top of page

18 September 2025

A-case-study-in-china-privacy-operations-the-dior-wake-up-call

A-case-study-in-china-privacy-operations-the-dior-wake-up-call

The investigation was launched after a data breach in May 2025 (impacted personal data of Dior’s customers - names, gender, phone, email, addresses, purchase, shopping preferences).


In September 2025, Dior's Shanghai subsidiary was penalized for PIPL violations

- unauthorized cross-border data transfers

- inadequate user consent practices

- insufficient technical security measures


PIPL cross border CBDT:

  • Privacy Impact Assessments (PIAs);

  • Standard Contractual Clauses (SCCs) with the CAC;

  • "Sufficient Notice" & "Separate Consent" such as Employee privacy notices, consent letters;

  • Data Processing Agreements (DPAs) for B2B data-sharing arrangements;

  • Outward-facing privacy policies for B2C scenarios.

Other reference:

- https://www.rplawyers.com/china-fines-dior-reminder-for-firms-to-secure-cross-border-data/#:~:text=On%209%20September%202025%2C%20the,Article%2051%20of%20the%20PIPL)

- https://www.china-briefing.com/news/diors-pipl-violations-china-key-lessons/

Copyright @2026 The University of Hong Kong. All Rights Reserved.
bottom of page