Google Fined €403 Million for GDPR Violations Over Location‑Data Practices
What Happened – Ireland’s Data Protection Commission (DPC) imposed a €403 million fine on Google for unlawful processing of location data across three features: Web & App Activity, Location History, and Location Accuracy. The regulator found breaches of GDPR principles of lawfulness, fairness, transparency, and data‑retention, affecting both signed‑in users and anyone running Android.
Why It Matters for Trust & Control Assurance
- Demonstrates the audit risk when privacy‑by‑design and clear data‑retention policies are missing – a core control‑assurance scenario.
- Highlights the need for continuous evidence of lawful processing (consent records, retention schedules, transparency notices) to satisfy regulators and auditors.
- Shows that a single data‑handling flaw can trigger multi‑million penalties, underscoring the value of a unified privacy‑control framework.
Who Is Affected – Global technology providers, mobile‑OS vendors, and any organization that processes location or other high‑risk personal data.
Recommended Actions
- Conduct a privacy impact assessment (PIA) of all location‑data features.
- Align data‑collection, consent, and retention practices with GDPR Art. 5‑6 requirements.
- Implement continuous monitoring of consent logs and retention schedules; retain defensible audit evidence.
- Update user‑facing privacy notices to be clear, specific, and easily accessible.
Source: Security Affairs
Technical Notes – The DPC examined Google’s processing from 25 May 2018 (GDPR start) to 4 Feb 2020. Violations spanned collection, storage, and disclosure of location data, including the Android‑level “Location Accuracy” feature that operates without a signed‑in account. No specific CVE or exploit was involved. Source: same