Privacy

TikTok privacy update in Europe confirms China staff access to data as GDPR probe continues

Comment

TikTok logo displayed on a smartphone
Image Credits: Jonathan Raa/NurPhoto / Getty Images

An incoming privacy policy change announced by TikTok yesterday for users in Europe — which, for the first time, names China as one of several third countries where user data can be remotely accessed by “certain” company employees to perform what it claims are “important” functions — has landed months ahead of expected movement on a year+ long investigation into the platform’s data exports to China under the bloc’s General Data Protection Regulation (GDPR).

The GDPR probe into the legality of the video sharing platform’s data transfers to China is being led by Ireland’s Data Protection Commission (DPC), TikTok’s lead privacy regulator in the region, which opened the inquiry just over a year ago. The DPC told TechCrunch today that it expects its TikTok data transfers inquiry to progress to the next stage in the coming months — with a draft decision slated to be sent to other EU DPAs for review in the first quarter of next year.

This ‘Article 60’ review process could lead either to an affirming of Ireland’s draft decision — which would then, in relatively short order, allow for a final decision to be issued (potentially before the middle of next year, judging by past inquiry timelines). However if other EU regulators raise objections to Ireland’s draft decision the inquiry would have to move to an ‘Article 65’ dispute resolution process — which could add many more months to the process before a final decision could be issued as the bloc’s regulators seek consensus.

It’s not clear whether TikTok’s announcement of the privacy policy tweak relates to this overarching GDPR investigation. The incoming changes — which are due to apply from December 2 — do also include an update on how the platform collects users location information so they are not wholly focused on data transfers.

But the disclosure of China staffers accessing European user data could also be a not-very-subtle attempt to preempt regulatory enforcement over its data transfers — and try to soften a future blow by being able to point to steps already taken to improve its transparency with European users. (Not that that is the only potential issue of regulatory concern vis-a-vis data exports, though.)

A spokesman for TikTok declined to comment on whether its updated privacy policy is in any way linked to the GDPR inquiry — saying it could not do so as the inquiry remains ongoing.

However in a blog post announcing the update, the company claimed the changes “include greater transparency into how we share user information outside of Europe”.

That’s notable because transparency is a key principle of the GDPR — while infringements of the transparency principle can lead to stiff penalties (such as the $267M fine for Meta-owned WhatsApp last year, after an Ireland-led inquiry found a string of transparency breaches).

Claiming you’re being transparent and actually being transparent are not necessarily the same thing, of course. So it’s worth noting that TikTok’s updated privacy policy appears to atomize key bits of information — such as the full list of countries where employees may remotely access European users’ data and for what specific reasons — across a number of collapsable menus and hyperlinks spread throughout the policy, thereby requiring a user to click around, follow multiple links and basically hunt for relevant intel amid a larger morass of data in order to piece together a comprehensive view of what’s happening with their data (rather than clearly articulating and collating everything into a single, easy to digest view).

So, if it’s transparency TikTok is really shooting for here it still looks like it has work to do.

Also still a work in progress for TikTok: A data localization project to store European users’ data in the region — which, earlier this year, it announced had been delayed again (until 2023).

Thing is, if TikTok intends to continue to allow employees located in countries with no EU adequacy agreement affirming they have essentially equivalent data protection standards as the bloc to have remote access to European users’ information then questions over the legality of its international data transfers are likely to persist.

As well as China, TikTok’s privacy policy names Brazil, Malaysia, Philippines, Singapore and the U.S. (which has only a preliminary agreement with the EU for a fresh data transfer agreement at the moment) as countries where employees have remote access to European user data without the cover of an adequacy agreement — saying it’s relying on standard contractual clauses (SCCs) for these transfers.

But, as the EDPB guidance on data transfers points out, each transfer to a third country must be individually assessed and some may not be possible legally, even with supplementary measures applied. So every single one of these transfers will need to stand up to regulatory scrutiny.

Given so many third country transfers, TikTok’s European data localization project can only — at least for now — be considered a PR exercise. And/or an attempt to curry favor with local regulators in the hopes they take a kinder view of ongoing data exports. Unless or until it ceases data exports to third countries and finds a way to fully firewall its parent entity in China from being able to access any European users’ data in the clear.

