Google Fined €403 Million Over GDPR Violations Tied to Location Data
- ID
- 26958
- Status
- summarized
- Published
- 22 Sep 2026, 12:57 AM
- Fetched
- 22 Sep 2026, 3:24 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/google-fined-403-million-over-gdpr.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 5.5
- Created
- 22 Sep 2026, 3:28 AM
- Tags
- Audience
- developerssaas_founders
What happened
Ireland's Data Protection Commission fined Google €403 million for GDPR violations in how three features—Web & App Activity, Location History, and Location Accuracy—handled user location data from May 2018 to February 2020. The DPC found breaches in lawful/fair processing, transparency, and excessive data retention, and ordered Google to bring its processing into compliance within 6 months. The fine is the DPC's fourth-largest but cannot be collected until an Irish court confirms it; Google can appeal within 28 days.
Why it matters
If your app or SaaS collects location data from EU users, the specific violations here—bundling location into a general activity setting without clear consent, retaining location data longer than necessary, and failing to demonstrate lawful processing for a feature available even to non-logged-in users—are the exact patterns regulators are targeting. Review your location data consent flows and retention policies against these three failure modes before a regulator or enterprise customer does it for you.
Discussion angle
Walk through the three features the DPC flagged and map each violation to a concrete checklist item for any app handling location data—especially whether your consent UI separates location from general activity tracking and whether your retention policy has a defensible time limit.