Qna.Qa Ireland Fines Google €403 Million for Location Data Violations
Article Content
- •Google fined €403 million for GDPR violations related to location data processing.
- •The inquiry revealed users were unaware of how their location data was used.
- •Google must comply with GDPR regulations within six months.
On September 21, 2026, Ireland's Data Protection Commission (DPC) fined Google €403 million (approximately $463 million) for breaching the EU's General Data Protection Regulation (GDPR) regarding user location data. The violations occurred between May 2018 and February 2020, involving features like 'Web & App Activity' and 'Location History.' The DPC's inquiry, initiated in February 2020, revealed that Google failed to ensure the lawfulness and fairness of its data processing practices. Users were potentially unaware that their location data was being used for targeted advertising and interest inference. The DPC mandated Google to comply with GDPR regulations within six months. This fine marks the fourth-largest penalty imposed by the DPC on major tech firms, contributing to over €4 billion in total fines since GDPR's implementation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Google in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…