Shein is facing an investigation by the Irish Data Protection Commission over how it transfers customer data to China.
The regulator said the inquiry will examine whether Shein Ireland has complied with its obligations under GDPR when transferring personal data belonging to people in the EU and EEA outside Europe.
Under GDPR, personal data sent to a country outside the EU must be given protections that are essentially equivalent to those available within the bloc.
DPC deputy commissioner Graham Doyle said: “When an individual’s personal data is transferred to a country outside the EU, the GDPR requires that this personal data is afforded essentially the same protections as it would within the EU.
“Recent regulatory action by the DPC, together with complaints to other European supervisory authorities, has brought data transfers to China, in particular, into focus.”
Doyle added that the inquiry was an “important strategic priority” for the regulator and said the DPC would work closely with other European supervisory authorities during the investigation.
A Shein spokesperson said the online fashion giant takes its data protection responsibilities “extremely seriously” and remains committed to complying with GDPR and all relevant data protection laws.
“Ensuring the security of our customers’ personal data is a top priority for our business,” the spokesperson said.
“We have been actively engaging with the DPC in recent months on our data protection approach, including a number of important ongoing initiatives that reflect our commitment to maintaining the highest standards in data handling.
“We look forward to presenting that work as part of this process.”
The inquiry marks the latest regulatory scrutiny facing the Chinese-founded fast fashion retailer, which has grown rapidly across Europe in recent years.
Click here to sign up to Retail Gazette‘s free daily email newsletter


