Ireland’s Data Protection Commission (DPC) has imposed a €403 million ($463 million) fine on Google for GDPR violations in its processing and retention of users’ location data. The investigation examined the company’s Web & App Activity, Location History, and Android Location Accuracy features between May 25, 2018, and February 4, 2020, finding shortcomings involving lawfulness, fairness, transparency, accountability, and retention practices.
The DPC ordered Google to make its location-data processing compliant within six months. Google said the ruling concerns historical practices that it has since changed, citing stronger user controls, automatic deletion settings, and device-based storage of Google Maps Timeline data.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
Ireland's Data Protection Commission opened an own-volition inquiry following complaints from European consumer-rights organizations, examining Google's location-data processing features.
Google said it began updating the historical practices and policies at issue in 2019, including adding easier location-data management controls, automatic deletion options, and device-based storage for Maps Timeline data.
The DPC fined Google €403 million for GDPR violations involving Web & App Activity, Location History, and Location Accuracy, citing deficiencies in lawfulness, fairness, transparency, accountability, and retention. It ordered Google to bring its location-data processing into compliance within six months.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
6 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourceinfosecurity-magazine.com
Open sourceabcnews.com
Open sourcehelpnetsecurity.com
Open sourcedataprotection.ie
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.