Google Fined €403M Over Location Data, Plus 3 Stories
Google’s €403 million location-data fine is about more than one setting
Google has been hit with a €403 million privacy fine over the way it handled location data, and the important part isn’t really the number. Ireland’s Data Protection Commission says Google’s Web & App Activity, Location History and Location Accuracy systems violated different parts of the GDPR between May 2018 and February 2020. The regulator found problems with lawfulness, fairness, transparency, accountability and how long some location data was retained.
Those three names are worth slowing down for, because “Google location tracking” makes this sound like one giant on/off switch. It wasn’t. Web & App Activity can save activity from Google services and can include location-related information. Location History was the account setting that built a record of places a user had been. Location Accuracy is the Android system that can combine signals such as GPS, Wi-Fi, mobile networks and sensors to improve a device’s estimate of where it is. Different systems, different purposes, and apparently different compliance problems.
The DPC’s argument is also more serious than “Google collected too much data.” Location is revealing. Over time, where somebody goes can expose their workplace, home, doctor, religious services, relationships, political activity and quite a bit more. The regulator specifically says people could have been unaware their location was being used to influence advertising or infer interests. That’s the problem with data that looks mundane one point at a time: a long enough trail stops being mundane.
Now, this is where the date matters. The investigation examined practices from 2018 to 2020, not Google’s exact controls in September 2026. Google says the case is about historical policies and points to changes since 2019, including automatic deletion, on-device Timeline storage and controls over how location data is used for advertising. Ireland has ordered Google to bring the processing covered by the decision into compliance within six months.
So I wouldn’t read this as “your phone is secretly doing exactly what it did in 2019.” I would read it as a good excuse to review the location and activity controls in your Google account and decide whether they match what you actually want. Settings nobody revisits for seven years aren’t much of a choice.
The rules around technology matter too
Platforms, privacy, speech, competition, surveillance, copyright, and regulation increasingly determine what technology companies can build and what the rest of us have to live with. Browse more Raymond Tec News for practical coverage of technology policy and digital rights.
Veeam and Zyxel flaws are being actively exploited
Two separate security problems moved from “patch when you can” into “people are actually using this.”
Arctic Wolf says it is observing active exploitation of CVE-2026-32996 in Veeam Agent for Microsoft Windows. This is a local privilege-escalation flaw, which means an attacker already needs some access to the machine. That’s an important limitation. It also doesn’t make the bug harmless.
Veeam’s backup service runs with very high privileges. The flaw involves the way that service handles elevated client sessions over a local gRPC named pipe. In simplified terms, the service can associate administrator-level authority with a session identifier that isn’t properly tied to the user who requested it. That identifier also ends up in a log readable by ordinary users. An attacker with low-level local access can reuse it and execute commands as Windows SYSTEM.
That’s basically the operating-system equivalent of turning a foothold into the master key.
Veeam says the problem is fixed beginning with Backup & Replication 13.0.2.29, which updates the Windows agent to 13.0.3.1220. Arctic Wolf says there isn’t a reliable vendor-supported workaround, so affected systems should be upgraded, particularly shared machines and systems used by administrators, backup operators or support staff.
CISA has also added Zyxel’s CVE-2026-7273 to its Known Exploited Vulnerabilities catalog. This one affects GS1900-series switches and can allow an unauthenticated attacker to execute operating-system commands through a stack buffer overflow in a CGI program.
But here’s another qualifier that matters: Zyxel describes the attacker as LAN-based. This isn’t the same thing as saying any random person on the internet can point at every GS1900 switch and own it. An attacker needs network access to the management path first. Once they’re there, though, unauthenticated command execution on a switch is not the sort of feature anyone ordered.
Zyxel has published fixed firmware for supported GS1900 models. If you manage one, check the exact model and firmware against Zyxel’s advisory and patch it. If you run Veeam Agent for Windows, check that too. The common lesson is pretty boring: exploited vulnerabilities should outrank the theoretical ones in the patch queue.
