CHRISTIAN DIOR PRIVACY POLICY

PRIVACY STATEMENT – PARFUMS CHRISTIAN DIOR (3)

Privacy statement

The Maisons Christian Dior Couture and Parfums Christian Dior attach particular importance to the processing, confidentiality and security of your personal data. We are committed to offering you personalized services while respecting your privacy and personal choices.

The purpose of this privacy policy (hereinafter “Statement”) is to inform you in a clear, simple and complete manner of the processing carried out on the personal data that you provide to us, or that each of our Maisons can collect from the various outlets contact you may have with us (e.g. shop, customer care, dior.com, social networks, digital applications, events), their possible transfer to third parties as well as your rights and the options you have to control your information protect your privacy, in accordance with current regulations.

During your shopping experience, and in order to inform you in advance, you will go from Maison Christian Dior Couture to Maison Parfums Christian Dior, or vice versa. Depending on the type of product ordered, the Data Controller will be either Maison Christian Dior Couture or Maison Parfums Christian Dior, within the meaning of the regulations applicable to personal data and in particular with regard to article 24 of the Regulations (EU) 2016/679 (hereinafter "GDPR").

As an example, referring to a few iconic products from the two Maisons:

Maison Christian Dior Couture
- Lady Dior bag
- 30 Montaigne bag
- Bar jacket

Maison Parfums Christian Dior
- J’adore or Sauvage perfume
- Dior Prestige beauty care
- Maquillage Dior Forever products

Christian Dior's 7 key engagements towards you and your personal data: 1.Christian Dior is engaged to respecting your privacy and your choices, particularly with respect to our commercial communications 2.Christian Dior is engaged in seeking the best security and applying the appropriate protection standards in its systems 3.Christian Dior will not sell your data 4.Christian Dior will only work with trusted partners 5.Christian Dior is engaged in updating its privacy notices and policies as regularly as possible 6. Christian Dior undertakes to respond to your requests as far as possible and within the time limits set 7.Christian Dior is engaged to applying data protection rights in a harmonized manner regardless of your location in the world

In this Statement, you will find information about:
• Who are we?
• What data we may collect about you
• How we collect or receive your data
• For what purposes we use your data
• How long we keep them
• Who are the recipients of your data
• How we protect them and ensure their confidentiality
• How we treat your preferences and your rights stemming from European Regulation
• The additional protections we offer to residents of certain regions
• How to contact us if you have questions about our use of your personal data
• Modification of this privacy statement

WHO are we?

The Maison Christian Dior Couture

Christian Dior Couture SA (head office), a public limited company under French law with its head office located at 30 avenue Montaigne, Paris 8, France, registered in the Paris Trade and Companies Register under number 612 035 832 and represented by Hien Tran Trung in his capacity as Administrative and Financial Director of Christian Dior Couture.

And all of the Christian Dior Couture affiliates with whom you share your information.

Christian Dior Couture is a story of dreams and elegance, passion and excellence; it is also a story of know-how. The creations of Christian Dior Couture express the passion for beautiful gestures and exceptional objects. From haute couture to ready-to-wear, including leather goods, watchmaking and jewellery, know-how is transformed into the art of making.

The Maison Parfums Christian Dior

Parfums Christian Dior (head office), a public limited company under French law whose head office is located at 33, avenue Hoche, 75008 Paris, France, registered in the Paris Trade and Companies Register under number 552 065 187, and represented by Laurent Kleitman in his capacity as Managing Director.

And all the affiliates of Parfums Christian Dior with whom you share your information.

Parfums Christian Dior is a story of dreams, glamor, creativity and excellence. The Maison, which has unique expertise, is made up of talented and ambitious professionals who are committed to perpetuating the heritage of the Dior heritage and transmitting their passion for beauty.

WHAT data do we collect about you?

"Personal data" means any information that identifies you either directly (such as your name) or indirectly (for example, using a unique customer number).

The personal data we collect depends on the point of contact through which you interact with us, as well as the purposes of this interaction as described in this Statement and are also limited to those which are relevant and appropriate for this interaction. Visitors to the Dior.com website who view our products, information and offers can choose to do so without logging in, and the same is true for point-of-sale search and browsing on social media. Unless you choose to interact with us through these contact points, for example:
• by creating an account and connecting to it
• by making a purchase on our site
• by subscribing to one of our programs or services
• by writing to us via the consumer contact forms
• or by writing us a comment in the free online order fields

Or else, our data collection is limited to the use of "cookies" (visitors) for website visitors whose conditions are specifically defined by our cookie policy and according to your preferences. For the sake of transparency and clarity, our cookie management policy is separate from this Statement.

The cookie management policy is accessible from this link.

For one thing, for customers and others who sign up for programs or services, we need to collect certain relevant information from you. The information we collect is related to a given transaction as well as in the context of our business relationship with you. For example, if you make purchases on Dior.com or in our points of sale, we must collect information to process (and, if necessary, execute and dispatch) your order, to ensure its tracking and invoicing, to be in order to respond to any after-sales inquiries you may have. For customers and others who sign up for our programs or services, we generally collect your contact information, contact preferences and information that allows us to make recommendations to you about our products or services that may be of interest to you. We can centralize information about our customers to organize it in one place, as this helps us manage our relationship with you as well as your choices and preferences. Finally, if you subscribe to our personalised newsletter, we collect your email address.

