Google’s location data privacy failures draw a €403 million fine
Cybersecurity Classified by Officially
The Irish Data Protection Commission (DPC) has fined Google €403 million ($459 million) for violating European privacy law. The penalty follows a six-year inquiry into Google’s management of user location data between May 2018 and February 2020.
During that time, Google collected users’ location data without making clear that it could be used to infer their interests and shape the ads they saw.
Google’s location history keeps track of users’ locations when using their devices. It’s an opt-in service that includes a Timeline feature to display a private map of the places they’ve visited. A separate Android feature, Location Accuracy, helps devices determine their location more accurately than GPS alone.
Google had told users that they could stop Location History tracking by turning off that setting. But a report by the Associated Press in 2018 found that doing so wasn’t enough to stop Google from saving some of that location data. Researchers at Princeton University later confirmed the AP’s findings.
One reason was Web & App Activity, a separate Google account setting that can save information about what Google account holders have been browsing on the web and doing with their apps. That service was also collecting location data. Turning off Location History did not turn off Web & App Activity.
This issue led to payouts in multiple US jurisdictions. Google agreed to pay $85 million to Arizona in October 2022, $392 million to 40 states that November, and $9.5 million to the District of Columbia the following month. It also agreed to pay $39.9 million to Washington State in 2023, $1.38 billion to Texas in May 2025 as part of a two-suit settlement. Last September, a jury awarded $425 million in a separate class action case.
This is an extract. The publication continues at the source.
Read the original at the source: https://www.malwarebytes.com/blog/news/2026/09/googles-location-data-privacy-failures-draw-a-e403-million-fine
Officially imported this from Malwarebytes’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Malwarebytes — imported from official source
- Official source
- https://www.malwarebytes.com/blog/feed/index.xml RSS
- Imported
- September 24, 2026 09:00
- Versions
- 1 recorded
- Identity
https://www.malwarebytes.com/blog/news/2026/09/googles-location-data-privacy-failures-d...