SHEIN’s €150m cookie warning

The French regulator found advertising cookies arriving before visitors made their choice.

By GDPRFix · Published · 2 min read
AI-assisted reporting and commentary · Official sources linked below.
Source / announcement date: 3 September 2025

Regulator announcement; this article does not establish payment or the outcome of any subsequent appeal.

What happened

CNIL imposed a €150 million fine on Infinite Styles Services Co., the company concerned with the SHEIN website, on 1 September 2025. Its published findings included cookies placed before users interacted with the banner. The decision concerned French cookie rules under Article 82, rather than a generic fine for having a website without a banner.

Source: CNIL — original source ↗

What it means for your website

Your site does not need SHEIN’s traffic to benefit from the technical lesson. The order in which things load matters. A marketing script in a theme can run before a consent plugin has a chance to block it. A tag manager might be configured correctly while an embedded widget takes a separate path. Begin by tracing the actual source of each affected script. Do not assume that switching plugins will remove code installed somewhere else. After a fix, clear caches and test again as a new visitor, including product and campaign pages rather than just the homepage.

Three useful next steps

  1. Find every installation path for advertising scripts.
  2. Check pages with embedded content and campaign tags.
  3. Retest after deployment and cache clearing.

Sources & context

Official sources consulted on 1 October 2026. A regulator’s announcement records its findings at that time; it is not proof of payment or the outcome of every later appeal.

CNIL — original source

Our practical suggestions are GDPRFix commentary. A public website scan cannot establish your full legal position. For advice on a specific obligation or enforcement matter, use a suitably qualified adviser.

Keep reading