Google Fined €403 Million Over GDPR Violations Tied to Location Data
Data Privacy / Regulatory ComplianceGoogle has been fined €403 million for breaking the EU's data 2026-9-21 16:57:31 Author: thehackernews.com(查看原文) 阅读量:10 收藏

Data Privacy / Regulatory Compliance

Google has been fined €403 million for breaking the EU's data protection law, the GDPR, in the way three of its features handled people's location data from May 2018 to February 2020.

Ireland's Data Protection Commission (DPC), Google's lead regulator in the EU, also ordered the company to make its processing comply with the law within 6 months. The DPC has not said publicly which processing the order covers, and it says its full decision will be published later.

The three features are Web & App Activity, Location History and Location Accuracy.

Web & App Activity is a Google account setting that, when turned on, lets Google process data about a user's activity on its sites and apps. That data can include location. Location History, which users must opt in to, keeps track of where they go with their signed-in mobile devices, even when they are not using a Google service.

For both cases, the DPC found that Google breached the GDPR's rules on lawful and fair processing and on transparency, and that it retained location data longer than necessary.

Location Accuracy is an Android feature that works out a device's location more precisely than GPS alone, and it is available to Android users with or without a Google account. The DPC's findings for this feature are narrower.

Google broke the transparency rules and the GDPR's accountability rules because it could not demonstrate that this processing was lawful, fair and transparent.

DPC Deputy Commissioner Graham Doyle said these failures meant people could have been unaware that their location was being used, for example, to influence them with ads or to infer their interests. They could also lose control of their personal data, and keeping it for so long made that worse.

At €403 million, the fine is the fourth-largest the DPC has issued. It cannot be collected yet, because a DPC fine becomes payable only after an Irish court confirms it. Google can appeal to the High Court within 28 days of receiving formal notice of the decision.

In a statement reported by the Associated Press, Google said the case "centers around historical policies that have since been updated" and that it has changed its practices significantly since 2019.

In May 2019, during the period the DPC examined, Google announced auto-delete controls for Location History and Web & App Activity. They let users have that data deleted automatically after 3 or 18 months. In June 2020, Google made 18-month auto-delete the default for Web & App Activity on new accounts and for anyone turning on Location History for the first time.

In December 2023, Google announced that Timeline, the Google Maps feature that shows Location History on a map, would keep its data on users' devices. Auto-delete would also default to 3 months for anyone turning on Location History for the first time.

The DPC has not publicly said whether these changes are sufficient to meet its order.

The DPC opened its inquiry in February 2020 after complaints from European consumer groups, including BEUC, the European Consumer Organization. BEUC's member groups had filed the complaints with national data protection authorities in November 2018. The period the DPC examined ends on 4 February 2020, the day it announced the inquiry.

The decision came more than 6.5 years after the inquiry opened. In comments reported by NewsIreland.EU, BEUC director general Agustín Reyna welcomed it but criticized how long it took. "Late enforcement can be as harmful as no enforcement at all," he said.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2026/09/google-fined-403-million-over-gdpr.html
如有侵权请联系:admin#unsafe.sh