Depending on the data that you communicate to us or that you share with us, personal data may include information concerning:
• Your identity and contact details: surname, first name, postal address, email address, telephone number
• Your interests
• A history of your purchases (in store or online, including your orders, tracking and invoices, amount and type of purchase) and your repairs
• Your requests via our customer care service or our public relations service
• The Dior events in which you participate
• Your size and stylistic preferences (only for Christian Dior Couture)
• Your date of birth in order to benefit from the Birthday offers eligible according to your program
• Your satisfaction and comments on our programs, services and products
• The information that you specify related to the possible undesirable effects that you could report to us (only for Parfums Christian Dior)
• Your publications and mentions of our products on social networks

Regarding your purchases, payments are made via a secure payment platform, supplemented by control measures, including encryption of contact details, in order to guarantee the security of purchases made and to fight against fraud. Your bank details are therefore not accessible on Dior's servers.

We invite you to ensure that your data is regularly updated, either by modifying it directly on our sites or, by informing us in writing of any modification by referring to the dedicated section "How to contact us".

HOW do we collect or receive your data?

As part of our relationships, the data we collect may be collected through the following contact points:
• Course on Dior.com
• Exchanges with our advisors in Dior stores as well as points of sale in department stores
• Dior events in which you participate
• Relationship with our public relations services
• Contact with customer care
• Forms that you fill out (in store or online)
• Digital applications with which you interact
• Third party data providers with whom you share information
• Retailers for whom you agree to receive our communications
• Satisfaction surveys or questionnaires to which you answer
• Publications/mentions on social networks

We make sure to identify the personal data essential for the purpose for which it is collected by indicating it with an asterisk like this ‘(*)’ on each personal data collection form. If you do not fill in these mandatory fields, we will not be able to respond to your requests and / or provide you with the services requested. The other information is optional and allows us to know you better and improve our communications and services to you. Although not mandatory, we recommend that you fill them in to allow you to benefit from the best possible experience during our interactions with you.

During your purchase journey, you will be able to choose between i) logging into your existing Dior account, ii) creating a new account, or iii) paying as a Guest (or also called Guest Check out). This last purchasing experience is thus summarized as follows.

Payment for purchases as a Guest refers to the possibility for any Dior customer or prospect to make a purchase in our online store without logging into an account. Your information is collected for the process of payment and delivery of items or for Dior in order to comply with applicable laws. Your information may also be used for analytical purposes by Dior and for communication purposes via its preferred channel (for example: sending a general newsletter relating to the news of our Maisons by email for which you have the right to object). For more information on these purposes, please go to the section below, under the "Analysis and personalization purposes" section.

FOR WHAT PURPOSES is your data used by Dior?

We are required to use your data for purposes defined according to the nature of our relationships. Thus, depending on the context in which your data is collected, it may be used for one or more of the following purposes:
• Managing your orders
• Management of personalized content and Dior communications (digital or not)
• Managing your client profile (For example, in order to simplify your navigation through the different markets on our website: if you navigate to another market, your customer account will automatically be duplicated in that market. This means that it will not be necessary to create a new customer account)
• Managing your requests in connection with Dior
• The management of events in which you register / participate
• The management of alerts that you send us as part of our cosmetovigilance obligations (only for Parfums Christian Dior products)
• The management of our website and our digital applications
• Management and improvement of our products and services, image and reputation
• Transaction management (securing online payments, prevention of fraud, incidents related to payments and debts)
• Promoting our Maison on social networks
• The sending of a generic newsletter: you have the right to object if you no longer wish to receive it
• Analysis purposes: > analyse the performance of our brand on social networks in order to produce statistical analyses (studies of results by market, influence of the brand and analysis of the campaigns implemented). > analyse your preferences and habits, anticipate your needs from of your consumer profile and your publications/mentions on social networks. > personalised customer experience: we may provide you with personalised communications by means of email, postal mail, SMS or calls based on the communication preferences you have indicated and your consumer profile (where permitted) here https://www.dior.com/en_gb/beauty/account to channel preference manager if you have a customer account, otherwise you can contact our customer service (see section "how to contact us")). With your free, specific, informed and unambiguous consent (where required), we use your personal data to send you personalised communications based on your interests (newsletters, offers, invitations and surveys).

In the latter two interactions ('analysing your preferences and habits' & 'providing you with a personalised customer experience'), when we send personalised communications or content, we may use so-called profiling techniques. For the sake of transparency within this Statement, profiling is defined as any kind of automated processing of personal data which consists of using that personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict elements relating to the preferences, interests, behaviour or location of that natural person. In these circumstances, you have the right of opposition, meaning the right to withdraw your consent.

We ensure the legal basis for the processing of your data according to the purpose (s) concerned, which may be, depending on the context in which it is collected:
• Your explicit consent: for example, for the purposes of managing our personalized commercial offers, managing your browsing via cookies under the conditions defined by our Cookies Policy, or establishing your consumer profile in applicable cases
• The implementation of a contract, for example for your access to your customer account, the processing and follow-up of your orders ...
• A legal obligation when processing is required by law, for example, keeping purchase invoices to prevent fraud
• Our legitimate interest: for example, to improve our products and services, to defend ourselves, to secure our tools or to refine our customer knowledge via the tools of our third party partners and in particular to : o to define the personalised profile of our customers based on their interests and to offer them relevant offers from our brand on other websites; o identify audiences that are similar to our target audience (in order to deliver our offers to audiences of people who have similarities to our customers' profiles).

HOW LONG can we keep them?

