By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Google Fined €403M for GDPR Location Data Violations

Google has been fined €403 million for violating the European Union's General Data Protection Regulation (GDPR) concerning the handling of users' location data. The penalty, issued by Ireland's Data Protection Commission (DPC), stems from the way three of Google's features processed location information between May 2018 and February 2020. The DPC, acting as Google's lead supervisory authority in the EU, has also mandated that the technology giant must bring its data processing practices into compliance with GDPR within a six-month period. The specific features implicated in the violation have not been publicly disclosed by the DPC. This significant fine underscores the ongoing scrutiny of major technology companies regarding their data privacy practices under the stringent GDPR framework. The GDPR, which came into effect in May 2018, grants individuals greater control over their personal data and imposes strict obligations on organizations that collect and process this information. Fines for non-compliance can reach up to 4% of a company's annual global turnover or €20 million, whichever is greater. The DPC's decision follows an investigation into Google's data handling practices, highlighting the challenges companies face in navigating complex data protection laws across different jurisdictions. The ruling is expected to have broader implications for how other tech firms manage user location data and adhere to privacy regulations. Google has previously faced scrutiny and fines from various European data protection authorities for privacy-related issues. The company is expected to appeal the decision or implement the required changes to its systems and policies. The DPC's order for compliance within six months indicates a push for immediate corrective action, aiming to ensure user privacy is adequately protected. The investigation likely examined the transparency of data collection, the consent mechanisms employed, and the purposes for which location data was used. The substantial financial penalty serves as a strong deterrent against future violations and reinforces the importance of robust data governance frameworks within the digital economy. The DPC's role as the lead regulator for Google in the EU means its decisions carry significant weight and can influence regulatory approaches in other member states. The €403 million fine represents one of the largest penalties imposed under GDPR, reflecting the severity of the breaches identified. The case also brings attention to the technical complexities involved in managing and securing vast amounts of user data, particularly sensitive information like location history. Google's response to this fine and its subsequent compliance efforts will be closely watched by regulators, privacy advocates, and consumers alike, as it sets a precedent for data protection enforcement in the digital age.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.