Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The agreement authorizes disclosure of personal information, including account data, wallet balances, and loyalty points, to buyers or successors in corporate transactions such as mergers, asset sales, or bankruptcy proceedings, and asserts that users acknowledge and agree to the assignment of their personal data rights.
This analysis describes what Shein's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes pre-agreed user consent to data transfer in corporate transaction scenarios, which may be assessed under state privacy statutes that restrict the transfer of personal data to third parties without renewed consent or separate notice, depending on the jurisdiction and enforcement context.
Interpretive note: Whether the pre-agreed consent assertion satisfies the consent standards of each applicable state privacy statute is jurisdiction-dependent and may require enforcement-context evaluation.
Previously, Shein asked users to explicitly agree or disagree with account persistence for future logins. The updated terms remove this choice entirely. Instead of a consent decision, users now see a promotional discount offer in that location. This means users lose direct control over whether Shein maintains their login session across device visits, which affects convenience and privacy preferences around authentication persistence.
View change record →New provision explicitly authorizing transfer of user financial data (Wallet balance, points) and account information in M&A transactions without separate user consent.
View full change record →Under this clause, personal data including account information, wallet credits, points, and purchase history may be transferred to a new corporate entity in the event of a sale, merger, or bankruptcy, with the agreement asserting that users have acknowledged and agreed to such transfer by accepting the policy.
Cross-platform context
See how other platforms handle Corporate Transaction Data Transfer and similar clauses.
Compare across platforms →Monitoring
Shein has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"We may disclose personal information—including account information, Wallet balance or points information—to a buyer, prospective buyer, corporate affiliate, or other successors in the event of a merger, divestiture, restructuring, reorganization, dissolution, or sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding in which personal information held by us about our Services users is among the assets transferred. You acknowledge and agree to our assignment or transfer of rights to your personal information.Excerpt from Shein's Terms and Conditions
1. REGULATORY LANDSCAPE: This provision engages state privacy statutes in California, Colorado, Virginia, Texas, and other states that govern the transfer of personal data to third parties. The CPRA and similar statutes may limit the extent to which a pre-agreed consent embedded in a privacy notice constitutes valid authorization for a materially different data controller to assume processing rights. The FTC has historically scrutinized personal data transfers in bankruptcy and acquisition contexts under its Section 5 authority. 2. GOVERNANCE EXPOSURE: Medium. The assertion that users pre-agree to data assignment in all future corporate transaction scenarios, regardless of the nature of the acquiring entity or the scope of the transaction, may face challenge under state privacy frameworks that require consumers to be provided with updated notice and the opportunity to exercise rights when data is transferred to a materially different controller. 3. JURISDICTION FLAGS: California's CPRA creates heightened scrutiny for personal data transfers in M&A contexts, particularly where the successor's privacy practices differ materially from those disclosed in the current policy. The FTC has issued guidance indicating that personal data transferred in bankruptcy proceedings may not automatically inherit the consent under which it was collected. EU GDPR would apply to any EU resident data transferred in such transactions, requiring a lawful basis assessment independent of contractual notice. 4. CONTRACT AND VENDOR IMPLICATIONS: B2B contracts incorporating SHEIN data processing may require amendment triggers tied to change-of-control events. Prospective acquirers should conduct data due diligence to assess whether inherited data sets are accompanied by valid consent or notice sufficient to support continued processing under applicable law. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should evaluate whether the pre-agreed consent language in this provision satisfies the consent standards of each applicable state statute, and whether a change-of-control event would require re-notice to consumers and a renewed opt-out opportunity under applicable frameworks. Contract amendment protocols for M&A scenarios should address data mapping, consent inheritance, and regulatory notification obligations.
This provision establishes pre-agreed user consent to data transfer in corporate transaction scenarios, which may be assessed under state privacy statutes that restrict the transfer of personal data to third parties without renewed consent or separate notice, depending on the jurisdiction and enforcement context.
Under this clause, personal data including account information, wallet credits, points, and purchase history may be transferred to a new corporate entity in the event of a sale, merger, or bankruptcy, with the agreement asserting that users have acknowledged and agreed to such transfer by accepting the policy.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Shein.