HomeIntelligenceBrief
BREACH BRIEF 🟠 High Advisory

Google Fined €403 Million for GDPR Violations Over Location‑Data Practices

Ireland’s DPC fined Google €403 million for unlawful collection, retention, and lack of transparency around location data in Web & App Activity, Location History, and Android’s Location Accuracy. The enforcement underscores the audit risk of missing privacy controls and the need for continuous evidence of lawful processing.

Verisq™ Intelligence · 📅 September 22, 2026 · 📰 securityaffairs.com
🟠
Severity
High
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
securityaffairs.com

Google Fined €403 Million for GDPR Violations Over Location‑Data Practices

What Happened – Ireland’s Data Protection Commission (DPC) imposed a €403 million fine on Google for unlawful processing of location data across three features: Web & App Activity, Location History, and Location Accuracy. The regulator found breaches of GDPR principles of lawfulness, fairness, transparency, and data‑retention, affecting both signed‑in users and anyone running Android.

Why It Matters for Trust & Control Assurance

  • Demonstrates the audit risk when privacy‑by‑design and clear data‑retention policies are missing – a core control‑assurance scenario.
  • Highlights the need for continuous evidence of lawful processing (consent records, retention schedules, transparency notices) to satisfy regulators and auditors.
  • Shows that a single data‑handling flaw can trigger multi‑million penalties, underscoring the value of a unified privacy‑control framework.

Who Is Affected – Global technology providers, mobile‑OS vendors, and any organization that processes location or other high‑risk personal data.

Recommended Actions

  • Conduct a privacy impact assessment (PIA) of all location‑data features.
  • Align data‑collection, consent, and retention practices with GDPR Art. 5‑6 requirements.
  • Implement continuous monitoring of consent logs and retention schedules; retain defensible audit evidence.
  • Update user‑facing privacy notices to be clear, specific, and easily accessible.

Source: Security Affairs

Technical Notes – The DPC examined Google’s processing from 25 May 2018 (GDPR start) to 4 Feb 2020. Violations spanned collection, storage, and disclosure of location data, including the Android‑level “Location Accuracy” feature that operates without a signed‑in account. No specific CVE or exploit was involved. Source: same

📰 Original Source
https://securityaffairs.com/199494/laws-and-regulations/google-fined-e403-million-over-location-data-practices.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →