Shein

Shein’s €150M CNIL fine: cookies set before anyone clicked (2025)

Regulator: CNIL (France)Last updated

At a glance

Brought by
Regulator: CNIL (France)Regulator
Company
Shein (Infinite Styles Services)
Sector
Fast-fashion retail
Law
ePrivacy cookie rules (France)
Amount
€150M
Date
Decided Sep 1, 2025
Status
Decided

Summary

On September 1, 2025, France’s data protection regulator, the CNIL, fined the operator of shein.com €150 million for placing cookies, including advertising cookies, the moment a visitor arrived, before they used the banner, and for placing and reading cookies even after a visitor clicked “refuse all.”

What happened

The fine was against Infinite Styles Services Co. Ltd, the company that operates shein.com.

The mechanism

The banner was there, and it just did not gate what ran.

Timeline: analytics and marketing tags send data after the page opens, before the visitor accepts or rejects the banner.

Why it was preventable

“What fires before consent” and “what still fires after I click refuse” are two direct scans. Either one would have surfaced this.

In the regulator’s words

The CNIL found: “Several cookies, particularly with advertising purposes, were placed on the devices of users visiting ‘shein.com’ as soon as they arrived on the site, even before they interacted with the information banner to express a choice.”

Timeline

  1. Sep 1, 2025decided (CNIL deliberation SAN-2025-005).

Source

cnil.fr.

cnil.fr

Questions

Who fined Shein, and how much?

France’s data protection regulator, the CNIL, fined Infinite Styles Services (which operates shein.com) €150 million on September 1, 2025. The CNIL is a national data protection authority, separate from the EDPB and the EU as a whole.

What did the CNIL find?

Advertising cookies were placed on arrival, before the visitor used the banner, and cookies were placed and read even after a visitor clicked “refuse all.”

Why does clicking “refuse all” sometimes not work?

Because a banner can record the refusal without gating the tags. The only way to know is to test what still fires after you click refuse.

30-day free trial

See what your tags send before it becomes a case

DataTrue runs real journeys on your site in each consent state and reads what each tag sends, field by field. A tag sending what it should not shows up in a test.

What DataTrue checks
  • Every page, with coverage scans
  • Scheduled runs, with alerts when a result changes
  • Full journeys, like checkout and signup, in each consent state
  • What each tag sent, field by field
Also in the full platform
  • PII detection with test personas
  • iOS and Android app testing
  • Pre-publish testing for GTM and Adobe Tags
  • REST API, plus Slack and Jira alerts
Start a free 30-day trial ★★★★★ 4.6/5 on G2

The full platform, every feature, free for 30 days.

DataTrue scan overview showing scan details and page status for a scheduled daily coverage scan
A scheduled daily coverage scan in DataTrue