Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Google Fined €403M for GDPR Breaches in Location Data

Google Fined €403M for GDPR Breaches in Location Data

Posted on September 21, 2026 By CWS

Google has been penalized with a €403 million fine for contravening the European Union’s General Data Protection Regulation (GDPR) through the management of location data across three specific features from May 2018 to February 2020.

The penalty, imposed by Ireland’s Data Protection Commission (DPC), which serves as Google’s primary regulatory body in the EU, mandates the tech giant to align its processing practices with GDPR requirements within six months. Although the DPC has not publicly disclosed the specific processing practices under scrutiny, a comprehensive decision is anticipated to be released subsequently.

Impact of Features on User Privacy

The features implicated in the violations are Web & App Activity, Location History, and Location Accuracy. Web & App Activity, a Google account setting, enables the tracking of user activity across Google’s platforms, potentially including location data. Location History, requiring user consent, logs users’ movements via their mobile devices, regardless of active Google service usage.

The DPC concluded that Google breached GDPR statutes regarding lawful processing, fairness, and transparency and retained location data beyond necessary limits. Location Accuracy, an Android capability, determines device location with greater precision than GPS, applicable to Android users irrespective of Google account status. However, the DPC’s findings on this feature were less extensive.

Regulatory Concerns and Accountability

The DPC’s investigation revealed Google’s failure to comply with transparency and accountability obligations under the GDPR. Deputy Commissioner Graham Doyle indicated that this lack of compliance potentially led to users being unaware of their data being utilized for targeted advertising or profiling, diminishing their data control and exacerbating risks from prolonged data retention.

Ranked as the fourth-largest fine administered by the DPC, the €403 million penalty is pending collection until an Irish court upholds it. Google retains the right to appeal to the High Court within a 28-day window following the receipt of formal notification.

Google’s Response and Policy Updates

Google, in a statement to the Associated Press, emphasized that the case pertains to outdated policies, which have undergone significant revisions since 2019. Notably, in May 2019, Google introduced auto-delete controls for Location History and Web & App Activity, allowing users to automatically erase data after 3 or 18 months. By June 2020, the auto-delete option became default for new accounts and users activating Location History.

In December 2023, Google announced that its Timeline feature in Google Maps would store Location History on user devices, with auto-deletion defaulting to 3 months for new users. The DPC has yet to publicly determine if these measures sufficiently address its directives.

The DPC’s inquiry commenced in February 2020 following complaints from European consumer groups, including the BEUC. Although the investigation’s timeframe concluded on February 4, 2020, the decision was reached over six years later. BEUC’s director general, Agustín Reyna, welcomed the decision but highlighted the detrimental effect of delayed enforcement, as reported by NewsIreland.EU.

The Hacker News Tags:data privacy, DPC, GDPR, Google, Ireland, Location Accuracy, location data, location history, regulatory compliance, Web & App Activity

Post navigation

Previous Post: AWS Swiftly Quarantines Exposed IAM Keys on GitHub
Next Post: Massive Data Loss in 103 Seconds by AI Coding Agent

Related Posts

Hackers Exploit SharePoint Zero-Day Since July 7 to Steal Keys, Maintain Persistent Access Hackers Exploit SharePoint Zero-Day Since July 7 to Steal Keys, Maintain Persistent Access The Hacker News
ChocoPoC Malware Targets Researchers with Fake Exploits ChocoPoC Malware Targets Researchers with Fake Exploits The Hacker News
LangSmith Bug Could Expose OpenAI Keys and User Data via Malicious Agents LangSmith Bug Could Expose OpenAI Keys and User Data via Malicious Agents The Hacker News
How to Protect the Invisible Identity Access How to Protect the Invisible Identity Access The Hacker News
Pro-Iranian Hacktivist Group Leaks Personal Records from the 2024 Saudi Games Pro-Iranian Hacktivist Group Leaks Personal Records from the 2024 Saudi Games The Hacker News
Vibe-Coded Malicious VS Code Extension Found with Built-In Ransomware Capabilities Vibe-Coded Malicious VS Code Extension Found with Built-In Ransomware Capabilities The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Flaw in OpenShift Allows Malicious Releases
  • Zero-Day Tool Blocks Microsoft Defender Updates
  • Veeam Agent Vulnerability Exploited for SYSTEM Privileges
  • Critical AI Gateway Flaw Exposes Bifrost to Command Attacks
  • PowerShell Exploited in New TASK#STOMP Cyber Intrusion

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Flaw in OpenShift Allows Malicious Releases
  • Zero-Day Tool Blocks Microsoft Defender Updates
  • Veeam Agent Vulnerability Exploited for SYSTEM Privileges
  • Critical AI Gateway Flaw Exposes Bifrost to Command Attacks
  • PowerShell Exploited in New TASK#STOMP Cyber Intrusion

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark