
  • Inadequate DTAs can ground infringement: the DPC may find infringement where a controller’s assessment does not adequately address the relevant transfer scenario—without the DPC being required to re-run a full third-country-law inquiry to prove the opposite thesis.

This is framed as consistent with Schrems II’s statements that controllers must “verify” protection on a case-by-case basis and implement supplementary measures where needed, while preserving the GDPR’s objective that Chapter V prevents circumvention of EU-level protection by exporting processing abroad.

3.2 Precedents cited and their influence

(a) Schrems line: “essentially equivalent” protection and the controller/supervisor architecture

The judgment relies on Schrems II’s high-level architecture: transfers under Article 46 require an “essentially equivalent” level of protection (GDPR read in light of the Charter), with assessment considering both contractual safeguards and the third country’s legal system, especially public authority access. However, the Court distinguished Schrems II’s procedural posture—validity of Commission tools and duties of supervisory authorities when inadequacy is found—from the question here: whether a supervisory authority can find a breach based on a controller’s failure to conduct/record an adequate assessment addressing the actual transfer processing.

(b) Standard of review in Irish statutory appeals: LinkedIn v DPC

The Court adopted LinkedIn v DPC [2026] IEHC 235: the appeal is on the record, with discretion to admit new evidence/argument, and deference may be appropriate on matters within the DPC’s technical expertise. This shaped two key moves:

  • procedural defects do not automatically annul decisions where the appellate court can examine merits and (if sought) admit additional evidence;
  • where the DPC fails to provide reasons on technical conclusions, the court cannot meaningfully defer to “expertise” because the expert reasoning is not exposed.

(c) Fair procedures and finality: Facebook Ireland Ltd v DPC; Haverty; Klohn

On procedural fairness, the Court cited Facebook Ireland Ltd v DPC [2021] IEHC 336 for the need to balance rights to be heard against regulatory diligence and timeliness. It also drew on The State (Haverty) v An Bord Pleanála [1987] IR 485 and Klohn v An Bord Pleanála [2009] 1 IR 59 to emphasise that decision-making cannot be endlessly re-opened. But the Court held the DPC’s own conduct—continuing to accept and consider certain late materials while effectively sidelining other late but relevant materials—could, in context, create a fairness problem.

(d) Remittal in statutory appeals: O’Sheehan and An Bord Bainistíochta, Gaelscoil Moshíológ

A significant Irish administrative-law development is the Court’s acceptance that, notwithstanding the absence of an express remittal power in sections 142/150, an implied/inherent power to remit may exist where necessary to preserve the effectiveness and structure of the statutory scheme—drawing on O'Sheehan v Residential Tenancies Board [2024] IEHC 521 and the Supreme Court’s discussion in An Bord Bainistíochta, Gaelscoil Moshíológ v Labour Court [2024] IESC 38. This underpinned the remedy proposed for the flawed corrective-order reasoning: remittal back to the expert regulator rather than the High Court attempting a first-instance technical evaluation without adequate findings/reasons.

(e) “Criminal” character of GDPR fines and burden-of-proof arguments

The Court treated GDPR administrative fines as “punitive/criminal in nature” for Charter/ECHR purposes (drawing on Engel-type reasoning and CJEU/AG observations such as in NVSC), but held that presumptions and evidential approaches are not per se impermissible; and in any event the DPC still bore the burden to establish infringement by reference to an inadequate assessment. The Court used Case T-141/08, E.On Energie v European Commission to illustrate that expecting an undertaking to rebut strong direct evidence or address deficiencies does not necessarily offend the presumption of innocence.

3.3 Legal reasoning on the key factual hinge: “remote access” necessarily involves local processing

A core factual/legal hinge was TikTok’s emphasis on “data stored outside China”, said to be beyond Chinese enforcement jurisdiction by territoriality principles. The DPC’s decisive point—accepted by the Court—was that remote access entails personal data being processed on systems in China (albeit transiently), and TikTok’s assessments largely addressed the “stored abroad” scenario rather than the “processed in China” scenario.

The Court held that this “local processing” issue was not a new ambush: it was inherent in the Inquiry’s subject (transfers by remote access) and was signposted by RFIs. Accordingly, the infringement finding for the temporal scope (29 July 2020–17 May 2023) stood.

3.4 Corrective orders: proportionality acknowledged, but reasons and fair handling of evidence mattered

While the Court accepted that the DPC did not treat itself as mechanically bound to suspend transfers (and did address proportionality), it identified defects in how the DPC handled evidence relevant to whether suspension remained necessary after later measures (“Project Clover”) and later expert opinion:

  • Late expert material: given the DPC had not clearly closed the evidential phase and did consider other late updates, it should have substantively engaged with the third expert opinion on Chinese law insofar as it could bear on ongoing risk and proportionality.
  • Technical mitigation (pseudonymisation/differential privacy): the DPC summarised these measures but did not adequately explain why they failed to alleviate risk. Without reasons, the Court could not defer to the DPC’s technical expertise and could not safely determine the corrective-order necessity itself.

That combination led the Court to propose vacating the corrective orders and remitting the corrective-orders question to the DPC. Notably, the Court rejected the proposition that any procedural defect automatically annuls a decision in an appeal-on-the-record framework; remedy depends on whether the defect could have affected outcome.

3.5 Transparency (Article 13(1)(f)): naming third countries and describing remote access

The Court affirmed a robust transparency reading: telling users that data may be transferred “outside the EEA” and that SCCs may be used, without naming China (or other third countries) and without explaining the remote access model, was insufficient. The Court treated this as consistent with the GDPR’s purpose of enabling data subjects to understand risks, safeguards, and exercise rights.

3.6 Negligence threshold for fines (Ground 6) and why TikTok could be fined

Relying on Case C-683/21, NVSC and Case C-807/21, Deutsche Wohnen, the Court applied the low threshold: a controller can be fined where it could not be unaware of the infringing nature of its conduct. On the facts, transferring vast volumes of EEA-user data without an adequate assessment of the “processed in China” scenario satisfied negligence. The Court also upheld negligence regarding Article 13(1)(f).

4. Impact

  • Controllers’ transfer governance: DTAs must address the actual processing reality of the transfer tool used (including transient/local processing in the third country), not merely where servers are located.
  • Supervisory enforcement strategy: the DPC can ground an Article 46 infringement on inadequacy of the controller’s verification/demonstration, without being required to conduct (and prove) a complete, independent third-country-law determination in each case.
  • Corrective orders and reasons: where regulators reject complex supplementary measures (e.g. pseudonymisation/differential privacy), they must give intelligible reasons capable of appellate scrutiny; otherwise, remittal becomes likely.
  • Transparency drafting: privacy notices should specify third countries and explain the transfer mechanism sufficiently to be meaningful—particularly where the mechanism is central to the claimed legality (remote access, data localisation structures, etc.).
  • Litigation and remedy design: this decision strengthens the practical availability of remittal in Irish data protection statutory appeals where the court cannot safely substitute its own view for that of the expert regulator due to missing reasoning.

5. Complex Concepts Simplified

  • “Essentially equivalent” protection: third-country protection need not be identical to EU law, but must provide comparable practical safeguards and remedies, especially against public authority access.
  • SCCs + supplementary measures: SCCs are contractual. If third-country law can override them (e.g. surveillance mandates), controllers must add technical/organisational measures (encryption, access controls, minimisation, etc.) or stop transfers.
  • Accountability (Articles 5(2) and 24): controllers must not only comply but be able to prove they complied; for transfers, that means being able to show the assessment and safeguards were adequate for the actual transfer scenario.
  • Remote access as a “transfer”: making EEA personal data available for access from a third country can itself be a transfer, even if servers remain in the EEA/elsewhere.
  • Pseudonymisation vs anonymisation: pseudonymisation reduces direct identifiability but can still be personal data if re-identification is reasonably possible; anonymisation requires irreversibility in practice.

6. Conclusion

[2026] IEHC 347 confirms a demanding but workable transfer-compliance model: controllers relying on Article 46 must be able to demonstrate that their SCC-based arrangements and supplementary measures secure essentially equivalent protection for the real third-country processing involved—remote access included. Supervisory authorities may find infringement where a controller’s verification is inadequate, without being forced to “prove the opposite” by re-litigating third-country law from scratch in every inquiry.

At the same time, where a regulator imposes severe corrective measures in technically complex contexts, the judgment stresses two safeguards: consistent, fair engagement with relevant evidence (especially where the regulator continues to accept late material) and reasoned decision-making capable of meaningful appellate scrutiny. The High Court’s willingness to remit defective corrective-order determinations to the DPC underscores the institutional logic of the GDPR enforcement framework: courts review legality and rationality, but expert regulators must do the expert analysis—and explain it.