BleepingComputer 🔐 Cybersecurity 👁 0 📖 2 min read

Google fined €403 million over location data privacy violations

Ireland's Data Protection Commission (DPC) has fined Google €403 million ($463M) for multiple GDPR violations related to processing users' location data. [...]

Google fined €403 million over location data privacy violations

  • September 21, 2026
  • 11:41 AM

Google fined €403 million over location data privacy violations

Ireland’s Data Protection Commission (DPC) has fined Google €403 million ($463M) for multiple GDPR violations related to processing users’ location data.

The agency launched an investigation in February 2020 after receiving multiple complaints from consumer rights organizations. It examined three Google features that were active during the GDPR application period from May 25, 2018, through February 4, 2020.

The features cover permissions that allowed Google to process users’ web and app activity, location history, and location accuracy data:

  • Web and App Activity – A setting for Google Account holders that allows Google to process activity across its services, potentially including browsing history, search history, and location data.
  • Location History – An opt-in service that tracks users carrying compatible mobile devices. It can infer visited places, activities, and routes, and displays this information through a private Google Maps Timeline, even when the user is not actively using a Google service.
  • Location Accuracy – An Android feature that helps a device determine its position more accurately than GPS alone. It is available regardless of whether the user has a Google Account.

The DPC found that Google processed location data through Web & App Activity and Location History without meeting the GDPR’s requirements. At the same time, the company failed to demonstrate compliance with GDPR principles when processing personal data through Location Accuracy.

The Irish authority alleges that Google failed to meet transparency obligations for all three features and retained location data collected through Web & App Activity and Location History longer than necessary.

“[...] individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data,” stated Deputy Commissioner Graham Doyle.

“The retention of users’ location data for longer than necessary aggravated this loss of control.”

For these failures, the DPC has imposed administrative fines totaling €403 million and demands that Google bring its user data processing into compliance within the next six months.

The DPC has not published its full decision yet, but promised to do so in the future.

In a statement for BleepingComputer, Google said that it has updated its practices and policies, and implemented a mechanism for easy location data management.

“This case centers around historical policies that have since been updated. From 2019 onwards, we've significantly evolved our practices and launched robust tools that make managing location data simple,” a Google spokesperson said.

Over the years, the company has added controls that let users define a specific timeline for automatically deleting data in their account. Google Maps Timeline information is now stored on the device and automatically removes data older than three months.

Additionally, Google says that it does not save precise device location in Web & App Activity, but an estimated general area.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat
📰 Read the original article on BleepingComputer

Originally published by BleepingComputer. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.