Please note that the Maisons Parfum Christian Dior and Christian Dior Couture are independent entities, and each Maison has its own customer database. If you are a customer of both Maisons Dior and your data is deleted, either because of a deletion request from you or as part of our obligation to delete data after a certain period of retention, by one of the Maisons Dior and not by the other, our e-commerce site, which is shared by the Maisons Dior, may recognize you when you create a new account. If, for example, you wish to delete your data on the Parfum and Couture side, you must contact both Maison. (See section “HOW to contact us?” for contact details)

We keep your personal data only for the time necessary for the purpose pursued. In general, your personal data is stored in our database, as shown below:

For Maison Christian Dior Couture:


• Data subject: Any kind of customer (having a Customer profile or any Guest) Duration: 10 years from the date of the last purchase interaction


• Data subject: Prospect Duration: 3 years from the date of data collection Specificity: This period will be renewed each time you interact with Christian Dior Couture (e.g. participation in an event) or your consent to continue to interact at the end of this period


• Data subject: customer care (i.e.: calls for assistance, complaints or information) Duration: duration of the processing of the request, or 30 days maximum


• Data subject: Privileged interlocutors (e.g. agents, stylists, celebrity managers, artists) in relation to Christian Dior Couture Public Relations services Duration: 10 years from the date of your first contact Specificity: This period will be renewed each time you interact with Christian Dior Couture (for example a request for information on the Maison Christian Dior Couture)

For the Maison Parfums Christian Dior:


• Data subject: Regular customer (i.e.: having a Customer profile) Duration: 5 years from the date of the first purchase or account creation Specificity: This period will be renewed each time you interact with Parfums Christian Dior (for example a purchase or an update of your profile) or your consent to continue to interact at the end of this period


• Data subject: Prospect Duration: 3 years from the date of data collection Specificity: This period will be renewed each time you interact with Parfums Christian Dior (e.g. participation in an event) or your consent to continue to interact at the end of this period


• Data subject: Client ‘Guest’ (i.e. not having a Client account) Duration: 5 years from the date of first purchase Specificity: This period will be renewed each time you interact with Parfums Christian Dior (e.g. a purchase)


• Data subject: customer care (i.e.: complaints or information) Duration: duration of the processing of the request plus 5 years. For exercises of rights, under GDPR, the request is kept during its treatment plus 6 years


• Data subject: cosmetovigilance Duration: duration of the processing of the request plus 10 years in archive


• Data subject: Privileged interlocutors (e.g. agents, stylists, journalist, celebrity managers, artists) in relation to Maison Parfums Christian Dior Public Relations services Duration: 10 years from the date of your first contact Specificity: This period will be renewed each time you interact with Parfums Christian Dior (for example a request for information on the Parfums Christian Dior)

When we no longer need to use your personal data, it is deleted from our systems and our registers or made anonymous so that it can no longer be identified, subject to retention for archival purposes, claims and litigation management as well as to meet our legal and / or regulatory obligations and / or to respond to requests from authorities authorized to make the request.

WHO can access your data?

Your data is intended for the services of Maison Christian Dior concerned by your requests. We ensure that only duly authorized persons can access your personal data when this is necessary for the aforementioned purposes.

We do not share your data on to third parties for commercial purposes.

We are only required to communicate your information if necessary, and if possible in a form that does not allow direct identification to:
• Other Dior entities as well as department stores where you buy our products in order to provide you with identical personalized service worldwide
• Our trusted third-party providers, including other entities of the LVMH group, acting as subcontractors according to our instructions and on our behalf only

For example, we entrust certain services to third parties responsible for delivering a product to you, payment service providers and transaction security against fraud, third parties who assist us in the organization of our events, third parties providing services IT, digital communication and public relations agencies, third parties who assist us in customer care, third parties who assist us in qualitative surveys of our products, programs or services.


• Third parties including the LVMH group wishing to know your preferences and consumption trends for our programs and services in order to improve visibility, accessibility and performance


• Our trusted third party partners assist us in the management of your orders. In particular, we entrust certain services to third parties responsible for delivering a product to you, to payment service providers and to providers ensuring the security of anti-fraud transactions

Some key examples are listed below:
- DHL orders and deliveries (delivery), BlueLink (call center management), FluentCommerce (order and stock management) and any other service provider in management
- Ecommerce management SMILE (website host), CapGemini (eCommerce solution), Salesforce (management of customer profiles) and any other service provider in the management of your ecommerce shopping experience
- Payments and transaction security Cybersource (securing transactions against electronic commerce fraud), PayPal (payment service provider), OneyTrust (securing transactions against electronic commerce fraud) and any other payment service provider, verification, or banking provider

Please note that these partners may act as data controllers; in this case, they have their own privacy policies. We illustrate some examples in the list below:


• Third parties wishing to know your interests so that they can build similar audiences and target prospects corresponding to your profile. In the context of this specific processing, these partners may re-use the personal data made available to them to carry out autonomous and distinct targeting for commercial prospecting purposes, for which they are responsible, and are responsible for their legal and regulatory obligations.

Please note that in the context of re-use, these partners act as data controllers. You should therefore refer to their own privacy policies. We illustrate some examples below.
- Facebook (Privacy policy accessible here https://www.facebook.com/about/privacy/)
- Google (Privacy policy accessible here https://policies.google.com/privacy)
- Instagram (Privacy policy accessible here https://help.instagram.com/519522125107875/)

- Tiktok (Privacy policy accessible here)

- Snapchat (Privacy policy accessible here)

- Bing (Privacy policy accessible here)

- Pinterest (Privacy policy accessible here)

- Twitter (Privacy policy accessible here)


• Third parties conducting statistics on our performance on social networks on our behalf


• Third Parties in the event of a change of control or of status or company name, for legal reasons, or with your prior consent


• Third parties such as IAS (International Accreditation Service), which assists us, for example, in finding out the exposure rate of our created formats. For more information, their privacy policy is available here https://www.iasonline.org/privacy-policy/.


