HomeIntelligenceBrief
BREACH BRIEF 🟠 High Advisory

Google fined €403 million by Irish regulator for unlawful location‑data processing

Ireland’s Data Protection Commission fined Google €403 million for processing location data without a lawful basis and lacking transparency. The case underscores the importance of documented consent and retention controls for GDPR audit readiness.

Verisq™ Intelligence · 📅 September 22, 2026 · 📰 helpnetsecurity.com
🟠
Severity
High
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
helpnetsecurity.com

Google fined €403 million by Irish regulator for unlawful location‑data processing

What Happened – Ireland’s Data Protection Commission imposed a €403 million fine on Google for processing users’ location data through Web & App Activity, Location History, and Location Accuracy without a lawful basis, and for failing to provide transparent information or limit retention. The regulator ordered Google to bring the processing into compliance within six months.

Why It Matters for Trust & Control Assurance

  • Demonstrates the audit‑ready evidence gap when organizations cannot prove lawful, fair, and transparent data‑processing practices.
  • Highlights the need for continuous privacy‑control monitoring and documented consent mechanisms to satisfy accountability obligations.
  • Shows that a single control—transparent data‑governance—maps to many frameworks (GDPR, NIST CSF, ISO 27001) and is a litmus test for a trustworthy data‑handling posture.

Who Is Affected – Global online‑service providers, advertising platforms, and any organization that processes location or other personal data at scale.

Recommended Actions

  • Conduct a privacy‑impact assessment of all location‑tracking features and verify lawful bases.
  • Implement a consent‑capture and management solution that logs user choices and supports easy withdrawal.
  • Align data‑retention schedules with the principle of storage limitation and document the process for auditors.

Technical Notes – The DPC’s investigation covered Google’s handling of location data from 25 May 2018 to 4 Feb 2020. Violations centered on lawfulness, fairness, transparency, and excessive retention, not on a technical vulnerability. Source: Help Net Security

📰 Original Source
https://www.helpnetsecurity.com/2026/09/21/ireland-google-users-location-data-processing-fine/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →