INDEX / DIRECTORY / DIOR / DIGITAL

Dior DIGITAL

DIGITAL INFRASTRUCTURE AUDIT UPDATED 2026-09-08
Digital Score 1.50 /10 D Dior - Complicity Index 315
Digital 1.50

Evidence-only forensic audit. Scoring happens downstream - see the main dossier for the composite assessment.

Forensic audits like this are reader-funded - no sponsors, no ads. Support OpenIntel →

Target: Christian Dior Couture and Parfums Christian Dior (the Dior maison)
Audit phase: Digital Audit
Date: September 2026
Scope: This audit distinguishes Dior-maison conduct from LVMH group arrangements and Arnault-family/Aglaé investment activity unless a source establishes a direct Dior relationship.1, 2, 3

Christian Dior Couture, identified as a société anonyme in its legal notice, is the Dior fashion-and-accessories web/data entity, registered in Paris under no. 612 035 832, with its registered office at 30 avenue Montaigne, 75008 Paris; Dior identifies it as principal data controller and states that subsidiaries may act as processors for particular activities.1, 4 Delphine Arnault is identified as Chairman and CEO of Christian Dior Couture, while Pierre-Emmanuel Angeloglou was appointed Deputy CEO reporting to her effective 15 April 2025.4, 5 Parfums Christian Dior is separately identified as a French société anonyme, Paris registration no. 552 065 187, registered at 33 avenue Hoche, 75008 Paris, with Véronique Courtois identified as CEO.6

Christian Dior Couture was listed in LVMH’s 2023 reporting as a fully consolidated, 100%-owned Paris entity; that record establishes consolidation within the LVMH reporting perimeter but does not independently confirm its immediate parent or unchanged ownership in 2026.2 Christian Dior SE’s 2025 annual report states that it held 42% of LVMH capital and 56% of voting rights at 31 December 2025, while the Arnault family group additionally held 8% of capital and 10% of voting rights.3 The same report records Arnault-family ownership of 97.50% of Christian Dior SE capital and 98.63% of exercisable voting rights, with Financière Agache holding 96.00% of Christian Dior SE capital.3 A 2022 AMF disclosure recorded closely similar historical control figures, while a March 2026 AMF filing identifies Christian Dior SE as closely linked to Bernard Arnault and identifies Antoine and Delphine Arnault as LVMH board members.7, 8

Enterprise Technology Stack & Vendor Relationships

Dior’s client data was managed through a third-party Salesforce CRM environment that was compromised in the 2025 breach campaign described below, and Dior had operated the affected customer-management SaaS system since 2020.9, 10, 11, 12 South Korea’s privacy regulator independently confirms the 2020 start date and the use of SaaS customer-management software, but does not name Salesforce or identify a hosting country.12

For AR beauty and virtual try-on, Parfums Christian Dior has contracted Perfect Corp, a beauty-technology firm headquartered in New Taipei City, Taiwan, with a New York presence, in a relationship operating since 2020 across Dior and retailer sites, Google platforms, WeChat and the Taobao Mini Program.13, 14 A 2022–2023 live-consultation offering paired Perfect Corp’s AR try-on with Bambuser, a 2021 LVMH Innovation Award winner.13, 15 Dior’s eyewear “Try Online” virtual try-on used facial-recognition technology supplied by FittingBox, a virtual-fitting company headquartered in Toulouse, France, with a Miami base.16, 17 None of Perfect Corp, Bambuser, or FittingBox is identified in the record as Israeli-domiciled.13, 16, 17

The material Israel-nexus vendor relationship in Dior’s documented stack is with Kahoona. LVMH’s primary June 2025 materials establish that Kahoona worked with Maison Christian Dior on a hyper-personalised browsing experience for unregistered visitors to the Dior website and won the 2025 Best Business Prize for that collaboration.18, 19 LVMH describes the product as real-time predictive audience segmentation for anonymous online visitors.18 This establishes a Dior-specific 2025 collaboration, but not the exact contracting Dior entity, commercial value, visitor volume, deployment geography, contract term, or whether the project continued after June 2025.18, 19

Kahoona’s own 2022 disclosure says it generated anonymised real-time user profiles by analysing website interactions and was building an R&D centre in Tel Aviv while recruiting sales and marketing staff in San Diego.20 A current Senior Data Scientist vacancy identifies Tel Aviv as an engineering/data-science location for predictive-model development and deployment.21 Its current materials state that it analyses first-party audience interactions for segmentation, does not use fingerprinting or third-party data sources, and claims not to collect PII; these are vendor representations rather than evidence of the fields, retention, access controls, or processing arrangements in Dior’s implementation.22, 23, 24

Kahoona’s location and legal-entity evidence is mixed: Startup Nation Central lists a Tel Aviv-Yafo address and Israeli registrar number, while its website footer identifies Kahoona, Inc. in New York and its privacy materials refer to Kahoona Labs, Ltd.25, 23, 24 Its terms select Israeli law and Tel Aviv District Court jurisdiction, but that does not establish the contracting entity for Dior or that Dior-derived data were processed, stored, routed, or accessible in Israel.24

In Israel, the diorboutique-il.com storefront is operated by DRRR Ltd, described as the exclusive Israeli distributor of Parfums Christian Dior, and runs on Shopify.26, 27 The available evidence identifies this as a distributor storefront rather than Christian Dior Couture’s corporate e-commerce infrastructure.26, 27

Parent-group context: LVMH and Google Cloud announced a strategic AI/cloud partnership in June 2021, under which LVMH modernised IT infrastructure and used cloud-based AI across group operations.28 This is a group-level arrangement, not evidence of a Dior-maison-specific Google Cloud contract.28

Surveillance, Biometrics & Retail Technology

Dior operated an eyewear virtual try-on tool that, according to a 2022 class-action complaint, used FittingBox software to scan facial geometry for eyewear overlay.16, 29 The complaint alleges facial-geometry collection and FittingBox server storage during the process; these are pleadings, not adjudicated findings.29 The Illinois suit, filed on 30 August 2022, was reported dismissed on 10 February 2023 on the basis that Dior’s conduct fell within BIPA’s healthcare exemption concerning Class I medical devices.16 The documented vendor is French rather than Israeli.16, 17

Dior states that it uses video surveillance in stores to detect security and safety incidents, shoplifting, and other unlawful activity.30 Dior is also documented using NFC authentication tags and participating in luxury-sector clienteling across boutique, web, and aftersales touchpoints.31

No public evidence identified of Dior-operated in-store facial-recognition or biometric customer tracking in Israel or elsewhere beyond the documented FittingBox virtual try-on. No public evidence identified of an Israeli-origin biometric, facial-recognition, video-analytics, or retail-surveillance vendor in Dior’s own stack.16, 17, 30

Cloud Infrastructure, Data Residency & Sovereign Cloud Participation

The available evidence identifies a third-party Salesforce environment as the setting of the 2025 client-data compromise, while PIPC describes the affected system more generally as SaaS customer-management software.9, 10, 12 PIPC does not identify the data-hosting country or an Israel routing nexus.12 Dior’s current privacy notice says it collects information through stores, customer service, Dior.com, social networks, digital applications, and events, and may centralise customer information; it does not identify Israel as a storage, processing, routing, R&D, or legal-access location.1

Kahoona’s privacy policy permits international transfers but does not name service-processing countries, cloud providers, data centres, sub-processors, or a Dior-specific processing location.23 Israeli-law governing terms and a Tel Aviv forum clause are not evidence of Israeli data residency or access.24

No public evidence identified of Dior-operated Israeli data centres, a Dior-controlled Israeli data-residency programme, participation in Project Nimbus, Israeli sovereign-cloud services, or equivalent Israeli government-cloud participation.26, 27, 1, 23

Defence, Intelligence & Security Sector Technology Relationships

No public evidence identified of a Dior relationship with defence, military, intelligence, police, or security-sector technology suppliers or customers, whether Israeli or otherwise. The public record reviewed does not establish Dior technology provision to settlements, Israeli government bodies, or occupied-territory digital infrastructure.26, 27, 18, 19