TikTok’s spokesman declined to comment on any future plans it may have to further adapt its data transfers in light of these challenges but he pointed back to its blog post — which describes its approach to data governance in Europe as being “centred on limiting the number of employees with access to European user data, minimising data flows outside of the region, and storing European user data locally.”

TikTok’s wider problem is that it’s facing dialed up regulatory scrutiny across the Western world more generally as a result of security concerns attached to the Chinese state’s ability to gain access to data commercial platforms/services hold on their users — with national security laws in its home country overriding the usual standard contractual protections.

Its platform also collects an awful lot of user data — which only fuels concerns about its capacity to be repurposed as a data honeypot for state surveillance or even for ‘soft power’ foreign influence ops.

While its tracking and profiling of users invites further specific regulatory headaches in Europe — on the privacy and consumer protection side — which are applying some limits on how it can operate.

For example, TikTok recently agreed to freeze a controversial change to the legal basis it relies upon to run targeting advertising after a formal warning from the Italian DPA — and some follow-up “engagement” from the DPC — over a plan to remove consent (and claim a legitimate interest to run targeted ads). So its profiling and ad targeting model is facing challenges on a number of fronts, even as it tries to defend its business against wider, geopolitical-related security concerns.

After EU child safety complaints, TikTok tweaks ad disclosures but profiling concerns remain

More TechCrunch

Featured Article

Bangladeshi police agents accused of selling citizens’ personal information on Telegram

Two senior police officials in Bangladesh are accused of collecting and selling citizens’ personal information to criminals on Telegram.

4 hours ago
Bangladeshi police agents accused of selling citizens’ personal information on Telegram

Carta, a once-high-flying Silicon Valley startup that loudly backed away from one of its businesses earlier this year, is working on a secondary sale that would value the company at…

Carta’s valuation to be cut by $6.5 billion in upcoming secondary sale

Boeing’s Starliner spacecraft has successfully delivered two astronauts to the International Space Station, a key milestone in the aerospace giant’s quest to certify the capsule for regular crewed missions.  Starliner…

Boeing’s Starliner overcomes leaks and engine trouble to dock with ‘the big city in the sky’

Rivian needs to sell its new revamped vehicles at a profit in order to sustain itself long enough to get to the cheaper mass market R2 SUV on the road.

Rivian’s path to survival is now remarkably clear

Featured Article

What to expect from WWDC 2024: iOS 18, macOS 15 and so much AI

Apple is hoping to make WWDC 2024 memorable as it finally spells out its generative AI plans.

10 hours ago
What to expect from WWDC 2024: iOS 18, macOS 15 and so much AI

In a research note, HSBC estimates that the Indian edtech giant Byju’s, once valued at $22 billion, is now worth nothing.

HSBC believes that $22 billion Byju’s is now worth zero

As WWDC 2024 nears, all sorts of rumors and leaks have emerged about what iOS 18 and its AI-powered apps and features have in store.

What to expect from Apple’s AI-powered iOS 18 at WWDC 2024

Apple’s annual list of what it considers the best and most innovative software available on its platform is turning its attention to the little guy.

Apple’s Design Awards highlight indies and startups

Meta launched its Meta Verified program today along with other features, such as the ability to call large businesses and custom messages.

Meta rolls out Meta Verified for WhatsApp Business users in Brazil, India, Indonesia and Colombia

Last year, during the Q3 2023 earnings call, Mark Zuckerberg talked about leveraging AI to have business accounts respond to customers for purchase and support queries. Today, Meta announced AI-powered…

Meta adds AI-powered features to WhatsApp Business app

TikTok is testing streaks that are similar to Snapchat’s in order to boost engagement, including how long people stay on the app.

TikTok is testing Snapchat-like streaks

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! Your usual…

Inside Fisker’s collapse and robotaxis come to more US cities

New York-based Revel has made a lot of pivots since initially launching in 2018 as a dockless e-moped sharing service. The BlackRock-backed startup briefly stepped into the e-bike subscription business.…

Revel to lay off 1,000 staff ride-hail drivers, saying they’d rather be contractors anyway

Google says apps offering AI features will have to prevent the generation of restricted content.

