And in terms of jurisdiction - it's a bit like you visiting Ireland on holiday and committing a crime - and then arguing they have no jurisdiction over you as you are only there for 2 weeks.
It's ridiculous.
A more accurate version of your analogy would be Ireland choosing to punish a tourist for littering with a dramatically higher penalty than native Irish would face based on their New York salary.
EDIT: here's more about the general mechanism I'm referring to https://archive.is/0hcAK
And yes, everything a multi-billion dollar company does is indeed the government's business - and the people's business. We have a right to regulate them as we see fit.
Ireland offers a favorable tax and regulatory environment, within the EU, so this punishment is not only Ireland’s business. It represents the EU.
How much value did tiktok derive from flaunting these privacy laws? It's not entirely unlikely that it was less than 530M€.
The law does say global revenues, and I think that is a deterrent to treating fines as just a cost of doing business.
If their global revenue was $1000, and the local revenue is $1, fining them $0.10 isn't going to help much.
If you do business in Europe, there's a bunch of (good!) privacy regulations you have to comply with. One of these is that you're not allowed to transfer the data to a jurisdiction that doesn't follow equivalent protections to the GDPR[0]. TikTok transferred European user data to their Chinese servers, which is a pretty obvious no-go, since the Chinese government is an authoritarian watchdog that inherently can't guarantee these protections (as the GDPR also applies to transferring data to the government.)
Ireland has jurisdiction because the EU offers something called the "one stop shop" concept, where a foreign company can declare that they have EU headquarters in a specific member state, and from that point on the only EU regulations they have to directly worry about are how they're implemented in that country in specific[1]. Every major tech company is therefore in Ireland because the country is small enough to essentially steamroll local politicians with lobby money, leading to very lax enforcement until the EU starts applying pressure.[2]
[0]: This also causes issues with data transfers to the US, and in the most extreme interpretation, makes it so that you probably can't do business with both Europe and the US at the same time in the first place. This is because of the CLOUD act, which goes across jurisdictions and is something the US government can use to compel any service provider to hand over data.
[1]: Of course, a country can still have it's own laws that a company can run afoul of on top of that.
[2]: Other countries with this issue are Luxembourg (Fintech companies love Luxembourg because they can just hire all the good lawyers, meaning you can't negotiate legal disputes there effectively) and the Netherlands (which is a EU-based tax haven for large corporations that aren't in either sector.)
Then Brexit happened and they just moved to the nearest available option.
Malta is (along with Gibraltar) a preferred destination for gambling operators.
No, it's because Ireland had a very low corporation tax with the strategy of becoming the preferred HQ for foreign companies in the EU.
https://en.wikipedia.org/wiki/Corporation_tax_in_the_Republi...
"By 2018, Ireland had received the most U.S. § Corporate tax inversions in history, and Apple was over one–fifth of Irish GDP. Academics rank Ireland as the largest tax haven; larger than the Caribbean tax haven system."
It's more about taxes and an efficient well-understood legal system (similar to the Delaware advantage on the latter). While the DPC used to be kinda useless, it has somewhat gotten its act together, and today issues most of the big GDPR fines. If you were trying to specifically avoid GDPR scrutiny, you'd locate elsewhere.
At the base level, I suppose my point was about morality, but my intent was about rationality. A country can write laws that it can take all the money a company earns across the entire globe, but it's not a very reasonable position, IMO.
I can tell you Russia’s “fine” is not reasonable because it’s not enforceable and exists to be purely performative. It’s not the same thing as Ireland putting a fine based on global revenue but still within their power to enforce.
> The Irish national watchdog serves as TikTok’s lead data privacy regulator in the 27-nation EU because the company’s European headquarters is based in Dublin.
This is likely under the GDPR, whose penalties are based on global revenue. If TikTok doesn't like it, it is of course free to cease activity in Europe (strictly speaking the GDPR also protects European citizens outside of Europe, but in practice if a company doesn't operate in Europe there is little that the EU can do).