Google fined €403 million for GDPR location‑data privacy violations
What Happened – Ireland’s Data Protection Commission imposed a €403 million fine on Google for breaching GDPR requirements when processing users’ location data through Web & App Activity, Location History, and Location Accuracy features. The regulator found that Google failed to provide transparent notices, lacked a valid legal basis for the processing, and retained the data longer than necessary.
Why It Matters for Trust & Control Assurance
- The incident highlights the need for continuous evidence that privacy‑related controls (consent capture, purpose limitation, data‑retention policies) are operating as intended.
- A robust control‑assurance program can surface gaps in privacy governance before regulators identify them, providing a defensible audit trail.
- Verisq’s CookiePLUS Privacy capability helps organizations demonstrate compliance with consent and data‑retention controls across multiple frameworks.
Who Is Affected – Large‑scale SaaS providers, digital advertising platforms, and any organization that processes location or other personal data under GDPR.
Recommended Actions
- Review and document the legal basis for all location‑data processing activities.
- Implement automated consent‑capture and granular user‑controlled deletion mechanisms.
- Align data‑retention schedules with the “purpose‑limitation” principle and retain evidence of compliance for audit readiness. Source: BleepingComputer
Technical Notes – The DPC examined three Google features active between May 2018 and February 2020: (1) Web & App Activity, (2) Location History (opt‑in tracking), and (3) Location Accuracy (device‑level positioning). Violations stemmed from opaque processing notices and excessive retention of location timestamps. Source: same as above