www.securityweek.com 21 Sept 2026, 17:19 UTC

Google Fined €403 Million Over Unlawful Location Data Practices

Google Fined €403 Million Over Unlawful Location Data Practices
CyberSIXT Evidence Panel Source marked as original reporting

GOOGLE has been fined €403 million ($463 million) by Ireland’s Data Protection Commission (DPC) for breaching the EU’s General Data Protection Regulation over its handling of users’ location data. The regulator found that Google did not process location information lawfully or fairly in Web & App Activity, which records browsing and search history, and Location History, which maps places visited using mobile phones. It also found problems with the legality, fairness and transparency of processing in Android’s Location Accuracy feature.

The DPC, which leads regulation of Google in the EU because the company’s European headquarters are in Dublin, examined practices between the GDPR’s introduction in 2018 and February 2020. The investigation opened six years ago. Deputy Commissioner Graham Doyle said location data can provide useful services but can also reveal significant and inherently private information about individuals.

Google said the case concerned historical policies that had since been updated, adding that it had significantly changed its practices from 2019 and introduced tools to make location-data management simpler. The fine is the fourth largest issued by the Irish watchdog, which said three other investigations involving Google remain ongoing.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline