To ensure the best browsing experience, please enable JavaScript in your web browser. Without it, many website features are inaccessible.


Total Tests:
485,773,462
737,046
130,956

EU Fines Google €890 Million For Breaches Of DMA

July 28, 2026

Read also: South Korea fines TikTok and Apple; the US data broker hit with a €2M penalty over the GDPR violations; and more.

Views: 738 Read Time: 3 min.

EU Fines Google €890 Million For Breaches Of DMA

EU fines Google a whooping €890 million for breaches of DMA

The European Commission has fined Google €890 million ($1 billion) for breaking the European Union's Digital Markets Act (DMA), a law designed to keep online competition fair.

The Commission said Google gave its own services, such as shopping, hotels, transport, and sports results, better placement in Google Search than competing services. It also found that Google restricted businesses from directing consumers to alternative, often cheaper, purchase channels.

The Commission said that as a “gatekeeper,” Google shouldn’t treat its services more favorably but instead implement a transparent, fair, and non-discriminatory approach to rankings.

The fine includes €460 million for favoring its services in search results and €430 million for limiting app developers' choices. The Commission has ordered Google to fix the issues within 60 days or face additional penalties of up to 5% of its worldwide turnover.

South Korea fines TikTok and Apple over privacy law breaches

South Korea has fined TikTok and two Apple affiliates a combined 10.558 billion won (more than €6.3 million) for violating the country's Personal Information Protection Act and the former Act on Promotion of Information and Communications Network Utilization and Information Protection laws, citing unlawful data collection, inadequate transparency and improper overseas data transfers.

The Personal Information Protection Commission (PIPC) said TikTok failed to properly inform users about overseas transfers of personal data, including what information was shared and why. Regulators also found the platform collected behavioral data from about 9.45 million South Korean users through tracking technologies on third-party websites and mobile apps. The data, including browsing activity, purchases, clicks and device identifiers, was linked to user accounts for personalized advertising without adequate notice.

Two Apple affiliates were fined a combined 250 million won (~€149,000) after the PIPC found Siri voice recordings and transcripts were used to improve the service without an appropriate legal basis. The watchdog also said Apple transferred personal data to its US headquarters without sufficiently informing users about the nature and purpose of the transfers. The penalty was reduced after Apple strengthened its privacy controls, updated its policies and expanded user options for managing Siri transcripts during the investigation.

Separately, TikTok is facing preliminary charges from European Union regulators over account settings that could expose children to predators, cyberbullying and unwanted contact. The platform could face a fine of up to 6% of its global annual revenue if the allegations are upheld. Regulators said minors' accounts can be set to public, allowing content to be viewed widely, and recommended changes to default privacy settings to better protect young users.

Spain fines 23andMe more than €2 million over 2023 data breach

Spain's data protection regulator has fined 23andMe €2.4 million (about $2.7 million) for cybersecurity failures that led to a major 2023 data breach affecting 6.9 million people worldwide, including more than 2,600 people in Spain.

According to the regulator, company executives first learned about the breach after someone tried to sell stolen customer data on Reddit. Officials also said 23andMe waited 12 days before notifying Spanish authorities, delaying efforts to reduce the impact of the attack.

The investigation found that 23andMe failed to use basic security measures, including mandatory multi-factor authentication. The company also did not limit how much data could be accessed or downloaded from a single IP address, making the credential-stuffing attack easier to carry out.

The breach exposed sensitive customer information, including genetic ancestry data. Some of the stolen information was later offered for sale on the Dark Web.

23andMe initially denied that a breach had occurred. After confirming the incident, the company blamed customers for using weak or reused passwords. Earlier this month, 23andMe agreed to pay $18 million to settle claims with a coalition of 42 US state attorneys general over the breach.

ImmuniWeb Newsletter

Get Cybercrime Weekly, invitations to our events and webinars in your inbox:


Private and Confidential Your data will stay private and confidential

Portuguese wine company fined over €14,000 for GPS monitoring

A Portuguese wine company has been fined €14,790 after using a GPS tracker in a company car to monitor an employee's work performance.

Adega Moor, based near Lisbon, required a sales employee to submit daily reports about client visits. The company's manager then compared the reports with GPS data from the employee's vehicle to check if the information matched.

The company claimed the GPS was only used occasionally to verify one client visit and was not meant for regular monitoring. However, the Lisbon Court of Appeal found that the manager repeatedly checked the GPS history, making it a form of ongoing performance monitoring.

The court ruled that this practice breaks Portugal's Labour Code Article 20(1), which bans employers from using surveillance technology to monitor employees' work performance. While GPS systems can be used to protect company vehicles and property, they cannot be used to track how employees carry out their jobs.

The court upheld the fine and also said that even if the employee had agreed to the monitoring, it would still have been illegal under Portuguese law.

ImmuniWeb can help you to prevent data breaches and meet regulatory requirements.

US data broker hit with a €2M penalty over the GDPR violations

Italy's data protection authority, the Garante, has fined US data broker Lusha Systems Inc. €2 million for breaking privacy rules under the GDPR.

Lusha collects personal information such as job titles, email addresses, and phone numbers from sources including social media scraping and other data brokers. The company then sells access to the data for business and anti-fraud purposes.

The Garante found that Lusha processed the data of many people in Italy without a valid legal basis. It also said the company failed to provide clear information about how personal data was collected and used.

The authority noted that the database included information about staff working for government institutions, law enforcement, and the judiciary.

The Garante ruled that Lusha's activities fall under the GDPR, even though the company is based outside the European Union. The watchdog ordered Lusha to stop processing the personal data of people in Italy and to delete the information it had collected.

What’s next:

Talk to an Expert