Google fined €403 million over location data privacy violations
Ireland's Data Protection Commission fined Google €403 million for multiple GDPR violations related to processing users' location data. The investigation focused on three Google features active from May 2018 through February 2020: Web and App Activity, Location History, and Location Accuracy. The DPC found that Google processed location data without meeting GDPR requirements, failed transparency obligations, and retained data longer than necessary. Google has since updated its policies and implemented improved data management controls. The DPC requires Google to comply within six months. No active exploit or vulnerability is reported.
AI Analysis
Technical Summary
The Irish Data Protection Commission investigated Google's processing of location data through three features: Web and App Activity, Location History, and Location Accuracy, during the GDPR application period from May 25, 2018, to February 4, 2020. The DPC found that Google failed to meet GDPR transparency and data retention requirements, processing location data without proper user consent and retaining it longer than necessary. This resulted in a €403 million fine. Google stated that it has updated its practices since 2019, including tools for managing location data and automatic deletion of older data. The DPC demands compliance within six months but has not published the full decision yet.
Potential Impact
The impact involves violations of GDPR privacy regulations, specifically regarding user consent, transparency, and data retention of location information. Users potentially lost control over their personal location data, which could have been used for targeted advertising or profiling without adequate awareness or consent. There is no indication of a technical security vulnerability or exploitation; the issue is regulatory non-compliance with privacy laws.
Mitigation Recommendations
Google has updated its location data processing policies and implemented mechanisms for easier user control and automatic data deletion. The DPC requires Google to bring its practices into compliance within six months. Organizations and users should review and manage location data settings accordingly. No technical patch or security fix is applicable as this is a privacy compliance issue.
Google fined €403 million over location data privacy violations
Description
Ireland's Data Protection Commission fined Google €403 million for multiple GDPR violations related to processing users' location data. The investigation focused on three Google features active from May 2018 through February 2020: Web and App Activity, Location History, and Location Accuracy. The DPC found that Google processed location data without meeting GDPR requirements, failed transparency obligations, and retained data longer than necessary. Google has since updated its policies and implemented improved data management controls. The DPC requires Google to comply within six months. No active exploit or vulnerability is reported.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Irish Data Protection Commission investigated Google's processing of location data through three features: Web and App Activity, Location History, and Location Accuracy, during the GDPR application period from May 25, 2018, to February 4, 2020. The DPC found that Google failed to meet GDPR transparency and data retention requirements, processing location data without proper user consent and retaining it longer than necessary. This resulted in a €403 million fine. Google stated that it has updated its practices since 2019, including tools for managing location data and automatic deletion of older data. The DPC demands compliance within six months but has not published the full decision yet.
Potential Impact
The impact involves violations of GDPR privacy regulations, specifically regarding user consent, transparency, and data retention of location information. Users potentially lost control over their personal location data, which could have been used for targeted advertising or profiling without adequate awareness or consent. There is no indication of a technical security vulnerability or exploitation; the issue is regulatory non-compliance with privacy laws.
Defensive Guidance
Google has updated its location data processing policies and implemented mechanisms for easier user control and automatic data deletion. The DPC requires Google to bring its practices into compliance within six months. Organizations and users should review and manage location data settings accordingly. No technical patch or security fix is applicable as this is a privacy compliance issue.
Technical Details
- Classification
- {"confidence":0.75,"severitySource":"default","classifier":"rss-v2"}
Threat ID: 6ab1515f55bf5e2cf51a7485
Added to database: 09/21/2026, 15:46:39 UTC
Last enriched: 09/21/2026, 15:46:48 UTC
Last updated: 09/21/2026, 19:46:38 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.