Shein’s €150M CNIL fine: cookies set before anyone clicked (2025)
At a glance
- Brought by
- Regulator: CNIL (France)Regulator
- Company
- Shein (Infinite Styles Services)
- Sector
- Fast-fashion retail
- Law
- ePrivacy cookie rules (France)
- Amount
- €150M
- Date
- Decided Sep 1, 2025
- Status
- Decided
Summary
On September 1, 2025, France’s data protection regulator, the CNIL, fined the operator of shein.com €150 million for placing cookies, including advertising cookies, the moment a visitor arrived, before they used the banner, and for placing and reading cookies even after a visitor clicked “refuse all.”
What happened
The fine was against Infinite Styles Services Co. Ltd, the company that operates shein.com.
The mechanism
The banner was there, and it just did not gate what ran.

Why it was preventable
“What fires before consent” and “what still fires after I click refuse” are two direct scans. Either one would have surfaced this.
In the regulator’s words
The CNIL found: “Several cookies, particularly with advertising purposes, were placed on the devices of users visiting ‘shein.com’ as soon as they arrived on the site, even before they interacted with the information banner to express a choice.”
Timeline
- Sep 1, 2025decided (CNIL deliberation SAN-2025-005).
Source
Questions
Who fined Shein, and how much?
France’s data protection regulator, the CNIL, fined Infinite Styles Services (which operates shein.com) €150 million on September 1, 2025. The CNIL is a national data protection authority, separate from the EDPB and the EU as a whole.
What did the CNIL find?
Advertising cookies were placed on arrival, before the visitor used the banner, and cookies were placed and read even after a visitor clicked “refuse all.”
Why does clicking “refuse all” sometimes not work?
Because a banner can record the refusal without gating the tags. The only way to know is to test what still fires after you click refuse.
Related cases
Google’s €325M CNIL fine
Cookies steered during signup; Gmail inbox ads
CNIL’s €750,000 fine against Condé Nast
Cookies on arrival; “reject” did not stop tracking
American Express’s €1.5M CNIL fine
Cookies before, and despite, refusal
See what your tags send before it becomes a case
DataTrue runs real journeys on your site in each consent state and reads what each tag sends, field by field. A tag sending what it should not shows up in a test.
- Every page, with coverage scans
- Scheduled runs, with alerts when a result changes
- Full journeys, like checkout and signup, in each consent state
- What each tag sent, field by field
- PII detection with test personas
- iOS and Android app testing
- Pre-publish testing for GTM and Adobe Tags
- REST API, plus Slack and Jira alerts
The full platform, every feature, free for 30 days.
