Google Hit with €403m GDPR Fine Over Location Data Practices
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Vendors and products
- Reported by
- 1 outlet
Google has been fined €403m ($460m) by the Irish Data Protection Commission (DPC) for violating GDPR rules regarding to its processing of users’ location data.
Following a lengthy inquiry that started in February 2020, the Commission concluded that the tech giant’s unlawful practices in this area meant that individuals using services such as Google Maps and location accuracy features on Android devices could have been unaware that their location was being used to influence them with ads or to infer their interests. It found that this practice could result in a loss of control over their personal data.
In addition, the firm was found to have retained users’ location data for longer than necessary, aggravating this loss of control.
The investigation focused on Google’s processing of location data in three specific features – Web & App Activity, Location History and Location Accuracy between May 25, 2018, when the GDPR came into force, through to February 4, 2020.
Google was found to have violated the GDPR in four respects:
- The lawfulness and fairness of its processing of location data in Web & App Activity and Location History
- Its accountability obligations under the GDPR by failing to be able to demonstrate compliance with the lawfulness, fairness and transparency principle regarding its processing of personal data in Location Accuracy
- Its transparency obligations in respect of all three features referred to above; and
- Its retention of location data in Web & App Activity and Location History.
Commenting on the fine, Deputy Commissioner of the DPC, Graham Doyle, noted the highly sensitive nature of location data and the potentially serious implications of individuals’ location being inferred.
“Location data can bring both benefits and harms to individuals. It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private,” he said.
The DPC added that the company must also ensure it brings its processing approach into compliance within six months.
Responding to the judgement, a Google spokesperson said: “This case centers around historical policies that have since been updated. From 2019 onwards, we’ve significantly evolved our practices and launched robust tools that make managing location data simple.”
In November 2022, Google agreed to pay $391.5m to settle a lawsuit in the US that alleged the firm harvest location data without the knowledge of most consumers.
Image credit: credit: Stockinq / Shutterstock.com
Reproduced in full under licence from Infosecurity Magazine. © Infosecurity Magazine.
Coverage
One outlet has carried this so far.
2026-09-21 15:00 UTC
Related stories
- DORA Year Two: Can Your SOC Actually See the Attack?
The Hacker News · 2026-09-22
- Google Hit With $463 Million Fine for EU Location Data Rule Breach
SecurityWeek · 2026-09-21
- Google Fined €403 Million Over GDPR Violations Tied to Location Data
The Hacker News · 2026-09-21
- Google fined €403 million over location data privacy violations
BleepingComputer · 2026-09-21
- Irish data protection watchdog fines Google €403M over GDPR breaches
Hacker News · 2026-09-21