Home › Intelligence › Brief
BREACH BRIEF🟠 High Advisory

Google fined €403 million for privacy violations in location‑data handling

The Irish DPC fined Google €403 million after discovering that disabling Location History did not stop the collection of location data via Web & App Activity, breaching GDPR. The case underscores the need for unified consent controls and auditable privacy evidence.

LiveThreat™ Intelligence · 📅 September 25, 2026· 📰 malwarebytes.com
🟠
Severity
High
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
1 recommended
📰
Source
malwarebytes.com

Google fined €403 million for privacy violations in location‑data handling

What Happened — The Irish Data Protection Commission imposed a €403 million fine on Google for unlawfully collecting and retaining users’ location data between May 2018 and February 2020. The regulator found that turning off “Location History” did not stop Google from saving location signals via the separate “Web & App Activity” setting, violating GDPR consent and purpose‑limitation rules.

Why It Matters for Trust & Control Assurance

  • Demonstrates the risk of fragmented privacy settings that prevent a single, auditable consent record – a classic control‑gap that continuous‑control‑monitoring programs are built to detect.
  • Highlights the need for documented, defensible evidence that data‑processing activities align with GDPR‑required lawful bases and retention schedules.
  • Shows how a lack of unified privacy‑governance can trigger massive regulatory penalties, underscoring the value of a dedicated privacy‑control suite.

Who Is Affected – Global technology and SaaS providers that process EU residents’ location or behavioral data, as well as any organization that bundles multiple data‑collection services under a single user account.

Recommended Actions

  • Conduct a privacy‑control gap analysis against GDPR’s consent, purpose limitation, and data‑retention requirements.
  • Consolidate consent capture into a single, auditable workflow and map it to your control‑assurance evidence repository.
  • Implement continuous monitoring of privacy‑related settings (e.g., Location History, Web & App Activity) to ensure changes are reflected in real‑time compliance dashboards.

Source: Malwarebytes Labs

Technical Notes

  • Issue stemmed from a mis‑aligned configuration where disabling “Location History” did not disable “Web & App Activity”, allowing ongoing location capture.
  • No specific CVE; the problem was a privacy‑control misconfiguration across Google’s consumer services.

Source: Malwarebytes Labs

📰 Original Source
https://www.malwarebytes.com/blog/news/2026/09/googles-location-data-privacy-failures-draw-a-e403-million-fine ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

Data exposure is where consent and DSAR readiness get tested.

When personal data leaks, regulators ask what consent you held and how fast you can answer a subject request. The Verisq AI Trust Operations platform, with CookiePLUS, keeps that posture audit-ready under GDPR and CCPA.

Explore the Verisq AI Trust Operations platform →