CNIL sanctioned e-commerce platform SHEIN 150 million euros for violating its cookie policy

Insights
CNIL sanctioned e-commerce platform SHEIN 150 million euros for violating its cookie policy
Posted on: 17/12/2025

    On September 1, 2025, the Restriction Committee of the French National Commission for Informatics and Freedoms (CNIL) issued the Deliberation Judgment No SAN-2025-005[1], which is an important legal event confirming France's tough stance on compliance with cookie regulations[2]. The ruling sanctioned INFINITE STYLES SERVICES CO. LIMITED (ISSCL), a subsidiary of the SHEIN group, with a record administrative fine of €150,000,000.

     

     

    The core violation sanctioned by the CNIL is ISSCL's failure to comply with Article 82 of the French Data Protection Act (LIL) and the ePrivacy Directive. LIL stipulates that any storage or access to information on a user's terminal (including cookies and other tracking browsers) must be expressly consent, voluntary, specific, and informed in advance, with strict exceptions. The CNIL has found numerous serious violations related to the installation of non-consensual cookies, as well as deficiencies in the mechanisms for collecting and withdrawing user consent in France.

    1. Developments of the case

    INFINITE STYLES Group is a global economic organization, headed by Singapore-based parent company ROADGET BUSINESS PTE LTD. This group has many facilities in the European Union. Two key entities in the EU data management chain are INFINITE STYLES ECOMMERCE LIMITED (ensuring product distribution) and INFINITE STYLES SERVICES CO. LIMITED (ISSCL), both of which are wholly and directly owned by the parent company.

    ISSCL (located in Ireland) is an entity sanctioned by CNIL. As of August 1, 2023, ISSCL is responsible for managing the European subdomains of "shein.com" and operating all cookies on Shein's websites in the EMEA region (Europe, Middle East and Africa). The CNIL has clearly identified ISSCL as the data controller in relation to the placement and reading of cookies on the user's terminal of the "shein.com" website, a conclusion that was not disputed by the company during the proceedings.

    In addition, the group has a facility in France, INFINITE STYLES ECOMMERCE FRANCE (ISEF), which is wholly owned by INFINITE STYLES ECOMMERCE LIMITED. ISEF is responsible for promoting the SHEIN brand in France, mainly through offline activities such as organizing fashion shows and pop-up stores.

    On July 31, 2023, the CNIL issued Decision No. 2023-193C requiring verification of compliance with the French Data Protection Act (LIL) and the GDPR for all processing of data accessed from the "shein.com" domain name in France.

    The online test was conducted on 10/08/2023. After gathering information and communicating with the company, the reporter completed a sanctions report on February 18, 2025, recommending the Committee to Limit the Application of Administrative Fines and a compliance order with a periodic fine. The sanctioned company submitted two rounds of written feedback before the investigation officially ended.

    2. Shein's Violations Regarding Cookies

    The CNIL identified four major ISSCL violations during an online audit on 10/08/2023.

    Violation 1: Lack of consent before installing Cookies

    The first and most basic finding is that ISSCL places 10 cookies on users' devices as soon as they visit the website's homepage, before any interaction with the consent banner. This violates the basic principle of having consent before performing any action of writing or reading information on the terminal.

     

    Source: Journal Economique

     

    Cookies that are breached include:

    Advertising cookies (3): Includes _pinterest_ct_ua, _pin_unauth, and muc_ads. ISSCL acknowledged that this was a technical error and fixed it.

    Advertising Capping Cookies (6) (Capping Cookies): Includes no_pop_up_fr, hideCouponId_time,... ISSCL argues they don't need consent because they help improve the experience by preventing the same ad from showing too often. CNIL denied it, insisting that these cookies serve a broader advertising purpose and are not exceptional.

    Object measurement cookies (1): Cookie cookies used for A/B testing.

    Regarding cookie A/B testing, CNIL has conducted a thorough analysis of the exemption criteria. Although audience measurement cookies may be exempt if they are strictly limited  to measuring website performance and strictly necessary for the provision of services, the CNIL finds that cookies have an identification and storage value of up to 10 years. The CNIL argues that such a long "lifespan" is too intrusive, allowing users to be monitored for an unnecessarily long period of time. The CNIL emphasizes that exempt tracking browsers must strictly adhere to the principle of data minimization, and therefore, this cookie must be consented to.

    Violation 2: Involuntary and Prior Informed Consent

    According to both the GPDR and the LIL, Consent is only valid if it is voluntary and informed. The CNIL determined that ISSCL violated both of these criteria through user interface design.

    Firstly, in terms of notification, the CNIL believes that there is ambiguity in level 1 information (banner cookies) and serious omissions at level 2 (Consent Management Platform - CMP). The banner simply says that cookies are used to "offer content tailored to your interests". The CNIL considers that this description is insufficient to inform users that advertising cookies will be set to track their browsing across multiple websites for the purpose of personalizing ads.

    Second, at the second information level (CMP), ISSCL has failed to provide the identities of all third-party data controllers that place cookies. GDPR requires users to know the identity of the controller in order for consent to be communicated. This lack of information makes it impossible for users to fully assess the scope and consequences of the consent they are giving.

    Third, in terms of voluntariness, the CNIL points out that the simultaneous existence of two interfaces (cookie banner and "Welcome to the France site" pop-up) causes information overload and confusion. Notably, the pop-up only provides an "I agree" button and implies accepting cookies if the user continues to use them service, lacking an easy opt-out option. The CNIL considers it involuntary to only make the choice to accept unconditionally as a condition for continuing to browse the web, as it does not allow the user to have a real choice.

    Violations 3 & 4: Ineffective consent rejection and withdrawal mechanisms

    These violations involve not respecting the choice expressed by the user.

    Ineffective rejection

    Even if the user clicks the "Refuse All" button on the cookie banner and continues to browse the web, the CNIL still records the reading of   previously set cookies and  the writing  of new advertising capping cookies. This deprives the user of the effectiveness of the opt-out, because the user expects that no non-exempt cookies are set or read further once they have express clear intentions.

    Ineffective withdrawal of consent

    Similarly, the CNIL found that after a user has accepted the initial cookie, they then use the CMP to withdraw consent, the ISSCL mechanism still allows the reading of 75 existing cookies and  the writing of  10 new cookies (including third-party advertising cookies such as .bing.com). The CNIL takes the setting of new cookies after a user has withdrawn consent as particularly serious, as it completely disregards the user's choice.

     

     

    3. Strict decision of CNIL

    The CNIL asserts its material jurisdiction based on a clear distinction between two sets of legal rules in the EU area. The data processing is under investigation, in relation to the placement and reading of cookies on the user's terminal in France when browsing the "shein.com" subdomain.

    The CNIL rejected ISSCL's argument for the adoption of the GDPR's "One-Stop-Shop" (OSO) mechanism, which would give the Irish Data Protection Authority (DPA) authority. The CNIL is based on the consistent case law of the Conseil d'État (French Council of State), in particular the rulings against GOOGLE LLC (28/01/2022)[3] and AMAZON EUROPE CORE (27/06/2022).[4]

    In order to establish territorial jurisdiction over ISSCL (an Irish company), the CNIL demonstrated that: (1) ISSCL has a "facility" on French territory, and (2) the processing of cookies takes place "within the framework of its activities".

    Record fines

    To determine the application and amount of the fine, the CNIL used the criteria set forth in Article 83 of the GDPR, a provision that French law has chosen to harmonize the determination of fines, regardless of whether the violation is due to GDPR or ePrivacy. The CNIL insisted that the fine must be effective, proportionate and deterrent.

    The CNIL considered the following aggravation criteria: (1) The nature and severity of the violation. The CNIL finds that the company's actions constitute a serious breach of the privacy of data subjects. The processing of user data without their knowledge (setting cookies in advance of consent) and not respecting their opt-out/withdrawal choices has undermined control over personal data. (2) Processing scale: The processing process is considered to be very large. An average of 12 million unique visitors in France each month (from January to July 2023). (3) Negligence: The CNIL asserts that the company was negligent in complying with its obligations under Article 82 of the LIL. The CNIL emphasizes that cookie-related breaches are not new, and the CNIL has announced numerous sanctions for similar violations since 2020. In the context that the company is one of the leaders in the field of online sales, ISSCL cannot fail to know about the obligations. (4) Financial advantage: Although its main activity is retail, advertising personalization has helped the company increase product visibility and optimize marketing spend, especially through tracking users from other platforms such as Pinterest. Placing illegal cookies before consent has helped the company minimize the risk of rejection, thereby maximizing economic benefits.

    CNIL determined that ROADGET BUSINESS PTE LTD (parent company, Singapore) owns 100% of ISSCL (subsidiary, Ireland). Based on EU competition case law, there is an assumption that the parent company exercises decisive influence over the behavior of the subsidiary. Therefore, ROADGET BUSINESS PTE LTD and ISSCL constitute a single economic unit.

    The use of the concept of a single economic unit allows the CNIL to calculate the penalty based on the group's total annual global revenue, rather than just ISSCL's revenue. The CNIL concluded that the €150,000,000 fine  was appropriate and necessary to achieve the goal of deterrence for a corporation with such a large economic capacity.

    In addition, the CNIL rejected ISSCL's argument for non-disclosure of the decision, arguing that the disclosure measure was necessary and proportionate, given the severity of the violation, the company's market position, and the large number of affected users.  who need to be informed.

     

    Source: ICI

     

    4. Recommendations for Vietnamese businesses

    The SAN-2025-005 ruling sanctioning Shein's subsidiary – a global e-commerce platform is a clear demonstration of CNIL's assertiveness in enforcing digital privacy rights, especially in the field of ePrivacy[5]. The €150 million fine, calculated based on the group's global turnover, sets a precedent for how DPAs in the EU can penetrate multinational corporate structures to impose maximum deterrent penalties.

    Faced with great risks and risks of damage like the case of Shein, what do businesses operating e-commerce platforms in particular and Vietnamese companies in general need to do to minimize becoming companies that violate the law on personal data protection? According to HM&P, businesses should consider and implement some of the following solutions.

    Transition to opt-in model: All non-essential cookies (including analytics, advertising, social media, and similar trackers) must be completely blocked as soon as the user accesses the website. They are only allowed to work when the user actively clicks the "Accept" button. Businesses must consider removing the implied consent on the website. Because Vietnam's Law on Occupational Protection stipulates that consent must be clear, specific and voluntary.

    Establish transparency and voluntariness of consent. On the level 1 cookie banner, it must clearly and concisely describe the purposes of use. Not just say "Ads", but it should be clearly stated "Use cookies to track your browsing behavior on other websites for the purpose of displaying personalized ads. In addition, ensure that at level 2 cookies, users have easy access to a complete and up-to-date list of all third parties (data controllers) who will set cookies and process their data. In addition, the consent management interface is required to provide a "Refuse All" or "Manage Settings" button that is as prominent and accessible as the "Accept All" button. Article 28 of the Law on Environmental Protection 2025 also emphasizes the requirement to "establish a method to allow personal data subjects to refuse data sharing".

    Developing a detailed cookies policy: Businesses need to develop a  separate Cookies Policy or a detailed section of the Personal Data Protection Policy that clearly explains the types of cookies used and their storage periods.

    This ruling by the CNIL sends a strong message to all businesses that manage international e-commerce platforms and digital services that protecting the privacy and personal data of users has been a top priority. Any violation, even if it has not caused serious consequences, will be strictly and fairly sanctioned. This decision once again shows that the world and even Vietnam will force businesses doing business in cyberspace to strictly comply with national privacy regulations. Therefore, businesses must quickly find and implement appropriate and effective compliance solutions.


     

     

    [2] Cookies are small data files that a website sends to your browser and is stored on your device, which help the website remember information about you (such as login status, interests, browsing history) to personalize the experience (help you log in  faster, display relevant content) and  analyze behavior users, serving advertisements. They are not programs but just simple text data, which play an important role in making browsing the web more convenient and efficient

     

     

     

    [5] ePrivacy is an important legal framework of the European Union (EU) that protects privacy and personal data in the field of electronic communications, regulating the use of cookies, online marketing, messages, and other forms of electronic communications,  with the goal of complementing and tightening GDPR regulations for the digital environment.