Google Play cracks down on AI apps after circulation of apps for making deepfake nudes

The British retailers association also takes aim at Amazon’s “Buy Box,” claiming that Amazon manipulated which retailers were selected for the coveted placement.

UK retailers file a £1.1B collective action against Amazon over claims of data misuse

Featured Article

Rivian overhauled the R1S and R1T to entice new buyers ahead of cheaper R2 launch

Rivian has changed 600 parts on its R1S SUV and R1T pickup truck in a bid to drive down manufacturing costs, while improving performance of its flagship vehicles.  The end goal, which will play out over the coming year, is an existential one. Rivian lost about $38,784 on every vehicle…

14 hours ago
Rivian overhauled the R1S and R1T to entice new buyers ahead of cheaper R2 launch

Twitch has come up with a solution for the ongoing copyright issues that DJs encounter on the platform. The company announced Thursday a new program that enables DJs to stream…

Twitch DJs will now have to pay music labels to play songs in livestreams

Google said today it is partnering with RapidSOS, a platform for emergency first responders, to enable users to contact 911 through RCS (Rich Messaging Service).

Google partners with RapidSOS to enable 911 contact through RCS

Long before product-led growth became a buzzword, Atlassian offered free tiers for virtually all of its productivity and developer tools. Today, that mostly means free access for up to 10…

Atlassian now gives startups a year of free access

Featured Article

A social app for creatives, Cara grew from 40k to 650k users in a week because artists are fed up with Meta’s AI policies

Artists have finally had enough with Meta’s predatory AI policies, but Meta’s loss is Cara’s gain. An artist-run, anti-AI social platform, Cara has grown from 40,000 to 650,000 users within the last week, catapulting it to the top of the App Store charts. Instagram is a necessity for many artists,…

14 hours ago
A social app for creatives, Cara grew from 40k to 650k users in a week because artists are fed up with Meta’s AI policies

Google has developed a new AI tool to help marine biologists better understand coral reef ecosystems and their health, which can aid in conversation efforts. The tool, SurfPerch, created with…

Google looks to AI to help save the coral reefs

Only a few years ago, one of the hottest topics in enterprise software was ‘robotic process automation’ (RPA). It doesn’t feel like those services, which tried to automate a lot…

Tektonic AI raises $10M to build GenAI agents for automating business operations

SpaceX achieved a key milestone in its Starship flight test campaign: returning the booster and the upper stage back to Earth.

SpaceX launches mammoth Starship rocket and brings it back for the first time

There’s a lot of buzz about generative AI and what impact it might have on businesses. But look beyond the hype and high-profile deals like the one between OpenAI and…

Sirion, now valued around $1B, acquires Eigen as consolidation comes to enterprise AI tooling

Carlo Kobe and Scott Smith believed so strongly in the need for a debit card product designed specifically for Gen Zers that they dropped out of Harvard and Cornell at…

Kleiner Perkins leads $14.4M seed round into Fizz, a credit-building debit card aimed at Gen Z college students

A new app called MyGlimpact is intended not only to help people understand their environmental footprint, but why they shouldn’t feel guilty about it.

How many Earths does your lifestyle require?

Prolific Machines believes it has a way of transitioning away from molecules to something better: light.

Prolific Machines, with a $55M Series B, shines ‘light’ on a better way to grow lab proteins for food and medicine

It’s been 20 years since Shira Yevin, the lead singer of punk band Shiragirl drove a pink RV into the Vans Warped Tour grounds, the now-defunct punk rock festival notorious…

Punk singer Shira Yevin pushes for fair pay with InPink, a women-focused job marketplace

While the transport industry does use legacy software, many of these platforms are from an earlier era. Qargo hopes its newer technologies can help it leapfrog the competition.

Qargo raises $14M to digitize and decarbonize the trucking industry

When you look at how generative AI is being implemented across developer tools, the focus for the most part has been on generating code, as with GitHub Copilot. Greptile, an…

Greptile raises $4M to build an AI-fueled code base expert