The Privacy SDK deployed on the Shein US privacy notice page is configured with GPC support enabled (enableGpcSdk: true), linking GPC settings to the Shein Privacy and Security Policy. This configuration indicates the platform is set up to recognize and process Global Privacy Control browser signals.
This analysis describes what Shein's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
Under CPRA regulations effective January 2023, businesses subject to California privacy law are required to treat a valid GPC signal as a consumer's opt-out of sale and sharing of personal information. This provision documents that the Shein platform has technically configured GPC signal processing, which is an operationally significant compliance mechanism for California-based users.
Interpretive note: The SDK configuration code documents technical enablement of GPC processing but does not confirm operational suppression of data flows to all advertising partners upon receipt of a GPC signal.
Previously, Shein asked users to explicitly agree or disagree with account persistence for future logins. The updated terms remove this choice entirely. Instead of a consent decision, users now see a promotional discount offer in that location. This means users lose direct control over whether Shein maintains their login session across device visits, which affects convenience and privacy preferences around authentication persistence.
View change record →Removal of GPC (Global Privacy Control) signal recognition indicates Shein no longer honors user privacy preference signals, weakening user control over data sharing.
View full change record →Provision renamed from 'Global Privacy Control Signal Detection' to 'Global Privacy Control Signal Recognition' with identical functionality.
View full change record →This provision establishes that Shein's consent management infrastructure is configured to recognize GPC browser signals as opt-out of sale or sharing of personal information for applicable users. Under CPRA, consumers using a GPC-enabled browser may have their opt-out preference automatically communicated to and processed by the platform.
How other platforms handle this
we do honor legally-recognized browser-based mechanisms (such as the Global Privacy Control designed to signal your opt out choices under certain state laws).
When you use them, we'll validate your request by verifying your identity (for example, by confirming that you're signed in to your Google Account).
If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.
"enableGpcSdk: true, gpcSetting: { privacyPolicyLink: '/Privacy-Security-Policy-a-282.html' }Excerpt from Shein's Terms and Conditions
1) REGULATORY LANDSCAPE: This provision directly engages the California Privacy Rights Act (CPRA) and regulations issued by the California Privacy Protection Agency (CPPA), which require businesses subject to CPRA to treat a GPC signal as …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Search "[your state] attorney general consumer complaint" to find your state's direct complaint form
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Under CPRA regulations effective January 2023, businesses subject to California privacy law are required to treat a valid GPC signal as a consumer's opt-out of sale and sharing of personal information. This provision documents that the Shein platform has technically configured GPC signal processing, which is an operationally significant compliance mechanism for California-based users.
This provision establishes that Shein's consent management infrastructure is configured to recognize GPC browser signals as opt-out of sale or sharing of personal information for applicable users. Under CPRA, consumers using a GPC-enabled browser may have their opt-out preference automatically communicated to and processed by the platform.
ConductAtlas has identified this type of provision across 290 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Shein.