Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2988+ Articles
168+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Google Fined €403 Million Over Location Data Privacy Violations
Google Fined €403 Million Over Location Data Privacy Violations
NEWS

Google Fined €403 Million Over Location Data Privacy Violations

Ireland's DPC fined Google €403M ($463M) after finding it failed to meet GDPR transparency requirements across three location-tracking features.

Dylan H.

News Desk

September 22, 2026
2 min read

Six-Year Investigation Ends in a €403 Million Penalty

Ireland's Data Protection Commission (DPC) has fined Google €403 million (approximately $463M USD) for multiple GDPR violations tied to how the company processed users' location data. The penalty caps an investigation the DPC opened in February 2020 following consumer complaints.


What the DPC Found

The DPC determined Google failed to meet transparency requirements across three location-tracking features:

FeatureViolation
Web & App ActivityProcessed browsing and search history without proper disclosure
Location HistoryTracked user movements without adequate consent mechanisms
Location AccuracyAndroid positioning feature lacked demonstrable compliance

The regulator concluded users "could have been unaware that their location was being used to, for example, influence them with ads," and found that Google retained location data for longer than necessary.


Investigation Timeline

DateMilestone
May 25, 2018 – February 4, 2020Period under examination
February 2020DPC opens formal investigation
September 21–22, 2026Fine announced — €403M ($462–463M)
+6 monthsCompliance deadline imposed on Google

Google's Response

Google says its practices have "evolved substantially" since the period under investigation. The company points to since-implemented changes including:

  • Automatic data deletion — Google Maps Timeline now removes location history older than three months by default
  • User-friendly management controls for reviewing and deleting stored location data
  • Reduced data precision — Google says it no longer stores precise device locations in Web & App Activity, only estimated general areas

Why It Matters

This is one of the larger GDPR enforcement actions against a major tech platform to date, and it underscores continued regulatory scrutiny of how ad-supported platforms handle location data specifically — a category regulators increasingly treat as sensitive given its potential to reveal patterns of life, health status, religious practice, and other protected characteristics.


Sources

  • BleepingComputer — Google Fined €403 Million Over Location Data Privacy Violations
  • The Record — EU Data Regulator Fines Google More Than $460 Million for Location Data Violations
#Google#GDPR#Privacy#Data Protection Commission#Regulatory Fine

Related Articles

Google Hit With $463 Million Fine for EU Location Data Rule Breach

Ireland's DPC fined Google €403M ($463M) after finding it unlawfully processed Location History, Web & App Activity, and Location Accuracy data.

3 min read

Uber Fined €825 Million by Dutch Regulators Over Automated Driver Account Suspensions

The Dutch DPA fined Uber €825M for GDPR violations after its algorithm suspended driver accounts without meaningful human review or transparent explanation.

4 min read

Spain Fines 23andMe Nearly $3 Million for Cybersecurity Failings Enabling 2023 Hack

Spain's data protection agency AEPD has fined 23andMe approximately $3 million for cybersecurity failures that enabled the 2023 credential-stuffing breach...

5 min read
Back to all News