Technology

TikTok Faces GDPR Complaints Over Alleged Cross-App Tracking

TikTok Faces GDPR Complaints Over Alleged Cross-App Tracking
Editorial
  • PublishedDecember 18, 2025

TikTok is facing formal complaints for allegedly violating the European Union’s General Data Protection Regulation (GDPR) by tracking users across multiple applications without their consent. The complaints, filed by the privacy advocacy group noyb, assert that TikTok has extended its surveillance capabilities beyond user interactions within the app, monitoring behaviors on unrelated platforms, including shopping and dating applications like Grindr.

The allegations stem from TikTok’s use of third-party tracking tools, particularly software development kits (SDKs) from companies such as AppsFlyer. According to noyb’s complaint, these tools enable TikTok to gather data on users’ activities across various applications. This cross-device tracking may reveal sensitive information such as shopping habits and personal relationships, raising significant privacy concerns.

Privacy Concerns and Regulatory Oversight

At the core of the controversy is the claim that TikTok’s tracking mechanisms operate continuously, even when users are not actively engaging with the app. This kind of persistent monitoring is seen as a violation of GDPR, which requires explicit user consent for processing personal data, particularly in sensitive categories such as health or sexual orientation.

In their filing, noyb highlighted how TikTok’s SDK interacts with that of AppsFlyer, allowing for a detailed collection of user data. This integration reportedly enables TikTok to link user activities on external platforms with their TikTok profiles, creating comprehensive behavioral profiles without users being aware of it. For example, one of the complaints alleges that TikTok tracked a user’s interactions with Grindr, potentially exposing sensitive details about their sexual orientation.

“These practices could compromise personal privacy and lead to discrimination,” noyb warned in their statement.

Potential Consequences and Industry Implications

The implications of these complaints are substantial, potentially resulting in hefty fines for TikTok under GDPR, which allows penalties of up to 4% of a company’s global annual turnover. As scrutiny over TikTok’s data practices intensifies, the company is already under the spotlight due to previous fines related to inadequate child privacy protections.

Industry experts express concerns that TikTok’s tracking methods exploit existing loopholes in mobile ecosystems. While operating systems like iOS and Android have introduced features designed to enhance user privacy, such as Apple’s App Tracking Transparency, third-party SDKs often bypass these protections by utilizing unique device identifiers.

Social media reactions reflect growing public unease regarding TikTok’s data practices. Many users have taken to platforms like X, formerly Twitter, to express their outrage, citing longstanding concerns over the app’s extensive monitoring capabilities. Posts have highlighted the potential risks associated with sharing personal data across platforms, further fueling distrust in TikTok’s ability to protect user privacy.

While TikTok has not yet provided a detailed response to the latest allegations, the company has previously emphasized its commitment to compliance with local laws and user privacy. Critics, including noyb, argue that these reassurances may lack credibility given the evidence of ongoing data tracking.

The outcome of these complaints could have broader ramifications for tech companies that engage in similar practices. If upheld, the findings may necessitate significant changes to how companies integrate tracking technologies, potentially setting a precedent for obtaining granular user consent for data sharing.

The situation also highlights the interconnected nature of app ecosystems. With shared tracking technologies, a breach in one platform can compromise user privacy across many applications, as evidenced by the recent impact on Grindr’s stock price amid these allegations. This interconnectedness raises critical questions about corporate accountability and user rights in the digital space.

As investigations continue, advocacy groups like noyb play a crucial role in holding tech companies accountable. Their efforts have previously resulted in substantial fines and policy changes, and they may prompt regulatory authorities to impose interim measures against TikTok and its partners.

Ultimately, this unfolding saga serves as a reminder of the urgent need for robust and transparent data practices in the tech industry. As consumers become more aware of potential privacy violations, there is growing demand for companies to prioritize user rights over data monetization. The ongoing scrutiny of TikTok may catalyze a shift towards more ethical digital environments, ensuring that user privacy is not sacrificed in the name of innovation.

Editorial
Written By
Editorial

Our Editorial team doesn’t just report the news—we live it. Backed by years of frontline experience, we hunt down the facts, verify them to the letter, and deliver the stories that shape our world. Fueled by integrity and a keen eye for nuance, we tackle politics, culture, and technology with incisive analysis. When the headlines change by the minute, you can count on us to cut through the noise and serve you clarity on a silver platter.