• Public authorities within the framework of their functions and missions of public interest, such as the establishment, exercise or defence of legal rights

You can also choose to disclose your personal data to our partners, advertisers and affiliates by following a link to and from their websites. Please note that these websites apply their own privacy policy.

We may also offer you the possibility of using your social media connection data. Please note that in this case, you are sharing your profile information with us. The personal data shared depends on the configuration of the social network platform. Please note that these social networks apply their own privacy policy.

HOW do we protect and ensure the confidentiality of your data?

We take all the necessary precautions to guarantee the confidentiality and security of your data and to prevent it from being distorted, damaged, destroyed or from unauthorized third parties having access to it.

We ask our partners and group companies to maintain a level of protection similar to ours concerning your personal data. The security measures put in place are evaluated and updated to face new threats and new challenges, as well as new legal requirements in the countries where we operate.

HOW do we process cross-border data flows?

Given the presence of Dior in many countries around the world and in order to provide you with personalized service worldwide, some of your data may be collected, accessible or stored outside your country of residence. You should be aware that data protection and security requirements differ from place to place and may not offer the same level of protection as those of your country of origin. However, Dior and our group companies have taken measures to guarantee an adequate level of protection of your data, regardless of their location, for example by using standard data transfer clauses, or any other method approved by the European Commission (where data protection legislation is considered to be the most effective in the world) and / or the National Data Protection Authorities. We also ask our third party partners to comply with the applicable data transfer obligations, for example by contractual clauses, with regard to the personal data they receive on our behalf.

In this context:
- Christian Dior Couture and all of its affiliates have entered into a Personal Data Processing and Transfer Agreement
- Parfums Christian Dior and all of its affiliates have entered into a Data Processing and Transfer Agreement
- In specific cases and roles, Christian Dior Couture and Parfums Christian Dior have entered into a Data Processing and Transfer Agreement

HOW are consumer preferences and individual rights treated?

In accordance with applicable laws and requirements, Dior and its group companies have put in place measures to guarantee respect for the rights of individuals with regard to personal data that we (or our third parties) have about them. This includes, for example, the right to know the data that we hold about you or to obtain a copy, as well as the limited rights to modify your data, to request erasure or to object to the processing of your data. We encourage those who have given their data to us to keep it up-to-date (for example, if you change your email address, address or telephone number), so that we keep your correct information in our files. We also encourage consumers to update their preferences with us, for example regarding products and frequency of contact, so that we can customize our service to suit your expectations and needs. Finally, we offer individuals the right to withdraw their consent from our programs and offers at any time. To do this, or to exercise any of these other rights, please use or the contact possibilities in the section "How to contact us" below. For people wishing to access their data, we also need authentication to ensure that we do not provide personal data to an unauthorized person.

WHAT additional protections are provided for residents of certain regions?

Dior has adopted the data protection and security practices described in this Statement for all individuals concerned. In addition, we have also identified and taken in to account the data protection and security measures required at local or regional level. This includes, for example, those required for residents of the European Union / European Economic Area under the General EU Data Protection Regulation (GDPR) 2016/679.

In particular, the GDPR provides the following rights:

• Right to information: you have the right to obtain clear, transparent and understandable information about how we use your personal data and about your rights. You will find all of this information in this Statement
• Right of access: you have the right to access the personal data that Dior holds about you
• Right of rectification: you have the right to have your personal data rectified if it is inaccurate or obsolete and / or to supplement it if it is incomplete
• Right to erasure / right to be forgotten: you have the right to have your data erased or deleted. However, this right may be limited by a legal reason or our legitimate interest in keeping your personal data
• Right of opposition: you can at any time request to no longer receive our communications relating to our offers, news and events. You can in particular use the hypertext link provided for this purpose in each email or communication that we send to you. You can also request to receive non-personalized communications about our products and services
• Right to withdraw consent at any time for data processing based on consent: you can withdraw your consent relating to our processing of your data when this processing is based on consent
• Right to data portability: you have the right to move, copy or transfer data from our database to another. This right only applies to the data you have provided, and provided that the processing is based on a contract or your consent and carried out using automated processes

If you wish to contact Dior regarding the exercise of your rights, please contact the Parfum Christian Dior and/or Christian Dior Couture Maisons depending on which Maison you belong to. Parfum Christian Dior and Christian Dior Couture are two independent Maison and manage their own customer database independently, so if you wish for example to delete your data on the Parfum and Couture side, you must contact both Maisons. (See section “HOW to contact us?” for contact details)

Dior has adopted practices aimed at avoiding collecting or storing information on children under the age of 15, in accordance with laws. If we learn that we have mistakenly collected information from people under the age of 15, we will purge it immediately, except to answer a single question or request from the person, their parent or legal guardian.

HOW to contact us?

1 / Please contact us in the manner below if you wish to exercise these rights or if you have questions or complaints regarding the processing of your personal data.

Christian Dior Couture


- By email to privacy@christiandior.com
- By online form: https://www.dior.com/en_gb/beauty/contact-parfum
- By phone: +44 (0)207 172 0172


- By post: Christian Dior Couture, 30 avenue Montaigne, 75008 Paris, France

Parfums Christian Dior


- By online form: https://www.dior.com/en_gb/beauty/contact-parfum
- By phone: +44 (0)20 7216 02 16

2 / You also have the right to contact the Dior lead data protection authority, the ICO (Information, Commissioner’s Office), at any time, in order to lodge a complaint against Dior's data protection and privacy practices.