Parent/holding-level context: Aglaé, identified by Wiz as Groupe Arnault’s venture arm, participated in Wiz’s June 2021 additional US$120 million funding announcement.32 Wiz’s September 2021 announcement also lists Aglaé among investors in an additional US$250 million round that brought its then-total funding to US$350 million.33 Those figures describe round and cumulative funding, not Aglaé’s individual investment, ownership percentage, board role, or continuing holding.33, 32

Wiz’s own materials describe civilian cloud-infrastructure security, multi-cloud coverage, and risk prioritisation.33, 34 Those 2021 materials do not identify Christian Dior Couture as a customer or user or establish military, intelligence, Israeli-state, settlement or occupied-territory use involving Dior.33, 32, 34 Current customer clarification (8 September 2026): Google’s 11 March 2026 completion release lists LVMH among Wiz’s customers; it does not specify a Dior operating entity, geography, contract amount, data flow or downstream Israeli-state/security use.35 Google completed its acquisition of Wiz on 11 March 2026, and Alphabet reported Wiz’s financial results in the Google Cloud segment.36, 37 The transaction does not disclose Aglaé’s post-closing position, sale proceeds, or any continuing Arnault/Aglaé equity interest.36, 37

AI, Algorithmic & Autonomous Systems

Dior deploys AI across personalisation, virtual try-on, demand forecasting, and trend prediction, with available reporting describing dynamic customer profiles informed by browsing behaviour, purchase history, and social-media engagement.38, 39 The Kahoona deployment is the clearest documented Israel-nexus AI relationship: LVMH describes real-time predictive segmentation of anonymous or unregistered Dior-site visitors for hyper-personalised browsing.18, 19

The official materials support interaction-derived profiling of non-logged-in visitors, but do not establish legal anonymity, identified-account data transfer, biometric data, payment data, government-ID data, purchase histories, special-category data, or Israel-origin data in the Dior–Kahoona deployment.18, 19, 23 They also do not disclose retention periods, controller/processor allocation, server locations, or whether the pilot became a continuing production service.18, 19, 23

AR/AI beauty personalisation is additionally provided through Taiwan’s Perfect Corp.13, 14 No public evidence identified of autonomous systems or Dior AI deployed in a military, security, occupation, surveillance, or other rights-affecting context.13, 18, 19

Technology Ecosystem & R&D Footprint

Dior engages external technology vendors through La Maison des Startups LVMH, including Kahoona and London-based 3D/AR company Threedium.40, 41, 42 Among Dior’s documented technology collaborations, Kahoona has the clearest Israeli corporate and R&D nexus through its Tel Aviv presence; Perfect Corp, Bambuser, FittingBox, and Threedium are documented as Taiwan-, non-Israeli, France-, and UK-linked respectively.13, 16, 40, 42, 21

No public evidence identified of a Dior-operated R&D centre, innovation laboratory, engineering presence, Israeli technology acquisition, Israeli academic co-development, or relevant patent licensing in Israel. Dior’s documented Israeli footprint is commercial retail, including Tel Aviv and Jerusalem/Mamilla Mall activity with local partners or distributors, rather than technology R&D.26, 43

Civil Society Scrutiny & Regulatory History

2025 Salesforce/ShinyHunters breach. Dior was among luxury brands affected by a 2025 social-engineering campaign against Salesforce environments attributed by Google’s Threat Intelligence Group to UNC6040, an actor widely linked in reporting to ShinyHunters.9, 44 At Dior, an unauthorised party accessed client data; reporting places the intrusion on 26 January 2025, discovery on 7 May 2025, and US notifications from mid-July 2025.10, 11 The reported data categories included names, contact details, mailing addresses, dates of birth, purchase history, and in some cases government-issued ID numbers, while Dior stated that payment and bank data were not in the affected database.10, 11

PIPC’s primary enforcement record identifies Christian Dior Couture Korea Co., Ltd. and states that a customer-service employee was deceived by voice phishing into granting access to the SaaS customer-management service, exposing information relating to approximately 1.95 million people.12 PIPC found no IP access restriction, no restriction on bulk-download tooling, and no monthly inspection of relevant download/access logs; it states that Dior identified the incident on 7 May 2025 and notified affected persons on 12 May, after the 72-hour period.12 PIPC imposed a KRW 12.236 billion administrative fine, a KRW 3.6 million penalty, and publication of the disposition on 12 February 2026.12 The regulator does not name Salesforce or connect the breach to Israel.12

US litigation. Data-breach class actions connected to the Salesforce incident were reported, with at least some claims against Dior dismissed.45

BIPA biometric suit. The FittingBox-related Illinois BIPA matter was filed in August 2022 and reported dismissed in February 2023; the underlying complaint remains evidence of allegations rather than proof of adjudicated data-processing facts.16, 29

Israel-related brand scrutiny. In November 2023, Dior faced pro-Palestinian boycott calls after selecting Israeli model May Tager for a campaign; contemporaneous coverage reported that claims Dior had “replaced” Bella Hadid were inaccurate because Hadid’s Dior Makeup contract had ended in 2022.46 This was reputational brand scrutiny rather than a digital-technology matter.

No public evidence identified naming Dior in the reviewed 2025 OHCHR settlement-business database; this is a reviewed-document result, not a database-wide or universal absence finding.47 No public evidence identified in the reviewed sources of civil-society, regulatory, court, UN, or other authoritative scrutiny alleging that Dior’s Kahoona use involved Israeli-state surveillance, settlement activity, military or intelligence customers, occupied-territory processing, or an Israeli data pipeline.18, 19, 23, 12, 47

Footnotes

  1. https://www.dior.com/fr_fr/fashion/donnees-personnelles ↩ ↩2 ↩3 ↩4

  2. https://urd.lvmh.com/en/urd-2023-va_vdef.pdf ↩ ↩2

  3. https://www.dior-finance.com/pdf/d/2/1292/2025%20Christian%20Dior%20-%20Annual%20Report%20as%20of%20December%2031,%202025.pdf ↩ ↩2 ↩3

  4. https://www.dior.com/en_int/fashion/legal-terms ↩ ↩2

  5. LVMH, https://www.lvmh.com/en/publications/appointments-at-louis-vuitton-loro-piana - christian-dior-couture ↩

  6. https://www.dior.com/en_int/beauty/folder?fid=legal-terms ↩

  7. https://bdif.amf-france.org/back/api/v1/documents/2022/222C2657/4D3F3A1EA5295473C85D274C5D69DAA077270138EAE8CE5A1A491D7C9D3BD45D.pdf ↩

  8. https://bdif.amf-france.org/back/api/v1/documents/2026/2026DD1101269/5FDDDE841426CA1D5DDB06B4F9BDBFE097342104678C181B96F927477C2FE679.pdf ↩

  9. https://socradar.io/blog/salesforce-data-breach-affecting-multiple-companies/ ↩ ↩2 ↩3

  10. https://www.bleepingcomputer.com/news/security/dior-begins-sending-data-breach-notifications-to-us-customers/ ↩ ↩2 ↩3 ↩4

  11. https://www.bleepingcomputer.com/news/security/louis-vuitton-dior-and-tiffany-fined-25-million-over-data-breaches/ ↩ ↩2 ↩3

  12. https://pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS074&mCode=C020010000&nttId=11817 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9

  13. https://www.happi.com/breaking-news/perfect-corp-partners-with-parfums-christian-dior/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6

  14. https://en.wikipedia.org/wiki/Perfect_Corp ↩ ↩2

  15. https://www.pymnts.com/news/retail/2022/bambuser-collabs-with-perfect-corp-to-advance-virtual-try-on-with-christian-dior/ ↩

  16. https://www.classaction.org/news/dior-collected-illinois-residents-biometric-info-through-try-online-tool-lawsuit-says ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8

  17. https://fittingbox.com/en/glasses-virtual-try-on ↩ ↩2 ↩3 ↩4

  18. https://www.lvmh.com/en/publications/lvmh-recognizes-three-tech-partners-for-exceptional-collaborations-with-its-maisons-at-2025-lvmh-innovation-award-ceremony/ ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9

  19. https://www.lvmh.com/en/lvmh-x-vivatech-2025/maisons-x-tech-partners ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8

  20. https://www.kahoona.io/in-the-media/privacy-focused-data-generation-platform-kahoona-raises-4-5-million-seed-round-led-by-global-founders-capital ↩

  21. https://www.kahoona.io/job-openings/senior-data-scientist ↩ ↩2

  22. https://kahoona.io/ ↩

  23. https://www.kahoona.io/privacy-policy ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7

  24. https://www.kahoona.io/terms-of-use ↩ ↩2 ↩3 ↩4

  25. https://finder.startupnationcentral.org/company_page/kahoona ↩

  26. https://diorboutique-il.com/pages/about-us-1 ↩ ↩2 ↩3 ↩4 ↩5

  27. https://www.linkedin.com/company/drrr-dior-parfums-israel ↩ ↩2 ↩3 ↩4

  28. https://www.prnewswire.com/news-releases/lvmh-and-google-cloud-create-strategic-partnership-for-ai-and-cloud-based-innovation-301313307.html ↩ ↩2

  29. https://www.classaction.org/media/warmack-stillwell-v-christian-dior-inc.pdf ↩ ↩2 ↩3

  30. https://www.dior.com/en_us/fashion/personal-data ↩ ↩2

  31. https://rfid-pro.com/how-nfc-tags-work-in-dior-products/ ↩

  32. https://www.wiz.io/blog/salesforce-ventures-blackstone-and-algae-join-team-wiz ↩ ↩2 ↩3

  33. https://www.wiz.io/blog/wiz-goes-even-more-global ↩ ↩2 ↩3 ↩4

  34. https://www.wiz.io/blog/celebrating-our-series-c-zero-to-6-billion-in-18-months ↩ ↩2

  35. Google, 11 March 2026, https://www.googlecloudpresscorner.com/2026-03-11-Google-Completes-Acquisition-of-Wiz ↩

  36. https://blog.google/innovation-and-ai/infrastructure-and-cloud/google-cloud/wiz-acquisition/ ↩ ↩2

  37. https://www.sec.gov/Archives/edgar/data/1652044/000165204426000048/goog-20260331.htm ↩ ↩2

  38. https://digitaldefynd.com/IQ/christian-dior-using-ai-case-study/ ↩

  39. https://www.klover.ai/dior-ai-strategy-analysis-of-dominance-in-luxury-fashion-ai/ ↩

  40. https://www.ainvest.com/news/lvmh-ai-driven-luxury-innovation-ecosystem-strategic-startups-key-dominance-tech-enabled-luxury-2506/ ↩ ↩2

  41. https://www.prnewswire.com/news-releases/privacy-focused-data-generation-platform-kahoona-raises-4-5-million-seed-round-led-by-global-founders-capital-301536593.html ↩

  42. https://www.businesswire.com/news/home/20220114005058/en/Threedium-Joins-La-Maison-des-Startups-LVMH ↩ ↩2

  43. https://www.israelhayom.com/2020/06/12/dior-set-to-launch-flagship-boutique-in-jerusalems-mamilla-mall/ ↩

  44. https://www.computerweekly.com/feature/ShinyHunters-Salesforce-cyber-attacks-explained-What-you-need-to-know ↩

  45. https://www.thefashionlaw.com/dior-dodges-data-breach-lawsuits-tied-to-salesforce-hack/ ↩

  46. https://www.haaretz.com/israel-news/2023-11-08/ty-article/.premium/pro-palestinian-activists-call-for-boycott-after-israeli-model-is-chosen-for-dior-campaign/0000018b-af36-dea2-a9bf-ffbe3be30000 ↩

  47. https://www.ohchr.org/en/press-releases/2025/09/un-report-identifies-businesses-involved-settlement-enterprise-occupied-palestinian ↩ ↩2