EU Regulation 2016/679 - Decision Register

DECISION OF THE FRENCH CNIL / 1 SEPTEMBER 2025

SHEIN €150 Million CNIL Fine, 2025 Cookie-Consent Decision Explained

France's Commission Nationale de l'Informatique et des Libertes fined Infinite Styles Services, the Irish operator of shein.com, €150 million for placing advertising cookies before consent, continuing to read them after users refused, and running consent banners that did not properly disclose the advertising purpose.

Fine amount

€150,000,000

Issuing DPA

French CNIL

Decision date

1 Sep 2025

Fined entity

Infinite Styles Services Co. Ltd

Legal basis

Art 82 (ePrivacy / cookies)

EDUCATIONAL ONLY

This page is a reference summary of a published regulator decision. It is not legal advice. Consult a qualified data protection lawyer for advice on your specific situation. The UK GDPR is a separate regime from the EU GDPR following Brexit. Always read the source decision in full before relying on any figure or quote.

DIRECT ANSWER / SHEIN €150M CNIL 2025

Why did the CNIL fine SHEIN €150 million?

On 1 September 2025 the French CNIL fined Infinite Styles Services Co. Limited, the Irish company that operates the shein.com website, a total of €150 million over its use of advertising cookies. The CNIL found that cookies requiring consent were placed on visitors' devices before any consent was given, that cookies continued to be read after users clicked “Refuse all” or withdrew consent, and that the information banners failed to describe the advertising purpose of the cookies and the third parties involved.

The site is visited by an average of around 12 million people in France every month, a scale that weighed towards the size of the penalty. Unlike the CNIL's Google decision the same day, no separate injunction or daily penalty was attached: the company had already corrected the practices during the proceedings. Like the other CNIL cookie fines, the decision rests on French ePrivacy law (Article 82) rather than the GDPR's substantive articles.

DECISION SUMMARY

What happened

The restricted committee (formation restreinte) of the CNIL adopted a decision on 1 September 2025 imposing a €150 million penalty on Infinite Styles Services Co. Limited, the Irish entity within the SHEIN group that runs the shein.com site for the European market. The decision followed an inspection of the website carried out by the CNIL in August 2023. Because the case concerns cookies under the ePrivacy framework rather than the GDPR's cross-border machinery, the CNIL was competent to act directly in respect of users established in France.

The CNIL identified several distinct failings in how shein.com handled cookies. Advertising cookies that required consent were deposited on visitors' terminal equipment as soon as they arrived on the site, before they had expressed any choice. When users did engage with the consent interface and chose to refuse, or later withdrew their consent, cookies continued to be read from their devices. And the information presented in the consent banner was incomplete: it did not clearly explain that the cookies served an advertising purpose, nor did it adequately identify the third parties placing cookies through the site.

The legal basis (and why it is not a GDPR-article fine)

The decision rests on Article 82 of the French Data Protection Act (the Loi Informatique et Libertes), the provision that transposes the ePrivacy Directive's requirement of consent before information is stored on, or read from, a user's terminal equipment. This is the same legal footing the CNIL used for its earlier cookie penalties against Google (€150 million and €90 million in 2022), Amazon (€35 million in 2020) and Microsoft (€60 million in 2022): the ePrivacy and national rules enforced by the CNIL under its own powers, rather than the GDPR's one-stop-shop mechanism and its substantive articles such as Article 6. The fine is nonetheless routinely counted among the largest data-protection penalties in France and within the wider GDPR-era enforcement record.

Why the fine was this size

The CNIL pointed to the scale of the audience exposed to the practices and the advertising benefit derived from cookie-based tracking. Shein.com is visited by an average of around 12 million people residing in France each month, so the number of individuals affected by the non-compliant cookie handling was very large. Depositing advertising cookies before consent and continuing to read them after a refusal go to the core of the consent requirement, and the incomplete banner information compounded the problem. Those factors together supported a €150 million penalty, one of the largest the CNIL has imposed and, alongside the €325 million Google decision issued the same day, part of the CNIL's largest single enforcement day to date.

