The Shein website cookies fine shows that businesses must prevent non-essential cookies from loading before consent and must honour every refusal or withdrawal. On September 1, 2025, France’s data protection authority, the CNIL, fined Shein’s Irish subsidiary INFINITE STYLES SERVICES CO. LIMITED €150 million for violations involving cookies and other tracking technologies on shein.com.
The enforcement action followed an August 2023 inspection and was based on Article 82 of France’s Data Protection Act, which implements the EU ePrivacy rules governing access to information stored on users’ devices. The case is particularly important because the CNIL found problems not only with the consent banner but with the underlying technical behaviour of the website.
This article explains what the authority found, why an Irish company could be fined by France, and how website owners can test and correct their own cookie systems. It also examines how a consent-management platform such as iubenda can help automate cookie scanning, prior blocking, consent collection and record-keeping.
Key Takeaways
- Website cookies requiring consent must not load before the visitor makes a valid choice.
- Rejecting cookies must actually prevent non-essential tracking from continuing.
- Cookie banners must clearly explain purposes and relevant third parties.
- Website owners should test technical behaviour, not merely the appearance of their banner.
- Automated consent-management tools can reduce the risk of configuration failures.
The Shein website cookies fine is a warning to website owners
The €150 million penalty against Shein is one of the clearest recent demonstrations that website cookies are no longer a minor technical or design consideration. The CNIL announced that it imposed the fine on September 1, 2025 against INFINITE STYLES SERVICES CO LIMITED, the Irish company responsible for managing Shein’s European website domains. The authority’s investigation found several failures concerning the placing and reading of cookies on devices belonging to visitors in France.
The case matters far beyond Shein because the technical principles involved apply to a vast number of commercial websites. A publisher, online shop, hotel, advertising-supported magazine, SaaS company or small business can have exactly the same underlying problem if Google Analytics, advertising pixels, social-media trackers, audience-measurement tools or other non-essential technologies load before the visitor has consented.
The most important lesson is that a cookie banner does not automatically make a website compliant. The technology behind the banner has to enforce the visitor’s decision.
That distinction is critical.
A website can display a beautifully designed “Accept” and “Reject” interface while continuing to fire third-party scripts in the background. From a regulatory perspective, the appearance of the banner does not cure the technical violation.
What are website cookies and why did it cost Shein €150 million?
Website cookies are small files or pieces of information stored on a user’s computer, smartphone or other device by a website. Some are first-party cookies, meaning they are created by the website the visitor is using. Others are third-party cookies or tracking technologies associated with external services.
Cookies can have legitimate technical purposes. A shopping basket, authentication session, security mechanism or language preference may require information to be stored so that the website can operate correctly. The European Commission explains that certain cookies that are strictly necessary for a service explicitly requested by the user can be exempt from consent requirements.
The regulatory problem arises when cookies or other trackers are used for purposes such as behavioural advertising, profiling, audience measurement, social-media tracking or marketing and are activated before the visitor has provided the required consent.
The distinction between necessary and non-essential cookies is therefore fundamental.
A website owner cannot reasonably assume that every cookie is covered by a blanket “essential” classification. Each technology should be understood according to what it actually does, why it operates and what information it stores or accesses.

Get the legal help you need, with our DIY services or attorney advice. Either way, we’ve got your back.
What did the CNIL find on Shein?
The CNIL’s findings were significant because they involved the complete consent lifecycle rather than one isolated defect.
During an August 2023 inspection, the authority reproduced a visitor’s journey on shein.com and examined cookies stored on the visitor’s device. It found that several cookies, particularly advertising-related cookies, were placed as soon as users arrived on the website, before they had interacted with the consent banner.
That means the visitor’s first interaction with the website was already capable of triggering non-essential tracking.
The principle is straightforward. Where consent is required, the website must obtain that consent before placing or accessing the relevant information. The EU’s Your Europe guidance states that cookies requiring consent cannot be set when a webpage is first opened and may only be set after the required consent has been obtained.
This is the technical issue that many website owners misunderstand.
A banner appearing after a tracking script has already executed does not provide meaningful prior consent. The script must be prevented from firing until the visitor makes the appropriate choice.
Why “Reject All” must actually mean reject all
The second major problem identified by the CNIL was even more revealing.
The authority found that when visitors selected the equivalent of “Reject all”, new cookies could still be placed and cookies already present could continue to be read. The same problem could occur after a user subsequently withdrew consent.
This creates a fundamental contradiction between the website’s interface and its underlying technology.
If a visitor chooses not to permit advertising tracking, the website cannot present the choice as though it has been respected while continuing to operate advertising trackers.
The same principle applies to withdrawal. Consent is not a permanent authorisation that becomes irreversible once granted. Users must have a meaningful mechanism to change their decision, and the technical system must implement that change.
The CNIL’s own decision states that the rules require not only consent before accessing or recording information on a user’s device but also the ability for users to withdraw that consent.
For website owners, this means a compliance test should include at least three distinct states: a visitor who has made no choice, a visitor who has rejected non-essential cookies and a visitor who previously consented but subsequently withdrew consent.
The website should behave correctly in all three situations.

Shein’s cookie banner also failed on information
The CNIL found another category of problem involving the information presented to visitors.
The first Shein banner contained options corresponding to cookie settings, rejection and acceptance, but did not adequately explain the advertising purposes of the cookies. A second interface offered an acceptance option without providing sufficient information about purposes. The CNIL also found that the second-level information did not properly identify third parties that could place cookies.
This is important because consent must be informed.
A visitor should be able to understand what they are being asked to authorise. The European Commission describes valid consent as being freely given, informed, specific and based on an affirmative action, with clear information about the purposes involved.
Consequently, “We use cookies to improve your experience” may be insufficient where the website is actually permitting advertising, profiling or third-party tracking.
The more sophisticated the tracking ecosystem, the more important accurate categorisation and disclosure become.
Why France could fine an Irish company
One of the most interesting legal aspects of the Shein case is jurisdiction.
Shein’s relevant subsidiary was based in Ireland, yet the French regulator investigated and fined the company for cookie practices affecting users in France.
The explanation lies in the relationship between the GDPR and the ePrivacy rules.
The CNIL specifically stated that the GDPR’s one-stop-shop mechanism does not apply to the cookie operations covered by this case because the relevant requirements derive from the ePrivacy Directive, transposed into French law through Article 82 of the French Data Protection Act.
This distinction is highly relevant to international website owners.
The GDPR and ePrivacy rules overlap in the broader privacy ecosystem, but they are not interchangeable. The technical act of accessing or storing information on a user’s device is subject to specific electronic-communications rules, while subsequent processing of personal data may also trigger GDPR obligations.
The result is that an international website cannot necessarily assume that its main corporate establishment determines which regulator can scrutinise its cookie practices.
If a website serves users in multiple European jurisdictions, its cookie compliance architecture deserves international consideration.

Why was the fine so large?
The size of the penalty reflects the scale and seriousness of the situation rather than the existence of a single incorrectly configured cookie.
The CNIL said the fine took account of several breaches, the scale of the processing and Shein’s position in the online ready-to-wear market. Approximately 12 million people residing in France visited shein.com each month, according to the authority. The CNIL also considered the fact that similar cookie practices had been sanctioned repeatedly since 2020.
The regulatory message is therefore broader than “Shein had a bad cookie banner”.
The message is that organisations operating high-traffic digital services are expected to understand how their tracking infrastructure actually behaves.
For a small website, a similar violation would not necessarily result in a €150 million penalty. Enforcement decisions consider circumstances and proportionality. Yet smaller organisations should not interpret the size difference as evidence that cookie compliance is irrelevant to them.
A recurring technical violation can affect businesses of every size.
The website cookie audit every owner should perform
The most useful response to the Shein case is a technical audit.
Open the website in a fresh private browser session where no previous consent has been stored. Open the browser’s developer tools and inspect the network activity and storage associated with the page.
The first question is whether non-essential cookies, pixels or tracking scripts appear before the visitor has made a consent choice.
The second question is what happens after selecting “Reject all”. Reload the page and inspect the browser’s cookies, local storage, network requests and third-party connections. Advertising and other non-essential trackers should not continue operating in a way that requires prior consent.
The third test is withdrawal. Accept the relevant categories, revisit the privacy controls, withdraw consent and then test whether subsequent tracking stops as required.
The fourth test concerns the information itself. Check whether the banner explains the relevant purposes, whether categories are meaningful, whether third parties are identified where required and whether users can make a genuine choice.
The fifth test should be performed across mobile and desktop environments because consent mechanisms can behave differently depending on how scripts are loaded.
This is where many websites discover that their visible cookie banner is working while the underlying scripts are not.

How website owners can correct cookie problems themselves
For technically capable website owners, the basic solution is conceptually straightforward.
First, inventory every cookie, pixel, script, tag and third-party service operating on the website. This includes technologies loaded through Google Tag Manager, advertising platforms, social-media plugins, analytics systems, embedded media and marketing automation tools.
Next, determine which technologies are strictly necessary and which require consent under the laws applicable to your visitors.
Non-essential scripts should then be configured so they do not execute before the appropriate consent is obtained.
The consent banner should present clear choices, explain the relevant purposes and provide a straightforward mechanism for changing those choices later.
The final step is testing. A compliant-looking banner is insufficient. The website owner needs evidence that the technical controls work.
For WordPress websites, this can become complicated because plugins and themes may introduce scripts independently of the site’s primary analytics configuration. Advertising networks can add additional technologies, while embedded YouTube videos, social-media widgets and other external services can create third-party tracking activity.
Consequently, cookie compliance should be treated as an ongoing technical process rather than a one-time installation.
Where iubenda can help
Website owners who do not have the technical resources to build and maintain this infrastructure themselves can use a consent-management platform such as iubenda’s Privacy Controls and Cookie Solution.
According to iubenda’s documentation, its system can scan websites for cookies and trackers, display consent banners, block scripts before consent and maintain consent records. Its documentation specifically describes prior blocking as a mechanism for preventing scripts that install non-essential cookies from running until the required choice has been made.
That functionality directly addresses one of the central lessons from the Shein enforcement action.
A website owner can also use iubenda’s cookie-management system to create and maintain a cookie policy and record user preferences. The company provides integrations for platforms including WordPress, Joomla, Magento and PrestaShop, while developers can integrate its JavaScript-based system directly.
For publishers and commercial websites using advertising, this can be particularly important because the number of third-party technologies can change without the site owner’s awareness.
A consent-management platform does not eliminate the website owner’s legal responsibilities, nor does installing a particular product guarantee compliance in every jurisdiction. Configuration still matters. The website’s actual tracking architecture, applicable laws, geographical audience and business model must all be considered.
The advantage is that specialist software can make the technical management considerably easier.

Website cookies are now a business responsibility
The Shein case demonstrates a fundamental change in the way website cookies should be regarded.
They are not merely small technical files and a cookie banner is not merely a piece of website decoration.
Cookies and associated tracking technologies can determine whether advertising platforms receive information about visitors, whether analytics systems record behaviour and whether third-party services can identify returning users. Consequently, the mechanisms controlling them can become part of a company’s regulatory risk profile.
The CNIL’s enforcement programme has been developing for years. The authority said its cookie action plan began in 2019, with guidelines and recommendations followed by repeated sanctions from 2020 onwards, particularly concerning advertising cookies and tracking. In September 2025, the CNIL announced both the €150 million Shein penalty and a separate €325 million penalty against Google as part of this continuing enforcement strategy.
That history makes the Shein decision more significant than an isolated regulatory event.
It represents continued enforcement.
For website owners, the practical lesson is clear. A visitor must be able to make a meaningful choice before non-essential website cookies are activated. That choice must be accurately communicated, technically enforced and capable of being withdrawn. The system must also remain accurate as new scripts, advertising partners and analytics technologies are introduced.
A business that takes these principles seriously can approach cookie compliance systematically: identify the technologies, classify them correctly, block those requiring consent until consent exists, provide transparent information, honour refusal, enable withdrawal and maintain evidence of user choices.
The technology required to accomplish this is increasingly accessible. Owners who have the technical expertise can build and test the controls themselves. Those who prefer specialist assistance can use a consent-management service such as iubenda’s Cookie Solution to help automate scanning, blocking, consent collection and record-keeping.
The Shein penalty ultimately demonstrates why website cookies deserve serious attention. The most dangerous cookie problem is not a banner that looks imperfect. It is a website whose technology continues tracking after the visitor has said no, or starts tracking before the visitor has had a meaningful opportunity to say yes.
For every website owner serving an international audience, that is a technical issue worth finding and fixing before a regulator does it for them.
Recent Articles
- Contour Airlines flights to Trinidad and Tobago: New nonstop Contour Service connects Trinidad and Dominica
- Back pain: Why sudden pain happens, what it means and when to seek medical care
- How mobile point-of-sale systems can improve retail operations and customer experience
- Planning a New York City, New York food day by neighbourhood, budget, and mood
- Responsible AI video editing for short-form creators
When you buy something through our retail links, we may earn commission and the retailer may receive certain auditable data for accounting purposes.
Follow Sweet TnT Magazine on WhatsApp

Every month in 2026 we will be giving away one Amazon eGift Card. To qualify subscribe to our newsletter.
You may also like:
10 Subtle signs of parental alienation to watch for in your NH custody battle
What happens after you are arrested for a violent crime?
The importance of immediate medical treatment after an accident
Car accident types and injuries one could sustain in Texas
Life after a car accident: The struggles you will face
Cape Girardeau car accident claim: The 5 actions you must avoid
10 reasons why you should buy a dashcam
5 Tips that can help you avoid truck accidents
How to protect your business truck drivers 24/7
Thermal runaway in batteries: A risk in hot climates and 10 things to do
Before you buy an electric vehicle, consider this
Tips for teenagers to get the most out of their driving lessons
How commercial trucks ensure product protection
@sweettntmagazine
Discover more from Sweet TnT Magazine
Subscribe to get the latest posts sent to your email.
Sweet TnT Magazine Trinidad and Tobago Culture
You must be logged in to post a comment.