Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Google Fined €403 Million for Massively Infringing Upon EU's GDPR, a Critical Examination of the Commission's Findings on Location Data Practices


Google has been fined €403 million by Ireland's Data Protection Commission for its massive infringement of the General Data Protection Regulation (GDPR) in its location data practices. The investigation, which spanned six years, found that Google had failed to meet the GDPR requirements for lawfulness, fairness, and transparency in its handling of location data.

  • Google has been fined €403 million by Ireland's Data Protection Commission (DPC) for violating the General Data Protection Regulation (GDPR) in its location data practices.
  • The investigation found that Google's processing of location data in three specific features (Web & App Activity, Location History, and Location Accuracy) failed to meet GDPR requirements for lawfulness, fairness, and transparency.
  • The DPC discovered that Google had failed to provide users with sufficient transparency and control over their location data, and had kept location data for longer than allowed.
  • The penalty is the fourth-largest EU privacy fine issued by Ireland's data protection regulator and sends a clear message to companies that their location data practices are strictly regulated.
  • The investigation highlights the importance of effective regulation in the EU and demonstrates that regulators are taking the GDPR seriously.
  • The €403 million penalty is a significant blow to Google's advertising business, which relies heavily on location and behavioral data.



  • The recent ruling by Ireland's Data Protection Commission (DPC) has set a significant precedent in the European Union's (EU) efforts to regulate the processing of personal data. In a stern warning to tech giants, Google has been fined a whopping €403 million for its massive infringement of the General Data Protection Regulation (GDPR). This monumental penalty is the fourth-largest EU privacy fine issued by Ireland's data protection regulator, and it sends a clear message to companies that their location data practices are not only scrutinized but also strictly regulated.

    The DPC's investigation into Google's location data practices spanned a period of six years, from February 2020 to 2020, and focused on the company's processing of location data in three specific features: Web & App Activity, Location History, and Location Accuracy. The investigation revealed that Google had failed to meet the GDPR requirements for lawfulness, fairness, and transparency in its handling of location data.

    Web & App Activity, which tracks a signed-in user's activities across Google's services, sites, and apps, was found to be a critical feature in the investigation. The DPC discovered that Google's processing of location data in this feature did not meet the GDPR requirements, as it failed to provide users with sufficient transparency and control over their location data. Similarly, Location History, which follows a device's movements over time and builds a private Timeline map of everywhere the phone has been, was also found to be in violation of the GDPR.

    Location Accuracy, a feature baked into Android itself, was found to be even more problematic. The DPC discovered that Google could not demonstrate that its Location Accuracy feature complied with the GDPR requirements for lawfulness, fairness, and transparency. This is particularly concerning, as Location Accuracy applies to anyone running the OS, regardless of whether they have ever signed into a Google account.

    The DPC's investigation also revealed that Google had failed to keep location data for the required period, which is a critical aspect of the GDPR. The commission found that Google had kept location data for longer than allowed, which made the problem worse.

    In a statement, Deputy Commissioner Graham Doyle emphasized the importance of transparency in location data processing. He noted that "location data is a type of personal data which is processed by way of location tracking, and includes data collected or processed by Google, which by itself or in conjunction with other information an individual's location can be inferred." Doyle also highlighted the potential risks of location data, stating that "there's no version of location tracking that's neutral by default."

    The €403 million penalty is a significant blow to Google's advertising business, which relies heavily on location and behavioral data. The DPC's findings demonstrate that companies must prioritize transparency and user control when processing location data, or face severe penalties.

    The investigation also highlights the importance of effective regulation in the EU. The GDPR provides strong protection for personal data across the EEA and requires companies to process this data in a lawful, fair, and transparent way. The DPC's findings demonstrate that regulators are taking the GDPR seriously and will not hesitate to take action against companies that fail to comply.

    In conclusion, Google's €403 million fine is a critical reminder of the importance of adhering to EU data protection regulations. The DPC's findings demonstrate that companies must prioritize transparency and user control when processing location data, and that regulators will take action against companies that fail to comply.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Google-Fined-403-Million-for-Massively-Infringing-Upon-EUs-GDPR-a-Critical-Examination-of-the-Commissions-Findings-on-Location-Data-Practices-ehn.shtml

  • https://securityaffairs.com/199494/laws-and-regulations/google-fined-e403-million-over-location-data-practices.html


  • Published: Mon Sep 21 17:13:54 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us