Why there was no injunction

A notable feature of the SHEIN decision is what it does not contain. In many of its cookie cases, including the Google decision adopted the same day, the CNIL attaches an injunction requiring the operator to fix the practice within a set period, backed by a daily penalty for delay. Here the restricted committee concluded that no such compliance order was necessary, because the company had already brought its cookie practices into line during the sanctioning proceedings. The €150 million penalty therefore stands on its own, as a sanction for past conduct rather than a lever to force a future change that had already been made.

What this decision tells advertisers

The SHEIN €150 million fine reinforces the standard the CNIL has built through its cookie enforcement. Advertising cookies must not be placed before the user has consented; a refusal or a withdrawal of consent must actually stop the reading of cookies, not merely be recorded; and the consent banner must clearly disclose the advertising purpose and the third parties involved. The decision also shows that fixing the problem during an investigation can remove the need for an injunction, but it does not erase the penalty for the period of non-compliance. For any business running cookie-consent flows for a French audience, the practical lesson is that the moment cookies are set, the effectiveness of the refusal option, and the completeness of the banner information are exactly where the CNIL looks, and that penalties scale with the number of people affected.

FREQUENTLY ASKED

About the SHEIN €150 million CNIL fine

Why was SHEIN fined €150 million?
France's data protection authority, the CNIL, fined the company that operates shein.com for its handling of advertising cookies. The CNIL found that cookies requiring consent were placed on visitors' devices before they had agreed, that cookies continued to be read after users clicked 'Refuse all' or withdrew consent, and that the consent banner did not properly inform users about the advertising purpose of the cookies or about the third parties placing them. The restricted committee (formation restreinte) adopted the decision on 1 September 2025.
Who was actually fined? SHEIN or another company?
The penalty was imposed on Infinite Styles Services Co. Limited, the Irish entity within the SHEIN group that operates the shein.com website for the European market. Because the sanction concerns cookies under the ePrivacy framework rather than the GDPR's one-stop-shop, the CNIL was competent to act directly in respect of users in France, regardless of where the operator is established.
Is this a GDPR fine?
Not in the strict sense. Like the CNIL's cookie penalties against Google, Amazon and Microsoft, the SHEIN decision rests on Article 82 of the French Data Protection Act (Loi Informatique et Libertes), which transposes the ePrivacy Directive's consent requirement for storing or reading information on a user's device. It is not a fine under a substantive GDPR article such as Article 6 (lawful basis). It is nonetheless routinely counted among the largest French data-protection penalties, and it sits within the same GDPR-era enforcement landscape.
How many people were affected?
The CNIL noted that shein.com is visited by an average of around 12 million people residing in France each month, which is one of the factors that weighed towards the size of the penalty. The scale of the audience exposed to the non-compliant cookie practices, alongside the advertising benefit derived from tracking, supported a €150 million sanction.
Was SHEIN ordered to change its cookie banner?
No separate injunction or daily penalty was attached. Unlike the CNIL's Google decision on the same day, the restricted committee found it was not necessary to issue a compliance order because the company had already brought its cookie practices into line during the proceedings. The €150 million penalty therefore stands on its own, without an accompanying deadline-and-daily-penalty mechanism.
When did the CNIL start looking at SHEIN?
The decision followed an inspection of the shein.com website that the CNIL carried out in August 2023. The gap between the inspection and the September 2025 decision reflects the CNIL's standard sanctioning procedure: investigation, a report from the rapporteur, the operator's written and oral observations, and then the restricted committee's deliberation.

CROSS-REFERENCES

Related entries on this register

SAME-DAY CASE

Google €325M CNIL (2025)

The other CNIL decision of 1 September 2025, on the same ePrivacy footing. Google's did carry an injunction.

Open reference →

SUPERVISORY AUTHORITY

French CNIL

The Commission Nationale de l'Informatique et des Libertes: profile, cookie-enforcement approach and headline penalties.

Open reference →

RELATED CASE

Google €150M CNIL Cookie Fine (2022)

The earlier cookie decision that set the 'refuse as easily as accept' standard on the same Article 82 basis.

Open reference →

ARTICLE 7

Consent & Cookies

The consent doctrine underlying every CNIL cookie and electronic-marketing decision.

Open reference →

REGISTER

Full Decision Register

Every major GDPR and ePrivacy fine indexed by company, country, year and violation type.

Open reference →

SOURCES & CITATIONS

Primary sources

Figures as of September 2026. Verified against published DPA decisions.

REGISTER UPDATED 2026-04-28