Skip to content
Tech News
clear
Topics: Today This Week This Month This Year

Ireland's DPC fines Google €403 million over location data practices

Ireland's Data Protection Commission concluded a five-year inquiry into how Google Ireland handled location data across Web & App Activity, Location History and Location Accuracy features between 2018 and 2020. The regulator found multiple GDPR violations spanning lawfulness, transparency, accountability and data retention, and has fined the company €403 million while giving it six months to fix its practices.

Ireland's DPC fines Google €403M over GDPR location data violations

Ireland's Data Protection Commission fined Google €403 million ($463 million) after a multi-year investigation into how it handled location data through Web & App Activity, Location History, and Location Accuracy features between 2018 and 2020. Regulators found Google failed to meet GDPR transparency and lawfulness requirements and violated data retention rules for two of the three features. Google must bring its location data practices into compliance within six months and says it has already updated its policies since 2019.

Ireland's DPC fines Google €403 million over location data GDPR breaches

Ireland's Data Protection Commission has imposed a €403 million ($463M) fine on Google following a probe into three features—Web & App Activity, Location History, and Location Accuracy—that operated during the GDPR's early enforcement window from May 2018 to February 2020. The regulator concluded Google failed to properly justify its processing of location data and kept that data longer than necessary, while also falling short on transparency requirements across all three tools.

CNIL fines Hôpital privé de la Loire €500,000 over 727,000-record breach

France's data protection authority CNIL has fined Hôpital privé de la Loire €500,000 after a 2025 breach exposed data belonging to over 727,000 people, including more than 524,000 patients and roughly 202,000 people listed as trusted contacts. Investigators found the hospital allowed external users to log in without VPNs or multi-factor authentication, gave a single compromised account access to all patient records, and had no real-time monitoring to catch the intrusion as it unfolded over several days.

Defenders push back on claims that GDPR's cookie banners prove the law failed

A commentary argues that the widespread criticism of GDPR, especially over cookie consent banners, misreads what's happening. The author contends that companies deliberately designed those banners as confusing dark patterns to frustrate users into clicking 'accept,' not because the regulation demanded it, and that this design choice is being unfairly blamed on the law itself.

Dutch regulator fines Uber €825 million for automated driver suspensions under GDPR

The Dutch Data Protection Authority fined Uber roughly $966 million after finding that between 2018 and 2022 the company suspended European drivers using automated systems without meaningful human review, violating GDPR's Article 22 protections against purely automated decisions with significant consequences. The case stemmed from a 2020 complaint filed with France's CNIL by La Ligue des droits de l'Homme on behalf of over 170 drivers, and was handled by Dutch authorities since Uber's main EU base is in Amsterdam. Uber plans to appeal, arguing that fraud suspensions were brief, permanent deactivations always involved human review, and drivers had appeal options.

Today's top topics: openai apple anthropic artificial intelligence dario amodei samsung ai safety android authority beats 360 claude opus 5.5
View all today's topics →