Skip to content

Ireland Opens GDPR Probe into Shein Following TikTok’s €530M China Data Transfer Fine

May 8, 202655 second read

Cross-border data transfers to China are moving back into the European regulatory spotlight.

Ireland’s Data Protection Commission (DPC) has launched a formal GDPR investigation into Shein over the transfer of European user data to China.

Key Focus Areas
• Whether Shein’s Dublin-based EMEA entity complies with GDPR requirements for international data transfers
• Whether EU user data transferred to China receives “equivalent protection” under EU standards
• Increasing scrutiny on China-related data flows across the EU regulatory landscape

Context matters:
Last year, the Irish DPC fined TikTok €530 million over China data transfer concerns and ordered suspension measures unless compliance standards were met.

Why This Matters
For companies operating under GDPR, NIS2, or other EU digital regulations, vendor and processor exposure linked to China is rapidly becoming a board-level compliance issue — not just a privacy-team issue.

Since 2020, Ireland’s DPC has issued more than €4 billion in GDPR fines, reinforcing its role as one of Europe’s most influential privacy regulators.

At S8fe.ai, we help multinational organizations navigate cross-border data compliance, third-country transfer risks, and emerging global AI/data governance requirements.

Source: https://lnkd.in/gZ_UuPJg

Share this article

Back To Top