Overview
- China’s Public Security Bureau cybersecurity department said it issued an administrative penalty against Dior’s Shanghai branch, with the amount undisclosed.
- Authorities found the unit sent Chinese customers’ personal data to Dior’s headquarters in France without the required security assessment, standard export contract or certification.
- Officials said Dior failed to obtain separate, explicit consent from customers and did not apply required safeguards such as encryption or data de-identification.
- State media, citing the National Cybersecurity Notification Centre, reported the probe followed media coverage of a breach and that mainland users received alert texts from Dior.
- Dior previously said a May 7 incident exposed contact and shopping details but not financial data, and it notified regulators and customers, including a report to South Korea’s privacy commission.