Skip to content

Dior Shanghai Branch Penalized for Illegal Cross-Border Data Transfer

September 12, 20252 minute read

China’s public security authority announced that Dior’s Shanghai branch committed serious violations of China’s data protection laws by transferring Chinese customer data to its headquarters in France without mandatory legal safeguards.

Background
The issue traces back to a breach in May, when Dior discovered that external parties accessed parts of its customer data. The leaked information included:
• Names, gender, phone numbers, email addresses, mailing addresses
• Purchase amounts, shopping preferences
• Other non-financial personal data

Violations under PIPL
Authorities found that Dior Shanghai violated several provisions of China’s Personal Information Protection Law (PIPL):
• Failure to conduct the legal process (security assessment, standard contract, or protection certification) before transferring data abroad.
• Failed to obtain users’ separate consent or provide full transparency on overseas processing.
• Failed to implement required safeguards such as encryption or de-identification.

Consequences
Dior Shanghai has received an administrative penalty under PIPL. Authorities stressed that this case should serve as a warning for all companies managing cross-border data transfers.

Key Takeaway for Businesses
Operating in China means ensuring that any transfer of personal information abroad must be:
• Backed by legally required mechanisms
• Supported by robust technical protections
• Transparent to users

Compliance is no longer optional—it is mandatory.

S8fe.ai helps organizations address this complexity by consolidating jurisdictional obligations, automating transfer-risk evaluations, and providing a single control plane to manage compliance and data flows across borders.

Source: https://lnkd.in/gCAPA6XF

Share this article

Back To Top