Technical discovery & auditing
The public page doesn’t tell you much about the machinery behind it. Raymond Tec audits inherited and long-running projects to uncover the plugins, integrations, data, dependencies, and old decisions that determine what the next change will really involve.
The FAA has started using AI to predict air-traffic congestion
The FAA has begun using its new SMART system around Washington, D.C., which is a much better example of useful AI than putting a chatbot in something because apparently every piece of software now requires one.
SMART stands for Strategic Management of Airspace, Routes, and Trajectories. It continuously analyzes airline schedules, weather, airport capacity, airspace conditions and operating constraints to predict congestion and potential conflicts before flights depart. The FAA’s older problem isn’t a lack of data; it’s that a lot of the data controllers and traffic managers need lives in separate systems, screens and spreadsheets.
This is decision support, not an autonomous air-traffic controller. Humans still make the airspace decisions. The software is supposed to give them a better shared picture early enough to do something useful with it instead of reacting after a bottleneck has already propagated across several airports.
The FAA awarded Air Space Intelligence a 12-year contract worth up to $875 million for SMART and a broader Flow Management Data & Services modernization effort. The Washington-area rollout is the beginning, with expansion planned elsewhere.
Could predictive software reduce delays? Sure. Weather will continue to be weather, runways will still close, airplanes will still break and human beings will continue finding exciting new ways to make schedules impossible. But predicting a capacity problem before 40 aircraft are already pointed at it is a considerably more plausible use of AI than asking a language model to improvise an answer after the fact.
Turning on AI is the easy part
Deciding what an AI tool should be allowed to see, who should use it, what work it should perform, and what happens when it gets something wrong is the more interesting problem. Raymond Tec helps businesses connect and automate the tools they actually use without treating every new feature like a button that obviously needs to be switched on.
Australia is deciding what AI companies owe creators
OpenAI and Anthropic are asking Australia to loosen its position on copyrighted material used to train AI models. The Australian government has already ruled out a broad copyright exemption. In submissions to a parliamentary AI inquiry, the companies are now arguing for narrower alternatives.
Anthropic says it would consider a conditional approval model in which AI training could be allowed in exchange for investment or other conditions supporting Australian creators and cultural work. OpenAI is arguing for a copyright framework that lets models learn from publicly available information while giving rightsholders opportunities to collaborate.
You can probably spot the commercial incentive without my help. Both companies want access to training material, and both are also making or supporting major AI-infrastructure investments in Australia. Creators, publishers and other rightsholders don’t want “we’re investing here” to become a substitute for consent or compensation.
Still, I think the useful part of this debate is that it gets us past the lazy version where one side says all training is theft and the other says anything publicly reachable on the internet is automatically fair game. Copyright law was not designed around systems that can ingest gigantic portions of human culture and use them to build commercial models. Pretending the old rules map perfectly onto that process doesn’t make the conflict disappear.
Australia’s Joint Select Committee on Artificial Intelligence is specifically examining the interaction between AI and copyright, including the use of Australian creative, cultural and media content in model training. Its final report is due November 30.
Whatever Australia eventually decides, the tradeoff is becoming clearer. Governments want AI investment, infrastructure and productivity gains. Creators want control over and compensation for the work that helps make those systems useful. AI companies want enough legal certainty to keep training models without negotiating one work at a time.
There probably isn’t a version of that bargain where everybody gets everything they want. That’s usually a sign we’re finally discussing the real problem.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- Irish Data Protection Commission: Google location-data decision
- Reuters: Irish regulator fines Google €403 million over location data
- Arctic Wolf: Active exploitation of CVE-2026-32996
- Veeam: Vulnerabilities resolved in Backup & Replication 13.0.2
- Zyxel: CVE-2026-7273 security advisory
- The Hacker News: Zyxel and Veeam flaws under active exploitation
- FAA: SMART and FMDS air-traffic modernization
- Reuters: FAA begins use of AI tool to reduce flight delays
- Reuters: Anthropic and OpenAI call for Australia to relax AI-training restrictions
- Parliament of Australia: Joint Select Committee on Artificial Intelligence
