Today’s Topics:

  • Google’s €403 Million Fine Shows the Cost of Losing Control of Location Data
  • CMMC Phase II Is Paused, but Defense Contractors Still Have Work to Do
  • How can Netizen help?

Google’s €403 Million Fine Shows the Cost of Losing Control of Location Data

Sankt-Petersburg, Russia, November 8, 2017: A woman’s hand is touching screen on tablet computer iPad Pro at night for searching on Google search engine. Google is the most popular Internet search engine in the world. Photo taken at company office.

On September 21, Ireland’s Data Protection Commission fined Google €403 million over its handling of location data, closing an inquiry that examined several of the company’s most familiar location-related features. The regulator found violations of the European Union’s General Data Protection Regulation connected to Web & App Activity, Location History, and Location Accuracy, covering data processing between May 25, 2018, when the GDPR became applicable, and February 4, 2020. Google must bring the affected processing into compliance within six months.

The size of the penalty draws attention, but the findings behind it are more relevant for organizations collecting sensitive telemetry. The DPC did not identify a single isolated privacy failure. It found issues involving lawfulness and fairness in Web & App Activity and Location History, failures to demonstrate compliance for Location Accuracy, transparency problems affecting all three features, and excessive retention involving Web & App Activity and Location History. Those findings reach several separate parts of the GDPR rather than treating location tracking as one narrowly defined consent problem.

Location information carries particular risk since individual data points can become much more revealing once they are combined over time. A location service can identify places a user visits, routes traveled, daily habits, and recurring patterns. In its decision announcement, the DPC said location data can reveal information that is inherently private and warned that users could have been unaware their location information was being used to influence advertising or infer interests. The regulator also found that retaining location information longer than necessary increased the loss of control experienced by users.

The three services examined by regulators also operated differently. Web & App Activity can store activity from Google services, including searches, browsing activity, and location-related information. Location History, which users opt into, has been used to build a private Timeline showing places visited and paths traveled. Location Accuracy is an Android feature used to improve device positioning beyond GPS alone and can operate for Android users regardless of whether they hold a Google Account. The DPC’s findings show why privacy reviews cannot stop at the most visible location setting in a product. Location information can be generated, retained, or inferred through several connected features.

Google disputes the relevance of the practices examined to its current products. The company told Reuters that the case concerns older policies and said it has made major changes since the period covered by the investigation. Google pointed to stronger location controls, automatic deletion features, and changes intended to store less precise location information. Those changes do not erase the regulator’s findings for the 2018-to-2020 period, but they matter when assessing how closely the enforcement action reflects Google’s current systems.

For other companies, the case shows that giving users a setting or toggle does not settle the compliance question. Regulators can examine what information a feature collects, the legal basis for processing it, what users were told, how long the information remained available, and whether the organization can demonstrate that its practices complied with the law. Accountability matters alongside technical controls. An organization may need evidence explaining why information was collected, how its processing was justified, how users were informed, and when the information was deleted.

Retention deserves particular attention. Organizations often focus privacy programs on collection and consent, then leave historical data in storage long after its immediate operational purpose has passed. Location records make that approach especially risky. A single coordinate may reveal little. Months or years of coordinates can describe patterns that were never explicitly provided by the person whose device generated them.

The decision also illustrates how old data practices can create current regulatory exposure. The DPC opened its inquiry in February 2020 after complaints from European consumer organizations, yet the final €403 million decision arrived more than six years later. Systems, interfaces, privacy controls, and internal policies can all change during an investigation, but organizations may still have to account for how personal information was handled years earlier.


CMMC Phase II Is Paused, but Defense Contractors Still Have Work to Do

The Department of War suspended Phase II of the Cybersecurity Maturity Model Certification program on July 13, halting a transition that had been scheduled to begin November 10, 2026. Phase II was expected to expand the use of Level 2 assessments conducted by Certified Third-Party Assessment Organizations, making independent certification a much larger part of the contracting process. The department instead opened a review of the program focused on cost, scalability, participation by smaller companies, and the burden placed on the defense industrial base.

The suspension is easy to misread as a broader retreat from CMMC. It is not. Current DoW guidance says implementation is paused in Phase I, and Phase I self-assessment requirements remain in effect. Companies handling Federal Contract Information can still face Level 1 requirements based on the 15 safeguards in FAR 52.204-21. Contractors handling Controlled Unclassified Information can still face Level 2 self-assessment requirements tied to the 110 controls in NIST SP 800-171 Revision 2.

For Level 1, organizations perform an annual self-assessment and submit the result to the Supplier Performance Risk System. Level 2 self-assessments remain valid for three years, paired with an annual affirmation of compliance. Limited Plans of Action and Milestones remain available for Level 2 self-assessments under the CMMC rules, with required closeout procedures. The current DoW guidance states plainly that pausing CMMC implementation in Phase I does not eliminate contractor obligations under DFARS 252.204-7012.

That distinction matters for companies that had been preparing for a C3PAO assessment. The external certification deadline may no longer be approaching on the original November 2026 schedule, but the security controls behind the program did not disappear. Contractors that store, process, or transmit CUI still need to know where that information resides, which systems fall inside the assessment boundary, which NIST SP 800-171 controls apply, and whether their documented assessment results match their actual security posture.

The department created a CMMC Reform Task Force as part of the suspension and announced a 60-day review of the program. The department said the review would examine ways to reduce barriers for small, medium-sized, and nontraditional defense businesses and replace unnecessary compliance burden with cybersecurity measures that can scale across the industrial base. Recent material published through the DoW CIO site indicates that officials have continued evaluating public and industry input. One recurring issue identified through listening sessions and responses has been inconsistent government designation and marking of CUI, which can make it harder for contractors to determine what information actually falls within protected environments.

That issue cuts directly into one of CMMC’s hardest operational problems. A contractor cannot accurately scope an assessment if it cannot reliably identify the information that creates the scope in the first place. Poor CUI marking can cause companies to protect systems that may not need to be in scope, increasing cost, or exclude systems that contain information requiring protection. For smaller suppliers, either mistake can be expensive.

The Phase II suspension also changes the immediate role of third-party certification. Phase II had been scheduled to make Level 2 certification assessments applicable to more solicitations beginning November 10. Under the current pause, DoW says the program may require only self-assessments at Levels 1 and 2 during Phase I. NIST SP 800-171 Revision 2 compliance can still be checked through contractor self-assessments and selected government-led assessments.

Contractors also need to separate CMMC from the contractual cybersecurity clauses that preceded it. DFARS 252.204-7012 already requires applicable contractors handling covered defense information to provide adequate security and implement NIST SP 800-171 requirements. CMMC created a structured assessment and verification model around those requirements. Pausing part of that verification model does not erase the underlying contractual duty.

The current period may give contractors more time before third-party certification becomes broadly required, but it also creates uncertainty about what the revised program will look like. The original CMMC implementation schedule called for Phase II in November 2026, Phase III in November 2027, and full implementation in November 2028. The Phase II suspension disrupted that schedule, and the department has not published a replacement Phase II date on its current CMMC pages.

That makes the pause a poor reason to abandon work already underway. Asset inventories, CUI data-flow mapping, access controls, multifactor authentication, logging, incident-response procedures, configuration management, supplier controls, security plans, and accurate SPRS submissions retain value under the requirements that remain active. They also put contractors in a better position if independent certification returns under a revised structure.

CMMC reform may change how compliance is verified and which organizations require third-party assessment, but the current federal position still expects defense contractors to protect CUI and document that protection. For organizations in the defense industrial base, the question has shifted from preparing for one fixed November 2026 deadline to maintaining defensible security practices during a period in which the certification model itself is being reconsidered.


How Can Netizen Help?

Founded in 2013, Netizen is an award-winning technology firm that develops and leverages cutting-edge solutions to create a more secure, integrated, and automated digital environment for government, defense, and commercial clients worldwide. Our innovative solutions transform complex cybersecurity and technology challenges into strategic advantages by delivering mission-critical capabilities that safeguard and optimize clients’ digital infrastructure. One example of this is our popular “CISO-as-a-Service” offering that enables organizations of any size to access executive level cybersecurity expertise at a fraction of the cost of hiring internally. 

Netizen also operates a state-of-the-art 24x7x365 Security Operations Center (SOC) that delivers comprehensive cybersecurity monitoring solutions for defense, government, and commercial clients. Our service portfolio includes cybersecurity assessments and advisory, hosted SIEM and EDR/XDR solutions, software assurance, penetration testing, cybersecurity engineering, and compliance audit support. We specialize in serving organizations that operate within some of the world’s most highly sensitive and tightly regulated environments where unwavering security, strict compliance, technical excellence, and operational maturity are non-negotiable requirements. Our proven track record in these domains positions us as the premier trusted partner for organizations where technology reliability and security cannot be compromised.

Netizen holds ISO 27001, ISO 9001, ISO 20000-1, and CMMI Level III SVC registrations demonstrating the maturity of our operations. We are a proud Service-Disabled Veteran-Owned Small Business (SDVOSB) certified by U.S. Small Business Administration (SBA) that has been named multiple times to the Inc. 5000 and Vet 100 lists of the most successful and fastest-growing private companies in the nation. Netizen has also been named a national “Best Workplace” by Inc. Magazine, a multiple awardee of the U.S. Department of Labor HIRE Vets Platinum Medallion for veteran hiring and retention, the Lehigh Valley Business of the Year and Veteran-Owned Business of the Year, and the recipient of dozens of other awards and accolades for innovation, community support, working environment, and growth.

Looking for expert guidance to secure, automate, and streamline your IT infrastructure and operations? Start the conversation today.


Posted in , , , ,

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.