Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Back To Home
Research Team (Tsaaro)
Ireland’s Data Protection Commission Fines Google €403 Million Over Location Data Processing

Ireland’s Data Protection Commission (DPC) has fined Google Ireland €403 million following an inquiry into the company’s processing of users’ location data. The decision, issued on 21 September 2026, concerned Google’s processing of location data through Web & App Activity, Location History and Location Accuracy between 25 May 2018 and 4 February 2020.
The DPC found infringements relating to the lawfulness and fairness of processing, transparency and accountability, as well as the retention of location data. The regulator concluded that Google had not adequately demonstrated compliance with the GDPR’s requirements and that users could have been unaware of how their location information was being processed and used.
The DPC also imposed a compliance order requiring Google to bring its processing into compliance within six months. The regulator highlighted the sensitivity of location data, noting that it can reveal information about an individual’s movements, activities and interests.
The decision reinforces the GDPR’s requirements around lawful processing, meaningful transparency and data retention. It also demonstrates that regulators may examine not only whether personal data is collected lawfully, but whether organisations can demonstrate accountability throughout the processing lifecycle.
Source: Ireland Data Protection Commission
NEWS OF THE WEEK
Ireland’s DPC Publishes AI Insights Report After Supervising Around 180 AI Products
Ireland’s Data Protection Commission has published a report detailing its supervision of artificial intelligence products and services between 2021 and 2025. The DPC reported that it engaged with controllers concerning approximately 180 AI products and services, reviewing thousands of pages of risk assessments, technical and organisational measures and compliance documentation.
The report covers technologies including large language models, recommender systems, facial recognition, age assurance and AI agents. The DPC identified lawful basis, transparency, data minimisation and children's data protection as key areas requiring attention, with legitimate interests as a legal basis for AI training receiving scrutiny.
The report also highlights the difficulty of ensuring meaningful transparency where AI systems involve complex or opaque processing operations. The DPC stated that controllers deploying AI should provide individuals with sufficient information to understand how their data is processed and the implications of that processing.
The publication provides a useful indication of the issues regulators are encountering in the practical supervision of AI systems and the areas likely to remain central to data protection compliance as AI deployment expands.
Source: Ireland Data Protection Commission
EDPB Harmonises GDPR Fining Methodology and Finalises DSA-GDPR Guidelines

The European Data Protection Board (EDPB) has adopted new guidelines on the application of administrative fines alongside other corrective powers under the GDPR, while also finalising its guidance on the interaction between the Digital Services Act (DSA) and GDPR.
The new fining guidelines establish a five-step methodology for supervisory authorities. This includes determining whether an infringement is subject to a fine, identifying the party liable, assessing whether the infringement was intentional or negligent, considering aggravating and mitigating factors, and determining whether a fine would be effective, proportionate and dissuasive.
The EDPB has also adopted the final version of its DSA-GDPR guidelines following public consultation. The guidelines address situations where DSA obligations concern the processing of personal data by intermediary service providers and rely on concepts established under the GDPR.
The fining guidelines are open for public consultation until 13 November 2026. The developments are relevant for organisations operating across the EU because they provide greater clarity on how DPAs may combine fines with other corrective measures and how the GDPR interacts with the DSA.
Source: European Data Protection Board
Spain Reports First AI Agent-Linked Personal Data Breach
Spain’s data protection authority, the AEPD, has received what it describes as the first reported notification of a personal-data breach allegedly carried out by an AI agent. According to the notification, the agent used a large language model to identify vulnerabilities, access a system, modify personal data and view billing records, with limited human intervention.
The AEPD clarified that the incident does not indicate that the AI model or its provider’s infrastructure was compromised, and the investigation remains ongoing. The affected organisation and AI model have not been publicly identified.
The incident highlights an emerging cybersecurity concern: AI agents can potentially automate several stages of an attack rather than merely assisting a human attacker. This may increase the speed and adaptability of attacks and reduce the time available for detection and containment.
For organisations deploying agentic AI, the development raises practical questions around access controls, monitoring, human oversight, incident response and the treatment of autonomous systems within existing cybersecurity and data-breach risk assessments.
Source: Spanish Data Protection Agency / Reuters
South Korea Proposes Stricter ISMS-P Certification Reviews
South Korea’s Personal Information Protection Commission (PIPC) has proposed amendments to the Enforcement Decree of the Personal Information Protection Act to strengthen the country’s ISMS-P information-security and privacy certification regime.
The proposal would allow documentary and on-site assessments to be conducted together and permit qualified technical personnel to undertake vulnerability assessments and penetration testing in certain circumstances, including following cyber incidents or personal-data breaches. Similar technical assessments could also be conducted during annual follow-up reviews.
The proposed amendments would also allow certification standards to vary according to factors such as the volume of personal data processed and an organisation’s potential social impact. Organisations legally required to hold ISMS-P certification whose certification is cancelled would receive a proposed one-year grace period before administrative fines apply, except where certification was obtained through fraudulent means.
The proposal is open for public consultation until 26 October 2026 and reflects a move towards greater technical verification and continuing oversight within privacy and information-security certification.
Source: South Korea Personal Information Protection Commission
Want to stay ahead?
Reach out to the experts at Tsaaro today.


