HomeIntelligenceBrief
BREACH BRIEF 🟠 High Advisory

EU Regulator Fines Google €403 Million for Unlawful Location‑Data Processing

Ireland’s Data Protection Commission has fined Google over €403 million for retaining and processing location data without adequate transparency or lawful basis. The enforcement illustrates why robust privacy‑control evidence is essential for audit readiness under GDPR.

Verisq™ Intelligence · 📅 September 22, 2026 · 📰 therecord.media
🟠
Severity
High
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
therecord.media

EU Data Regulator Fines Google Over €403 Million for Location‑Data Violations

What Happened – Ireland’s Data Protection Commission imposed a fine of more than €403 million (≈ $462 million) on Google for unlawful processing of users’ location data across its web‑and‑app activity, location‑history, and location‑accuracy services. The regulator concluded a multi‑year inquiry that found Google retained location data longer than necessary and failed to provide transparent, fair processing notices. Google has been ordered to remediate its practices within six months.

Why It Matters for Trust & Control Assurance

  • The case highlights the risk of inadequate data‑retention and purpose‑limitation controls, a core control objective that continuous‑monitoring programs must evidence.
  • It underscores the need for transparent consent and accountability mechanisms that can be demonstrated to regulators on demand.
  • A robust privacy‑control framework (e.g., CookiePLUS) provides the audit‑ready evidence required to prove compliance with GDPR‑style obligations.

Who Is Affected – Large‑scale digital platforms, advertising networks, and any organization that processes location or other sensitive personal data under GDPR or similar privacy regimes.

Recommended Actions

  • Conduct a gap analysis of your location‑data handling against GDPR’s transparency, purpose limitation, and retention requirements.
  • Deploy a consent‑management solution that captures granular user consent and logs consent changes for auditability.
  • Update data‑retention schedules, purge historic location data beyond the lawful period, and document the changes in a Data Processing Register.
  • Prepare a remediation plan and evidence package for supervisory review. Source: The Record

Technical Notes – The regulator focused on three Google services: web‑and‑app activity, location history, and location accuracy. The alleged violations stem from excessive retention of precise location traces collected since May 2018, without clear lawful basis or user notice. No specific vulnerability or exploit was cited. Source: The Record

📰 Original Source
https://therecord.media/google-europe-location-data-fine

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →