HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

Google fined €403 million for GDPR location‑data privacy violations

Ireland’s Data Protection Commission fined Google €403 million after finding that the company processed users’ location data without adequate transparency, lawful basis, or proper retention limits. The case underscores the importance of documented privacy controls for audit readiness.

Verisq™ Intelligence · 📅 September 22, 2026 · 📰 bleepingcomputer.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
bleepingcomputer.com

Google fined €403 million for GDPR location‑data privacy violations

What Happened – Ireland’s Data Protection Commission imposed a €403 million fine on Google for breaching GDPR requirements when processing users’ location data through Web & App Activity, Location History, and Location Accuracy features. The regulator found that Google failed to provide transparent notices, lacked a valid legal basis for the processing, and retained the data longer than necessary.

Why It Matters for Trust & Control Assurance

  • The incident highlights the need for continuous evidence that privacy‑related controls (consent capture, purpose limitation, data‑retention policies) are operating as intended.
  • A robust control‑assurance program can surface gaps in privacy governance before regulators identify them, providing a defensible audit trail.
  • Verisq’s CookiePLUS Privacy capability helps organizations demonstrate compliance with consent and data‑retention controls across multiple frameworks.

Who Is Affected – Large‑scale SaaS providers, digital advertising platforms, and any organization that processes location or other personal data under GDPR.

Recommended Actions

  • Review and document the legal basis for all location‑data processing activities.
  • Implement automated consent‑capture and granular user‑controlled deletion mechanisms.
  • Align data‑retention schedules with the “purpose‑limitation” principle and retain evidence of compliance for audit readiness. Source: BleepingComputer

Technical Notes – The DPC examined three Google features active between May 2018 and February 2020: (1) Web & App Activity, (2) Location History (opt‑in tracking), and (3) Location Accuracy (device‑level positioning). Violations stemmed from opaque processing notices and excessive retention of location timestamps. Source: same as above

📰 Original Source
https://www.bleepingcomputer.com/news/security/google-fined-403-million-over-location-data-privacy-violations/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →