Google Fined 403 Million Over Location Data (09/21/2026)
- › Ireland's Data Protection Commission fined Google 403 million euros, about 463 million dollars, over how it processed location data.
- › The finding was that people did not understand their movements were being used to influence what they were shown.
- › MIT Technology Review spent 15 months mapping deaths near the surveillance towers built to find people crossing the border.
- › Hong Kong and Singapore are extending facial recognition to drivers and passengers who never leave the vehicle.
- › The EFF argues the EU Kids Act will not deliver the accountability it promises, which is a familiar shape for child safety law.
Location is the most revealing category of data any of us produce, because where a person goes over a year describes their health, their faith, their relationships, and their politics without anybody having to ask. Ireland’s Data Protection Commission has now put a price on getting that wrong, and the finding was not that Google hid the collection so much as that people never grasped what it was for. Underneath that, a 15 month investigation into the surveillance towers along the southern border asks a harder question about what all this watching is actually achieving.
Top 5 Critical Privacy Alerts
1. Ireland Fines Google 403 Million Euros Over Location Data
The Data Protection Commission fined Google 403 million euros, roughly 463 million dollars, for GDPR violations in how it processed users’ location data, per BleepingComputer. The regulator’s core finding was that users did not understand their location was being used to influence the advertising they saw, according to Infosecurity Magazine.
Operator Note: Consent that is technically obtained and practically not understood keeps failing this test. If your own privacy notice would surprise the person who agreed to it, you have the same exposure at a smaller scale.
2. Fifteen Months Mapping the Deaths Near the Border Towers
MIT Technology Review published an investigation into how many people have died near the surveillance towers installed along the US and Mexico border, built from a 15 month effort to assemble the first map of those deaths anybody has produced. The reporting follows individual cases, including a man whose crossing should have triggered a chain of alerts and responses, and a woman who died within sight of a camera, and it asks why billions spent on detection has not translated into finding people in time. The team also published its methodology and four specific policy fixes alongside the main investigation and one woman’s story.
Operator Note: A system that detects reliably and responds unreliably is not a safety system, whatever it was funded as. The same gap shows up in corporate monitoring that generates alerts nobody is staffed to act on.
3. Hong Kong and Singapore Extend Facial Recognition Into Vehicles
Both jurisdictions are expanding facial recognition for border clearance so that drivers and passengers are identified without leaving the vehicle, per Biometric Update. Removing the step where a person hands over a document also removes the moment where they notice the check is happening.
4. The EFF Says the EU Kids Act Will Not Deliver What It Promises
The Electronic Frontier Foundation argues that the EU Kids Act will not make the internet meaningfully more accountable or trustworthy, in its analysis of the proposal, while Covington’s summary of the framework lays out what it would actually require. Child safety proposals tend to arrive with age verification attached, and age verification means identifying everybody in order to sort out the minors.
5. noyb Warns of Digital Expropriation for AI Training
The privacy group noyb argues that EU member states are preparing to let AI companies use Europeans’ personal data on a legal basis that individuals cannot meaningfully refuse, which it characterizes as digital expropriation. The argument to watch is whether legitimate interest becomes the route around consent for training data.
Additional Privacy Alerts
Surveillance and Law Enforcement Technology
- 404 Media is mapping Axon license plate cameras: The outlet is asking readers to help identify which cities have deployed Axon’s plate readers, which is the kind of inventory that should not have to be crowdsourced. 404 Media
- Researchers pulled the software off a Flock camera: A captured plate reader gave analysts a look at how the system works, though the most sensitive storage stayed encrypted. Schneier on Security
Privacy Laws and Regulations
- EDPB harmonizes how fines are calculated: The European Data Protection Board adopted a common fining methodology along with final guidelines on the interaction between the Digital Services Act and GDPR. EDPB
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A PhD candidate in Health Psychology and former Corrections Officer, Jeff founded GTA to dismantle passive security models. He focuses on the 'Human Zero-Day', mitigating executive burnout and decision fatigue before they become security breaches.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.