3 / We also wish to inform you about the contacts of other authorities in Europe that you can find and contact on the website of the European Data Protection Board: https://edpb.europa.eu/about-edpb/board/members_en

Privacy statement

Last Updated: 26/06/2024


Confidentiality and security of your personal data are important to us. We would like to offer you personalized services while respecting your privacy and choices.


This Privacy Statement (“Statement”) is provided by The Maison Parfums Christian Dior (together, “Christian Dior,” “Dior,” “Maisons,” “we” or “us”), a luxury retail and wholesale brand with its global headquarters in Paris, France.


The purpose of this Statement is to inform you in a transparent and simple manner about the processing of the personal data that you provide or that we collect through the different touchpoints you use to interact with us (e.g. in store, client services, dior.com, social media, digital apps, events), about possible transfers to third parties, as well as your rights and options to control your personal data and protect your privacy.



WHO are we?

The Maison Parfums Christian Dior

Parfums Christian Dior SA (head office), a public limited company under French law whose head office is located at 33, avenue Hoche, 75008 Paris, France, and all of the affiliates of Parfums Christian Dior with whom you share your information.


Parfums Christian Dior is a story of dreams, glamor, creativity and excellence. The Maison, which has unique expertise, is made up of talented and ambitious professionals who are committed to perpetuating the Dior heritage and transmitting their passion for beauty.


• Who we are?
• What data may we collect or receive about you?
• How do we collect or receive your data?
• For what purposes are your data used by Dior?
• For how long may we keep it?
• Who may access your data?
• How do we protect it and keep it confidential?
• How do we address cross-border protections?
• How are consumer preferences and individual rights addressed?
• What additional protections are provided for residents of certain regions?
• Notice of Financial Incentive
• How does Dior protect children's privacy?
• How does Parfums Christian Dior use your data to serve the models and functionalities of generative AI?
• Contact Us



WHAT data may we collect or receive about you?

“Personal data” means any information that could reasonably identify you either directly (e.g. your name) or indirectly (e.g. through a unique client ID number).


The personal data we collect depends upon the touchpoint of our interaction and is also limited to that which is relevant and appropriate for the interaction. Unless you choose to interact with us via other touchpoints, such as (but not limited to) by making a purchase on our site, signing up for one of our programs (for example: My Exclusive Loyalty Program by Parfums Christian Dior) or services, using our apps, communicating with us via email, phone or submitting online forms, or posting a comment or a like online, our data collection is limited to the use of ‘cookies’ for website visitors.


For customers and other individuals who sign up for programs or services or otherwise interact with us beyond browsing our site via the touchpoints described above, for example, we collect certain relevant information from you. The information we collect is related to the particular transaction as well as our overall relationship with you. For example, if you make purchases from Dior.com or in our stores, we must collect information to process (and, if relevant, fulfill and ship) your order. For customers and other individuals who sign up for our programs or services, we generally collect your contact details, contact preferences, and information that will allow us to make recommendations to you about our products or services that may be of interest. We may centralize the information pertaining to our customers so that we have it organized in one place, as this helps us manage our relationship with you as well as your choices and preferences. Or, if you subscribe to our personalized newsletter, we collect your email address.


Should you wish to know more about the types of information we collect, please refer to the dedicated table provided via this link


We invite you to keep us regularly informed in writing of any change in your contact details.


We Collect and Use Limited Sensitive Information.


As described above, we collect personal data that is described under some laws as sensitive personal data,” special categories of personal data, sensitive personal information, or similar terms (collectively referred to here as “Sensitive Personal Data”). Here, we provide more information about which categories of the personal data described above may be designated as Sensitive Personal Data, and how we use these categories of Sensitive Personal Data. We only use Sensitive Personal Data to provide you goods and services, and do not use such information to infer characteristics about you. Depending on what you choose to provide and how we interact with you, we may collect:


  • Account log-ins to provide Dior products and services. Account login information is used to identify an active user on any site that requires login. Login information includes first and last name and corresponding email for such account, as well as the associated account password.
  • Financial information to process your orders. We collect and use credit or debit card information and required security or access codes in order to process payments and fulfill any order you make.
  • Passport-related information to process your orders. We may collect passport or other government-issued ID information in connection with an order, including when you are purchasing a product in a country other than that in which you live, in order for you to make purchases free of value added tax (VAT).
  • Self-reported data regarding undesirable side-effects to fulfill legal cosmetovigilance obligations. If you have a medical reaction to a Parfums Christian Dior product and choose to complete a questionnaire about those side effects and/or provide us with photos or other self-reported data, our client services and quality control team will evaluate the information and determine whether to provide it to a health regulator to fulfill legal cosmetovigilance obligations.


HOW do we collect or receive your data?

We may collect or receive data via the following touchpoints:

  • Use of Dior.com.
  • In-store, including in communication with our salesperson.
  • Dior events you attend.
  • Public Relations relationship and communication.
  • Contact with the Client Services.
  • Forms you complete (in store or online);
  • During your purchase journey, you will be able to choose between i) logging into your existing Dior account, ii) creating a new account, or iii) paying as a Guest.
  • Digital apps you use.
  • Digital experiences such as virtual beauty technology in store (if you choose to use that technology were offered via a retailer), or our third-party vendors may receive data via virtual try-on online;
  • Loyalty or rewards program you benefit from.
  • Dior social media pages you visit or interact with, or other social media pages on which you post Dior content or comments;
  • Digital media advertising you click on;
  • Search engines’ paid advertising you click on;
  • Retailers (such as Department Stores) in which you have purchased a Dior product and in which you consented (e.g. via an iPad) to have your details shared with one of the Dior Maisons to receive its communications; or
  • Surveys or satisfaction questionnaires you answer.


