Irish Data Protection Commission Opens Inquiry Into EU-to-China Data Transfers
The Irish Data Protection Commission opened an inquiry this month into an online fashion retailer's transfers of EU and EEA personal data from its Irish entity to China, examining compliance with GDPR Article 5, Article 13, and Chapter V, with particular scrutiny on whether the arrangement guarantees protection "essentially equivalent" to EU standards. Separately, the Dutch data protection authori
BY FRONTIER DESK · JULY 2, 2026 · 1 MIN READ
The Irish Data Protection Commission opened an inquiry this month into an online fashion retailer's transfers of EU and EEA personal data from its Irish entity to China, examining compliance with GDPR Article 5, Article 13, and Chapter V, with particular scrutiny on whether the arrangement guarantees protection "essentially equivalent" to EU standards. Separately, the Dutch data protection authority fined a ride-hailing operator for unlawfully transferring Norwegian and Finnish drivers' and customers' personal data — including ID scans, location data, and chat content — to Russian servers without adequate safeguards, citing Russia's lack of an independent privacy authority. For cross-border data counsel, these enforcement actions confirm that EU regulators are treating third-country transfer adequacy as an active, fact-specific inquiry rather than a checkbox exercise, particularly for jurisdictions perceived as high government-access risk. Clients with data flows into China, Russia, or other non-adequacy jurisdictions should audit their Standard Contractual Clause supplementary measures now, since regulators are willing to order immediate cessation of transfers rather than issuing phased remediation timelines.