Case Study

How SHEIN’s cookie banner cost it €150m

On 1 September 2025, France’s data protection authority fined SHEIN’s Irish operating entity €150 million over how its website handled cookies. Here’s what went wrong, and what the same failure would cost a UK business today.

Fine
€150m
Regulator
CNIL, France
Law
Art. 82, French Data Protection Act
Status
Under appeal

What CNIL found

CNIL’s investigation centred on shein.com, a site it noted around 12 million people in France visit every month. The fine wasn’t for using advertising cookies. It was for the specific way consent was (or wasn’t) handled around them.

Consent timing

Advertising cookies were placed on visitors’ devices the moment they landed on shein.com, before the cookie banner had even been shown.

Banner transparency

Two different cookie banners were shown to visitors over time. Neither explained what the advertising cookies were for, and the second offered only an "accept" button, no way to review or decline.

Third-party disclosure

Clicking through to "cookie settings" did not tell visitors which third parties would receive their data, or why.

Withdrawal rights

Choosing "reject all", or withdrawing consent already given, did not stop new cookies being set or remove the ones already placed.

Why this matters in the UK

CNIL fined SHEIN under French law, not GDPR. It’s the French equivalent of the ePrivacy rules the UK enforces through PECR, and cookie consent specifically sits under PECR Reg. 6, policed by the ICO rather than CNIL.

Until 5 February 2026, that would have mattered a lot: a UK PECR breach was capped at £500,000, however bad the underlying failure. Since the Data (Use and Access) Act 2025 reform took effect on that date, a Regulation 6 breach now carries the same ceiling as UK GDPR itself: up to £17.5 million or 4% of global annual turnover, whichever is greater.

In other words, a SHEIN-style cookie banner wouldn’t just draw a slap on the wrist from the ICO today. It would be exposed to a fine on the same order of magnitude as CNIL’s.

How this gets caught

Every one of the four findings above is the kind of thing our Compliance Audit is built to catch: cookies firing before consent, banners that don’t say what they’re for, missing third-party disclosures, and reject buttons that don’t actually reject anything. An audit doesn’t make a fine impossible, but it puts these specific failure modes in front of you before a regulator finds them first.

Worried your cookie banner has the same gaps?

Book a Compliance Audit and find out before a regulator does.

Source: CNIL decision reported 1 September 2025; Browne Jacobson, “Cookie compliance crackdown: SHEIN fined €150 million by CNIL”. SHEIN has stated its intention to appeal the decision.