On September 21, 2026, Google was fined €403 million ($459 million) by its lead EU regulator, the Irish Data Protection Commission (DPC), for significant breaches of the General Data Protection Regulation (GDPR). The fine concludes a multi-year investigation into how Google processed user location data between May 2018 and February 2020. The DPC ruled that Google's data processing practices for several key features were not lawful, fair, or transparent, failing to provide users with adequate control over their sensitive location data. In addition to the financial penalty, Google has been ordered to bring its data processing operations into compliance within six months.
The inquiry was initiated in February 2020 following complaints from multiple European consumer rights organizations. The DPC's investigation focused on three specific Google features:
The DPC found that Google infringed upon several core GDPR articles:
The core issue was that users may not have been fully aware that their location data was being collected and used for purposes such as ad targeting and inferring personal interests, thereby losing meaningful control over their data.
The decision and fine are directed at Google Ireland Limited, which serves as Google's main establishment in the European Union for data processing purposes.
Beyond the €403 million fine, the DPC has issued a compliance order. Google is required to take corrective measures and bring its data processing operations related to the investigated features into full compliance with GDPR within six months of the decision. This will likely involve changes to user interfaces, consent flows, and internal data handling policies to enhance transparency and user control.
The financial impact on Google is significant, as this is the fourth-largest fine ever issued by the DPC. However, the reputational and operational impacts are also substantial. The ruling sets a strong precedent for how major technology companies must handle sensitive location data under GDPR. It reinforces that opaque settings and bundled consents are not compliant. For users, the decision empowers them and highlights the importance of regulatory bodies in protecting digital rights. Google stated that the issues related to older policies that have since been updated, but the fine and compliance order force a more rigorous and demonstrable adherence to GDPR principles going forward.
This case serves as a critical reminder for all organizations processing personal data, especially sensitive categories like location data:
Start of the period during which Google's location data processing was investigated.
The Irish DPC launches its formal inquiry into Google's handling of location data.
End of the period during which Google's location data processing was investigated.
The Irish DPC announces the €403 million fine against Google.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.