LIVE · cybersecurity feed
Live wire
security

Google Fined €403 Million Over Location Data Practices

Ireland’s Data Protection Commission (DPC) has imposed a fine of €403 million on Google for violations of the General Data Protection Regulation (GDPR) related to its handling of user location data. The decision, announced on September 21, 2026, concludes an investigation initiated in February 2020, which itself stemmed from complaints filed by several European consumer groups, including BEUC,…

ZeroDay News ·

Source: Security Affairs

Ireland’s Data Protection Commission (DPC) has imposed a fine of €403 million on Google for violations of the General Data Protection Regulation (GDPR) related to its handling of user location data. The decision, announced on September 21, 2026, concludes an investigation initiated in February 2020, which itself stemmed from complaints filed by several European consumer groups, including BEUC, dating back six years.

The DPC’s inquiry focused on Google’s processing of location data between May 25, 2018, when the GDPR came into effect, and February 4, 2020. Specifically, the investigation examined three Google features: "Web & App Activity," "Location History," and "Location Accuracy."

"Web & App Activity" tracks user interactions across Google services, sites, and applications, incorporating location data. "Location History" builds a timeline of a device’s movements over time, even when Google services are not actively in use. "Location Accuracy," an Android operating system feature, enhances location precision beyond standard GPS and applies to all Android users, regardless of whether they are signed into a Google account.

The DPC commissioners, Dr. Des Hogan, Mr. Dale Sunderland, and Ms. Niamh Sweeney, identified multiple issues with Google’s practices. They determined that the processing of data through "Web & App Activity" and "Location History" failed to meet GDPR requirements for lawfulness and fairness. Furthermore, Google could not demonstrate compliance with lawfulness, fairness, and transparency rules for its "Location Accuracy" feature.

Transparency was found to be a systemic problem across all three features. The DPC also concluded that Google retained location data for longer than permitted under GDPR. These findings represent four distinct violations spanning data collection, retention, and disclosure.

Deputy Commissioner Graham Doyle emphasized that location data, while enhancing online services, can also reveal highly private information about individuals. The DPC’s investigation found that Google’s failures meant users might have been unaware that their location data was being used for targeted advertising or to build interest profiles, thereby reducing their control over their personal information. The extended retention of this data exacerbated the issue.

The DPC has given Google six months to align its data processing practices with GDPR requirements. This is not the first time Google has faced scrutiny from the Irish regulator. The €403 million penalty is the fourth-largest EU privacy fine issued by the DPC, which has previously levied larger fines against companies such as TikTok and Meta, including a record €1.3 billion fine against Meta for transferring European user data to the United States. The six-year duration from initial complaint to final decision highlights the lengthy process involved in GDPR enforcement cases.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

CISA alerts of active exploitation of three Linux kernel flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the active exploitation of three distinct vulnerabilities within the Linux kernel, one of which is rated critical. These security issues were added to CISA's catalog last week, with severity ratings ranging from medium to critical. Federal agencies have been mandated to apply available security…

security

ShinyHunters Hacked Clop. Now What About Clop's Victims?

A recent report indicates that the ShinyHunters threat group has successfully compromised the dark web infrastructure associated with the Clop ransomware operation. This incident reportedly involved the defacement of Clop's dark web site and a claim by ShinyHunters to have exfiltrated data pertaining to Clop's victims. The primary concern arising from this alleged breach is the potential for…

nation-state

Gopass: Open-source command-line password manager for teams

Gopass, an open-source command-line password manager designed for teams, stores credentials in an encrypted format and operates without requiring a network connection, making it suitable for air-gapped systems. The tool functions as a direct replacement for the traditional Unix password manager, `pass`.

vulnerability

Intent injection attacks are a new worry for AI-native 6G networks

Researchers from the University of Ottawa and Nokia Bell Labs have identified a new class of threat, termed adversarial intent injection, targeting AI-native 6G networks that utilize intent-based networking (IBN). This attack vector exploits the abstraction inherent in IBN systems, where operators define desired outcomes and software translates these into network policies. The researchers…

ai

AI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factor

Forty percent of large companies have experienced an AI-related compliance or governance issue within the last year, according to a survey of 1,000 senior IT, operations, and transformation leaders. Process-related problems were cited as a contributing factor in 84% of these incidents.

vulnerability

U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux Kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal civilian executive branch (FCEB) agencies address these flaws by September 21, 2026. This directive, issued under Binding Operational Directive (BOD) 22-01, aims to mitigate significant risks posed by actively…