[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fQ3M5mdp74KZTiFIULyuPV6EC-igLyG5CALswZjvYIVk":3},{"article":4,"iocs":42},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":26},"91692901-3579-4721-9b4e-77debf8df90b","Google Hit With $463 Million Fine for EU Location Data Rule Breach","google-hit-with-463-million-fine-for-eu-location-data-rule-breach-80aeff","Google has been fined 403 million euros ($463 million) for breaching the European Union’s strict privacy rules because it mishandled users’ location data. The post Google Hit With $463 Million Fine for EU Location Data Rule Breach appeared first on SecurityWeek.","Google has been fined 403 million euros ($463 million) by Ireland's Data Protection Commission for violating EU privacy rules regarding the processing of user location data. The investigation found Google did not lawfully or fairly process location data in its Web & App Activity and Location History services, nor in its Android Location Accuracy feature. This marks the fourth-largest privacy fine issued by the Irish watchdog.","Google fined $463 million for mishandling EU user location data.","Google has been fined 403 million euros ($463 million) for breaching the European Union’s strict privacy rules because it mishandled users’ location data, the bloc’s data privacy watchdog said Monday. Ireland’s Data Protection Commission said its investigation found Google did not lawfully or fairly process location data in users’ Web & App Activity, a Google setting that tracks browsing and search history, and in their Location History, a service that maps places they’ve been with their mobile phones. Regulators also found the company failed to be lawful, fair and transparent when it processed personal data in its Location Accuracy feature in the Android mobile operating system. Ireland is the lead regulator for Google in the 27-nation EU because the U.S. tech giant’s European headquarters is based in Dublin. The investigation, which opened six years ago, examined how Google applied the EU privacy rule book, known as the General Data Protection Regulation, from the time it took effect in 2018 until February 2020. “This case centers around historical policies that have since been updated,” Google said in a statement. “From 2019 onwards, we’ve significantly evolved our practices and launched robust tools that make managing location data simple.”Advertisement. Scroll to continue reading. Regulators said that location data is a type of personal data that’s collected by Google and can be used to infer someone’s location. “Location data can bring both benefits and harms to individuals,” Deputy Commissioner Graham Doyle said. “It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private.” It’s the fourth biggest EU privacy fine issued by the Irish watchdog, which has previously handed out bigger fines to TikTok and Meta, including a 1.2 billion euro fine for Meta. The regulator said it still has three other ongoing privacy investigations involving Google. Related: Dior, Louis Vuitton, Tiffany Fined $25 Million in South Korea After Data Breaches Related: TikTok Reaches $400 Million Settlement With US Justice Department Over Children’s Privacy Related: Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts Written By Associated Press Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Associated Press Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI DevelopmentNew Warnings About the Risks of AI to Humanity Revive a Long-Running DebateAnthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch UpUsers in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic SaysAnthropic Researcher Resigns With Warning About the Dangers of AI DevelopmentMeta Launches Personal AI Agent, Muse, Emphasizes Safety and PrivacyParty’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin Theft Latest News Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ StealerCISO Conversations: Noopur Davis – The Accidental Global CISO at ComcastDragos Completes NetRise and runZero Acquisitions Following Accenture DealRatHat Android Trojan Uses AI for AutomationRust Team Members and Popular Crate Owners Targeted via Video CallsCrowdSec Confirms Source Code Stolen in Supply Chain AttackColorado Water Utilities Hit by Cyberattacks Targeting OT SystemsOrganizations Warned of 3 Exploited Linux Kernel Vulnerabilities Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveVeritas Capital has appointed Joel Fulton as Chief Information Security Officer.incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.Ruben D. Chacon has joined ADM as Vice President and Global CISO.More People On The MoveExpert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, \"data\" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fgoogle-hit-with-463-million-fine-for-eu-location-data-rule-breach\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2024\u002F07\u002FGoogle.jpeg","2026-09-21T17:19:53+00:00","2026-09-21T18:00:44.057444+00:00",7,[18],{"name":19,"type":20},"Google","vendor","d95477d7-eb04-4fad-a2dc-be1428040ce7",{"id":21,"icon":23,"name":24,"slug":25},null,"Privacy Fines","privacy-fines",[27,32,37],{"category":28},{"id":29,"icon":23,"name":30,"slug":31},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":33},{"id":34,"icon":23,"name":35,"slug":36},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":38},{"id":39,"icon":23,"name":40,"slug":41},"c5c77cdb-f7d7-4990-9436-c81dcbff1163","Policy","policy",[]]