Chinese police have fined Dior’s Shanghai subsidiary after finding the company guilty of transmitting data overseas without security screening. Citing the National Cybersecurity Notification Center, state news agency Xinhua reported that the investigation followed media reports of a data breach at the French fashion brand, while users in mainland China received text messages from Dior. The cyber police said their findings indicated multiple violations of China’s Personal Information Protection Law by Dior Shanghai. This included the transfer of personal data of customers in China to the Dior headquarters in France without carrying out a data export security assessment, and failing to establish a standard contract for such export or obtain personal information protection certification. Dior Shanghai is also accused of failing to fully inform the customers of how their personal information would be used by the French headquarters, and to obtain their “separate consent” on this. Dior Shanghai further did not implement security measures such as encryption and anonymization for the personal information collected.
The statement said that police had imposed administrative penalties on Dior Shanghai but did not disclose the amount of the fines or other specific details. This is the first major case of breaching China’s sweeping Personal Information Protection Law, which has been in effect since November 2021. Under the law, companies need to get specific, separate consent to access sensitive personal information. They also need to have a formal security assessment and anonymization – a process that removes or modifies personally identifiable information – prior to data export. Companies that fail to comply face heavy fines.
The Shanghai case comes some four months after Dior issued a public apology over an unauthorized external party gaining access to some of the customer data it held. The unauthorized access exposed sensitive details such as names, genders, birth dates, contact information, passport numbers, occupations, and even records related to fraud allegations and international sanctions. In its statement of apology in May, the luxury fashion house said that no financial data, including credit card or banking details, had been compromised, the South China Morning Post reports.