FOR WHAT PURPOSES are your data used by Dior?

Depending on the context in which your data is collected, we use your data for:

  • the provision of Dior products and services, including the management of your orders, the management of personalized content, communications and interactions with Dior (digital or otherwise), and providing customer support;
  • the facilitation of showing you what your selected product would look like on you (in relation to using our virtual beauty and try-on technology, though when online, all processing for providing the feature is done by our third-party vendors’ proprietary technology), and for certain in-store virtual try-ons, offering you the option of receiving your photo via email;
  • the management of your account and profile (for example, in order to simplify your navigation through our different country-specific websites, if you navigate to another country your customer account will automatically be duplicated in that market. This means that it will not be necessary to create a new customer account);
  • analyze the performance of our Maison on social networks in order to produce statistical analyses (studies of results by country, influence of the Maison and analysis of the campaigns implemented).
  • analyze your preferences and habits, anticipate your needs from your consumer profile and your publications/mentions on social networks.
  • personalized customer experience: we may provide you with personalized communications by means of email, postal mail, SMS or calls based on the communication preferences you have indicated and your consumer profile (where permitted) (if you have an account, please connect to either your Parfums Christian Dior account to modify your channel preferences. Otherwise you can contact our customer service (see "Contact Us" section below)). With your free, specific, informed and unambiguous consent (where required), we use your personal data to send you personalized communications based on your interests (newsletters, offers, invitations and surveys).

In the latter two interactions (“analyzing your preferences and habits” & “providing you with a personalized customer experience”), when we send personalized communications or content, we may use so-called profiling techniques. For the sake of transparency within this Statement, profiling is currently defined as any kind of automated processing of personal data which consists of using that personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict elements relating to the preferences, interests, behaviour or location of that natural person. In these circumstances, you have the right to opt-out, meaning the right to withdraw your consent by unsubscribing or see the “Contact Us” section below.


Should you wish to know more about the categories of processing activities for which we collect and use your information alongside indicative Legal basis for which we base such processing, please refer to the dedicated table provided via this link [place URL under “Via this link”]


The legal basis for the processing of your data can be, depending in which context your data is collected:

  • Your consent (e.g. to manage our tailored services, managing your browsing via cookies);
  • The performance of a contract (e.g. managing your access to your customer account, processing and tracking your orders, your subscription to our loyalty program);
  • A legal obligation when processing is required by law (e.g. retention of purchase invoices, cosmetovigilance for Parfums Christian Dior products); or
  • Our legitimate interest: improve our products and services, prevent fraud, secure our tools or tailor our communications.


FOR HOW LONG may we keep it?

Unless otherwise stated, we only keep your personal data for as long as we need it to fulfill the purpose of collection, to meet your needs, or to comply with our legal or business obligations, and to fulfill the purposes described above in this Privacy Statement. By way of example:


- for customers (i.e.: those that have a customer account) or Client ‘Guests’ (i.e. those that do not have a customer account but have made a purchase as a “Guest”), we keep your data up to 5 years from the last interaction with us (i.e: last purchase)

- for prospective customers (i.e. those that have not made a purchase and do not have a customer account, but are registered for our communications), we keep your data up to 3 years from the last interaction with us (i.e: participation in an event)

When you choose to use our Virtual Try-On tool, no photos or images are kept or stored beyond the end of the session.

When we no longer need to use your personal data, it is removed from our systems and records or anonymized so that you can no longer be identified from it.

We use the following criteria to determine how long to retain personal data:

  • Our relationship with you, and the products and services we provide to you;
  • Your requests to us regarding your information, or our products or services;
  • Any legal obligations to retain the data, or for our own legal purposes (such as enforcing our agreements or litigation);
  • Recommendations and legal requirements, including applicable international, national, federal and state statutes; and
  • Technical considerations and feasibility, and level of protections in place for your personal data.



WHO may access your data?

We communicate your information, including if possible in a form that does not allow a direct identification, to:


  • Other Dior entities as well as department stores where you buy our products in order to provide you with identical personalized service worldwide

  • Our trusted third-party providers, including other entities of the LVMH group, acting as subcontractors according to our instructions and on our behalf only

  • For example, we entrust certain services to third parties responsible for delivering a product to you, payment service providers and transaction security against fraud, third parties who assist us in the organization of our events, third parties providing services IT, digital communication and public relations agencies, third parties who assist us in customer care, third parties who assist us in qualitative surveys of our products, programs or services.

  • Third parties including the LVMH group wishing to know your preferences and consumption trends for our programs and services in order to improve visibility, accessibility and performance

  • Our trusted third-party partners assist us in the management of your orders. In particular, we entrust certain services to third parties responsible for delivering a product to you, to payment service providers and to providers ensuring the security of anti-fraud transactions.

  • Third-party partners, who provide advertising, marketing, website performance, analytics, and similar services for Dior, including cookies or other trackers, including for the purposes of behavior-based targeted advertising.

Before transferring data between different countries, we take into account the risks that this operation could create for the data; where appropriate, we rely on the mechanisms in place, such as the Data Privacy Framework in the United States or standard contractual clauses, to ensure that your rights relating to your data are protected. Where data is shared with third parties, we require them to guarantee the same protection for your data as we do.


Please note that these third-party partners may act as data controllers; in such cases, they have their own privacy policies. These third parties include:


  • Third parties in the event of a change of control, for legal reasons, or with your prior consent
  • Third parties wishing to know your main interests to constitute similar audiences and target prospects that match your profile. In the context of this specific data processing, Dior is not the Data Controller relating to prospecting and you will not be subject to prospecting, your data is only used to constitute profiles similar to yours

We illustrate some examples below:
- Facebook (Privacy policy accessible here)
- Google (Privacy policy here)
- Instagram (Privacy policy accessible here)
- Tiktok (Privacy policy available here)
- Snapchat (Privacy policy available here)
- Bing (Privacy policy available here)
- Pinterest (Privacy policy available here)
- witter (Privacy policy available here)

  • Third parties conducting statistics on our performance on social networks on our behalf
  • Third parties such as IAS (International Accreditation Service), which assists us, for example, in finding out the exposure rate of our created formats. For more information, their privacy policy is available here.

HOW do we protect it and keep it confidential?

We have adopted reasonable and appropriate physical, technical and organizational security safeguards to protect your data from loss, misuse, alteration, destruction or access by unauthorized third parties. The Internet, wireless networks and information storage are not 100% secure. We cannot guarantee the security of your personal data stored or sent to us. We encourage you to take precautions to protect your personal data. For example, in creating your account on dior.com, entering a personal password complying with our security requirements is compulsory and part of this Privacy Statement.

The security safeguards that we have adopted are commensurate with the sensitivity of the particular data collected. For example, credit, debit and other payment information is subject to stricter security measures.


Regarding your purchases, your bank details are encrypted through Dior servers. Payments are made via a secure payment platform which is PCI-DSS certified, supplemented by control measures, to ensure the security of purchases made and to fight against fraud.


We also require our partners and group companies to uphold a substantially similar level of protection for your data. The measures are evaluated and updated to address new threats and challenges, as well as new legal requirements in the countries where we operate.


To the maximum extent allowed by applicable law, you agree and acknowledge that Dior will not be liable or responsible for use or disclosure of your information that is the result of unauthorized or illegal access to our systems or those of our vendors, agents, contractors, affiliates, or partners. If you have reason to believe that the security of your communications or personal data has been compromised, please notify us immediately using the contact information below.



HOW do we address cross-border protections?

Because Dior operates in many countries across the world, some of your data may be collected, accessible or stored outside of your country of residence. You should know that the data protection and security requirements differ from place to place and may not offer the same level of protection as those in your home country. Nevertheless, Dior and our group companies have taken steps to ensure an adequate level of protection of your data irrespective of where it is located, such as by using data transfer methods approved by the European Commission (where the data protection laws are considered to be the strongest worldwide). We also require our third-party partners to fulfill applicable data transfer obligations in relation to the personal data that they receive on our behalf.


In this context:

- Parfums Christian Dior and all of its affiliates have entered into a Data Processing and Transfer Agreement
- In specific cases and roles, Christian Dior Couture and Parfums Christian Dior have entered into a Data Processing and Transfer Agreement

How are consumer preferences and individual rights addressed?

In accordance with applicable laws and requirements, Dior and its group companies have put in place measures to guarantee respect for the rights of individuals with regard to personal data that we (or our third parties) have about them. This includes, for example, the right to know the data that we hold about you or to obtain a copy, as well as the limited rights to modify your data, to request erasure or to object to the processing of your data. We encourage those who have given their data to us to keep it up to date (for example, if you change your email address, address or telephone number), so that we keep your correct information in our files. We also encourage consumers to update their preferences with us, for example regarding products and frequency of contact, so that we can customize our service to suit your expectations and needs. Finally, we offer individuals the right to withdraw their consent from our programs and offers at any time. To do this, or to exercise any of these other rights, please use or the contact possibilities in the section "How to contact us" below. For people wishing to access their data, we also need authentication to ensure that we do not provide personal data to an unauthorized person.


What additional rights are provided for residents of certain regions?

Dior has adopted the data protection and security practices described in this Statement for all individuals within scope. In addition, we also recognize and have addressed data protection and security measures that are required on a local or regional level. This includes, for example, those required for residents of the European Union/European Economic Area under the EU General Data Protection Regulation (GDPR) 2016/679.


In particular, the GDPR provides the following rights (with some exceptions):

  • The right to be informed: you have the right to obtain clear, transparent and easily understandable information about how we use your personal data, and your rights. You will find all this information in this Statement.
  • The right of access: you have the right to access to the personal data Dior holds about you.
  • The right of rectification: you have the right to have your personal data rectified if it is incorrect or outdated and / or completed if it is incomplete.
  • The right to erasure / right to be forgotten: you have the right to have your personal data erased or deleted. Please note this is not an absolute right, as we may have legal or legitimate grounds for retaining your personal data.
  • The right to object to direct marketing: you can unsubscribe or opt out of our direct marketing communication at any time. You are able to do so by clicking on the “unsubscribe” link in any email or communication we send you. You are also able to request to receive non-personalized communications about our products and services.
  • The right to withdraw consent at any time for data processing based on consent: You can withdraw your consent to our processing of your data when such processing is based on consent.
  • The right to data portability: you have the right to move, copy or transfer data from our database to another. This only applies to data that you have provided, where processing is based on a contract or your consent, and the processing is carried out by automated means.

You are also entitled to determine your personal data protection guidelines and directives in the event of death or extern circumstances.


You also have the right to contact the data protection authority of your country in order to lodge a complaint against the data protection and privacy practices of Dior.


We also wish to inform you about the contacts of other authorities in Europe that you can find and contact on the website of the European Data Protection Board: https://edpb.europa.eu/about-edpb/board/members_fr.


We may require proof of your identity and full details of your request before we process it.


How does Dior protect children's privacy?
Minors

Parfums Christian Dior is particularly committed to respecting the privacy of minors and avoids collecting personal data on minors under 15 years of age without their parents' consent.

In some cases, we need to obtain your consent to process your personal data, which we will do by means of a checkbox ☐ which you can click or not.

If you are over 15 years old, you can give your consent to the processing of your personal data on our website and therefore click on the dedicated check box.

If you are under 15 years old, you cannot give your consent alone and therefore click on the dedicated checkbox. You must obtain the consent of your parents or legal representative to use our services.

To find out more about how we handle your personal data, we invite you to read the full Privacy Policy. If you do not understand what is written on this page, or if you have any doubts about the use of your personal data, we advise you to speak to your parents or any other legal representative.


For holders of parental authority

Parfums Christian Dior may process the personal data of your minor child.

If you create an account on our website on behalf of your child in your capacity as a parent or guardian, please be aware that your child's personal data will be processed by Parfums Christian Dior in accordance with this Privacy Policy.


If your child under the age of 15 is browsing our website and his/her consent is required, we invite you in your capacity as the holder of parental authority to consent to the processing of your child's personal data in accordance with Article 8§1 of the GDPR and Article 45 of the French Data Protection Act (Loi Informatique et Libertés). As the holder of parental authority, you undertake to participate in your children's online activities to prevent data relating to your children under the age of 15 from being processed without your consent.

As the parent or guardian of a minor user, you can exercise your rights on behalf of your child and support him or her in doing so. In particular, you can request the deletion of your child's account. To do so, simply fill in the rights exercise form available here.


How does Parfums Christian Dior use your data to serve the models and functionalities of generative AI?

In addition to the primary purposes for using personal data described above, we may also use personal data we collect to:

Develop, operate, improve, maintain, protect, and deliver the Services and your overall user experience, including by means of training and refining our and our third-party providers’ artificial intelligence and machine learning models. At times we aggregate or pseudonymize data to help us to better understand our consumers, for example to measure our sales performance, identify audience segments.

What is generative AI?

Generative AI is the use of computer models to create new content. These models are a form of artificial intelligence trained by a large amount of information from different types of data, such as text and images. By studying this information, it is possible to identify relationships and associations between different types of content and to propose new content enriched with instructions and questions from its customers and prospects.


Where does Parfums Christian Dior obtain model training information?

Parfums Christian Dior uses external sources (e.g. Azure OpenAI) to train its models. It is part of a private LVMH body and relies on shared information about its products and services (e.g. publication of customer comments and opinions).

Data from Parfums Christian Dior products and services does not feed external sources such as Azure OpenAI, nor the LVMH AI model.


Why does Parfums Christian Dior use artificial intelligence services?

Parfums Christian Dior relies on its legitimate interest to develop and improve its Artificial Intelligence for the purpose of developing its products and responding to its customers' needs.


Confidentiality and generative AI

Parfums Christian Dior develops solutions to protect the confidentiality of personal data in terms of collection, use and sharing. Depending on the use, appropriate measures are implemented (automatic anonymization of nominative data, for example). Parfums Christian Dior customer data is not fed into any external source (neither LVMH AI nor Azure OpenAI).


Updates to this Statement

Dior reserves the right to change this Statement at any time at its sole discretion and will post the date it was last updated at the top of this Statement. Such changes shall be effective immediately upon posting them to Dior’s website, or otherwise providing them to you. We will provide additional notice to you if we make any changes that materially affect your privacy rights.


CONTACT US

If you have any general questions or concerns about how we process and use your personal data or would like to exercise any of your privacy rights, you may contact us at the Maison below that processes your personal information. Please note that you should direct any inquiries you may have about your data directly to the Maison that may hold your personal information. Each Maison manages its own database and cannot provide information about the data that may be held by the other Maison.


The Maison Parfums Christian Dior


Notice on the processing of data shared with the LVMH Group

How is your data shared with the LVMH group?

What is the context of the processing?

Parfums Christian Dior belongs to the LVMH Group, which comprises many exceptional Maisons that offer high quality products and services in all sectors including Fashion & Leather Goods, Perfumes & Cosmetics, Watches & Jewelry, Wines & Spirits, Selective Retailing and Hospitality, Culture & leisure. The list of all LVMH Maisons is available at https://www.lvmh.com. If you are customer of our Maison, you may also be a customer of other LVMH Maisons.


What is the purpose of the processing?

We endeavor to improve your experience by proposing personalized offers and services and customized marketing communications that correspond to your interests. This relies on knowing your preferences and interests.


How is the processing conducted?

If you consent, we will share the purchases you have made with us during the last 3 years with LVMH, our parent company, in a pseudonymous way (which means that your name and your contact details will not be sent to LVMH). Your purchases will be analyzed and matched with purchases made from other Maisons of the LVMH Group where you have given a similar consent. Each Maison that has your consent will receive back from LVMH generalized information concerning your purchasing habits and preferences.


Who is the Data Controller?

Parfums Christian Dior will remain the sole data controller which means that it is the company that is responsible for the information that you provide to it. LVMH acts as our data processor, or service provider, and will not use your data for any purpose other than the one described above. For example, LVMH will not use your data for its own purposes, will not contact you for marketing purposes based on the data we provide, and will not share information about you with Maisons of the LVMH Group to which you are not a customer and/or to whom you have not given consent.