Google fined €403 million for privacy violations in location‑data handling
What Happened — The Irish Data Protection Commission imposed a €403 million fine on Google for unlawfully collecting and retaining users’ location data between May 2018 and February 2020. The regulator found that turning off “Location History” did not stop Google from saving location signals via the separate “Web & App Activity” setting, violating GDPR consent and purpose‑limitation rules.
Why It Matters for Trust & Control Assurance
- Demonstrates the risk of fragmented privacy settings that prevent a single, auditable consent record – a classic control‑gap that continuous‑control‑monitoring programs are built to detect.
- Highlights the need for documented, defensible evidence that data‑processing activities align with GDPR‑required lawful bases and retention schedules.
- Shows how a lack of unified privacy‑governance can trigger massive regulatory penalties, underscoring the value of a dedicated privacy‑control suite.
Who Is Affected – Global technology and SaaS providers that process EU residents’ location or behavioral data, as well as any organization that bundles multiple data‑collection services under a single user account.
Recommended Actions
- Conduct a privacy‑control gap analysis against GDPR’s consent, purpose limitation, and data‑retention requirements.
- Consolidate consent capture into a single, auditable workflow and map it to your control‑assurance evidence repository.
- Implement continuous monitoring of privacy‑related settings (e.g., Location History, Web & App Activity) to ensure changes are reflected in real‑time compliance dashboards.
Source: Malwarebytes Labs
Technical Notes
- Issue stemmed from a mis‑aligned configuration where disabling “Location History” did not disable “Web & App Activity”, allowing ongoing location capture.
- No specific CVE; the problem was a privacy‑control misconfiguration across Google’s consumer services.
Source: Malwarebytes Labs