Chinese authorities fined Dior’s Shanghai subsidiary for transmitting customer data overseas without security screening, according to media reports. The National Cybersecurity Notification Centre investigation followed media reports of a data breach and alert messages sent to mainland users. Dior Shanghai violated China’s Personal Information Protection Law by transferring customer data to its headquarters in France without export security assessment, failing to establish standard contracts, and not obtaining personal information protection certification. The company also failed to inform customers how their data would be used by French headquarters and didn’t obtain separate consent. Additionally, Dior didn't implement security measures like encryption and anonymization. Police imposed administrative penalties but didn’t disclose fine amounts.
Dior Shanghai fined for illegal overseas data transfers
Upgrade to Pro
Luxury’s personalized toolkit for business in China.
Join now to sharpen your focus.
Subscribe now
Have an account? Login