www.infosecurity-magazine.com 21 Sept 2026, 15:00 UTC

Google Fined €403m for Mishandling Users’ Location Data

Google Fined €403m for Mishandling Users’ Location Data
CyberSIXT Evidence Panel Source marked as original reporting

GOOGLE has been fined €403m by Ireland’s Data Protection Commission (DPC) for breaching GDPR requirements over its processing of users’ location data. The inquiry, launched in February 2020, examined Web & App Activity, Location History and Location Accuracy between 25 May 2018 and 4 February 2020.

The DPC said people using services including Google Maps and Android location-accuracy features may not have understood that their location data could be used to influence advertising or infer their interests, potentially reducing their control over their personal data.

The regulator identified four areas of non-compliance: unlawful and unfair processing in Web & App Activity and Location History; failure to demonstrate compliance with lawfulness, fairness and transparency requirements for Location Accuracy; inadequate transparency across all three features; and retaining location data for longer than necessary in Web & App Activity and Location History. The DPC described location data as highly sensitive and said Google must bring its processing into compliance within six months.

Google said the case concerned historical policies that had since been updated, adding that it had significantly changed its practices from 2019 onwards and introduced tools to make location-data management simpler. The article also notes that Google agreed to pay $391.5m in November 2022 to settle a US lawsuit alleging that it collected location data without most consumers’ knowledge.

View full article

Article by CyberSIXT