DECISION SUMMARY
What happened
The restricted committee (formation restreinte) of the CNIL adopted a decision on 1 September 2025 imposing a €150 million penalty on Infinite Styles Services Co. Limited, the Irish entity within the SHEIN group that runs the shein.com site for the European market. The decision followed an inspection of the website carried out by the CNIL in August 2023. Because the case concerns cookies under the ePrivacy framework rather than the GDPR's cross-border machinery, the CNIL was competent to act directly in respect of users established in France.
The CNIL identified several distinct failings in how shein.com handled cookies. Advertising cookies that required consent were deposited on visitors' terminal equipment as soon as they arrived on the site, before they had expressed any choice. When users did engage with the consent interface and chose to refuse, or later withdrew their consent, cookies continued to be read from their devices. And the information presented in the consent banner was incomplete: it did not clearly explain that the cookies served an advertising purpose, nor did it adequately identify the third parties placing cookies through the site.
The legal basis (and why it is not a GDPR-article fine)
The decision rests on Article 82 of the French Data Protection Act (the Loi Informatique et Libertes), the provision that transposes the ePrivacy Directive's requirement of consent before information is stored on, or read from, a user's terminal equipment. This is the same legal footing the CNIL used for its earlier cookie penalties against Google (€150 million and €90 million in 2022), Amazon (€35 million in 2020) and Microsoft (€60 million in 2022): the ePrivacy and national rules enforced by the CNIL under its own powers, rather than the GDPR's one-stop-shop mechanism and its substantive articles such as Article 6. The fine is nonetheless routinely counted among the largest data-protection penalties in France and within the wider GDPR-era enforcement record.
Why the fine was this size
The CNIL pointed to the scale of the audience exposed to the practices and the advertising benefit derived from cookie-based tracking. Shein.com is visited by an average of around 12 million people residing in France each month, so the number of individuals affected by the non-compliant cookie handling was very large. Depositing advertising cookies before consent and continuing to read them after a refusal go to the core of the consent requirement, and the incomplete banner information compounded the problem. Those factors together supported a €150 million penalty, one of the largest the CNIL has imposed and, alongside the €325 million Google decision issued the same day, part of the CNIL's largest single enforcement day to date.
Why there was no injunction
A notable feature of the SHEIN decision is what it does not contain. In many of its cookie cases, including the Google decision adopted the same day, the CNIL attaches an injunction requiring the operator to fix the practice within a set period, backed by a daily penalty for delay. Here the restricted committee concluded that no such compliance order was necessary, because the company had already brought its cookie practices into line during the sanctioning proceedings. The €150 million penalty therefore stands on its own, as a sanction for past conduct rather than a lever to force a future change that had already been made.
What this decision tells advertisers
The SHEIN €150 million fine reinforces the standard the CNIL has built through its cookie enforcement. Advertising cookies must not be placed before the user has consented; a refusal or a withdrawal of consent must actually stop the reading of cookies, not merely be recorded; and the consent banner must clearly disclose the advertising purpose and the third parties involved. The decision also shows that fixing the problem during an investigation can remove the need for an injunction, but it does not erase the penalty for the period of non-compliance. For any business running cookie-consent flows for a French audience, the practical lesson is that the moment cookies are set, the effectiveness of the refusal option, and the completeness of the banner information are exactly where the CNIL looks, and that penalties scale with the number of people affected.