Security News

Google Fined €403m for Mishandling Users' Location Data

Infosecurity Magazine · 22 Sept 2026
Key Takeaway Businesses using any app or platform that collects location data should regularly review privacy settings and data retention policies to ensure customer information isn't kept or used longer than necessary.

Google has been fined €403m (around $460m) by Ireland's Data Protection Commission (DPC) following a lengthy investigation into how the company processed location data from users of services like Google Maps and Android location features. The inquiry, which began in February 2020, found that people using these services may not have realised their location data was being used to serve targeted ads or infer their interests, resulting in a loss of control over their personal information.

The investigation examined three specific features, Web & App Activity, Location History and Location Accuracy, covering the period from May 2018 to February 2020. The DPC found Google breached the GDPR in four respects, including keeping users' location data for longer than necessary. Deputy Commissioner Graham Doyle said location data is highly sensitive because it can reveal significant private information about individuals, even though it also enables useful services.

Google has six months to bring its data processing practices into compliance. A company spokesperson said the case relates to historical policies that have since been updated, pointing to tools introduced from 2019 onwards that make managing location data easier. This follows a separate $391.5m settlement Google agreed to in the US in 2022 over similar allegations.

GDPR Data Privacy Google Location Data Regulatory Compliance

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.