[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fSx53mHZLrxE67_gkPvk_F-SvSPPP-KADTpg-sQ1KPmo":3},{"article":4,"iocs":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"c9f92569-10ba-431b-a1f9-fd7131dfc09e","Google Fined €403 Million Over GDPR Violations Tied to Location Data","google-fined-403-million-over-gdpr-violations-tied-to-location-data-d1a929","Google has been fined €403 million for breaking the EU's data protection law, the GDPR, in the way three of its features handled people's location data from May 2018 to February 2020. Ireland's Data Protection Commission (DPC), Google's lead regulator in the EU, also ordered the company to make its processing comply with the law within 6 months. The DPC has not said publicly which","Google has been fined €403 million by Ireland's Data Protection Commission (DPC) for violating the EU's GDPR concerning the handling of location data across three features: Web & App Activity, Location History, and Location Accuracy. The DPC found breaches in lawful processing, transparency, and data retention rules. Google stated that the issues stem from historical policies that have since been updated.","Google fined €403M for GDPR violations regarding location data handling.","Google Fined €403 Million Over GDPR Violations Tied to Location Data Swati KhandelwalSep 21, 2026Data Privacy \u002F Regulatory Compliance Google has been fined €403 million for breaking the EU's data protection law, the GDPR, in the way three of its features handled people's location data from May 2018 to February 2020. Ireland's Data Protection Commission (DPC), Google's lead regulator in the EU, also ordered the company to make its processing comply with the law within 6 months. The DPC has not said publicly which processing the order covers, and it says its full decision will be published later. The three features are Web & App Activity, Location History and Location Accuracy. Web & App Activity is a Google account setting that, when turned on, lets Google process data about a user's activity on its sites and apps. That data can include location. Location History, which users must opt in to, keeps track of where they go with their signed-in mobile devices, even when they are not using a Google service. For both cases, the DPC found that Google breached the GDPR's rules on lawful and fair processing and on transparency, and that it retained location data longer than necessary. Location Accuracy is an Android feature that works out a device's location more precisely than GPS alone, and it is available to Android users with or without a Google account. The DPC's findings for this feature are narrower. Google broke the transparency rules and the GDPR's accountability rules because it could not demonstrate that this processing was lawful, fair and transparent. DPC Deputy Commissioner Graham Doyle said these failures meant people could have been unaware that their location was being used, for example, to influence them with ads or to infer their interests. They could also lose control of their personal data, and keeping it for so long made that worse. At €403 million, the fine is the fourth-largest the DPC has issued. It cannot be collected yet, because a DPC fine becomes payable only after an Irish court confirms it. Google can appeal to the High Court within 28 days of receiving formal notice of the decision. In a statement reported by the Associated Press, Google said the case \"centers around historical policies that have since been updated\" and that it has changed its practices significantly since 2019. In May 2019, during the period the DPC examined, Google announced auto-delete controls for Location History and Web & App Activity. They let users have that data deleted automatically after 3 or 18 months. In June 2020, Google made 18-month auto-delete the default for Web & App Activity on new accounts and for anyone turning on Location History for the first time. In December 2023, Google announced that Timeline, the Google Maps feature that shows Location History on a map, would keep its data on users' devices. Auto-delete would also default to 3 months for anyone turning on Location History for the first time. The DPC has not publicly said whether these changes are sufficient to meet its order. The DPC opened its inquiry in February 2020 after complaints from European consumer groups, including BEUC, the European Consumer Organization. BEUC's member groups had filed the complaints with national data protection authorities in November 2018. The period the DPC examined ends on 4 February 2020, the day it announced the inquiry. The decision came more than 6.5 years after the inquiry opened. In comments reported by NewsIreland.EU, BEUC director general Agustín Reyna welcomed it but criticized how long it took. \"Late enforcement can be as harmful as no enforcement at all,\" he said. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Android, data privacy, Google, Regulatory Compliance ⚡ Top Stories This Week Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It. How to Evaluate a Unified Security Platform Using a One-Incident Test Stop Trying to Control AI Behavior. Control What AI Can Reach ⭐ Featured Resources Validation Summit ’26: See How Pen Testing, Exposure Validation and BAS Work Together Red Teams: Learn How Attack Path Chaining Changes Automated Security Testing Turn Threat Intelligence Into Verified Risk With Threat-Led Penetration Testing Deploy Browser Security Monitoring in Minutes With a Single Header","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fgoogle-fined-403-million-over-gdpr.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEhrjOPn27sYW7sjjV6-SlFPjlnnAtZ2bVGvrJRbbussed8ddYCwrRnmyIBKOsJy9p3QGdwzMuxmxhtyNvyPQD9u53V0T84o-Pi1Euo1SPlHX9DiaFzVby2cKpyfdma7mA0b4F1gqDCvjWBrk3n916K6Su1Y1TaJcOKXHsuzNn0cxOmVzlUK1NIjPtElIXM\u002Fs1600\u002Fgoogle-location.jpg","2026-09-21T16:57:31+00:00","2026-09-21T20:00:30.045883+00:00",7,[18,21],{"name":19,"type":20},"Google","vendor",{"name":22,"type":23},"Android","product","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":24,"icon":26,"name":27,"slug":28},null,"Policy","policy",[30,35,40,45],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":36},{"id":37,"icon":26,"name":38,"slug":39},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":41},{"id":42,"icon":26,"name":43,"slug":44},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",{"category":46},{"id":47,"icon":26,"name":48,"slug":49},"d95477d7-eb04-4fad-a2dc-be1428040ce7","Privacy Fines","privacy-fines",[]]