Home › Intelligence › Brief
BREACH BRIEF🟠 High Advisory

Google fined €403 million by Irish regulator for unlawful location‑data processing

Ireland’s Data Protection Commission fined Google €403 million for processing location data without a lawful basis and lacking transparency. The case underscores the importance of documented consent and retention controls for GDPR audit readiness.

LiveThreat™ Intelligence · 📅 September 22, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
helpnetsecurity.com

Google fined €403 million by Irish regulator for unlawful location‑data processing

What Happened – Ireland’s Data Protection Commission imposed a €403 million fine on Google for processing users’ location data through Web & App Activity, Location History, and Location Accuracy without a lawful basis, and for failing to provide transparent information or limit retention. The regulator ordered Google to bring the processing into compliance within six months.

Why It Matters for Trust & Control Assurance

  • Demonstrates the audit‑ready evidence gap when organizations cannot prove lawful, fair, and transparent data‑processing practices.
  • Highlights the need for continuous privacy‑control monitoring and documented consent mechanisms to satisfy accountability obligations.
  • Shows that a single control—transparent data‑governance—maps to many frameworks (GDPR, NIST CSF, ISO 27001) and is a litmus test for a trustworthy data‑handling posture.

Who Is Affected – Global online‑service providers, advertising platforms, and any organization that processes location or other personal data at scale.

Recommended Actions

  • Conduct a privacy‑impact assessment of all location‑tracking features and verify lawful bases.
  • Implement a consent‑capture and management solution that logs user choices and supports easy withdrawal.
  • Align data‑retention schedules with the principle of storage limitation and document the process for auditors.

Technical Notes – The DPC’s investigation covered Google’s handling of location data from 25 May 2018 to 4 Feb 2020. Violations centered on lawfulness, fairness, transparency, and excessive retention, not on a technical vulnerability. Source: Help Net Security

📰 Original Source
https://www.helpnetsecurity.com/2026/09/21/ireland-google-users-location-data-processing-fine/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

Data exposure is where consent and DSAR readiness get tested.

When personal data leaks, regulators ask what consent you held and how fast you can answer a subject request. The Verisq AI Trust Operations platform, with CookiePLUS, keeps that posture audit-ready under GDPR and CCPA.

Explore the Verisq AI Trust Operations platform →