News

Home Article

Google Fined €403 Million by Irish Regulator Over Location Data Privacy Violations

Ireland’s Data Protection Commission has fined Google €403 million over violations of European Union privacy rules relating to the processing of users’ location data.

Ireland’s Data Protection Commission (DPC) has imposed administrative fines totalling €403 million, around $463 million, on Google Ireland Limited following a long-running investigation into how the technology company processed location information.

The regulator announced its final decision on September 21, 2026, saying Google had breached several requirements of the European Union’s General Data Protection Regulation, or GDPR.


Three Google Features Investigated

The investigation focused on Google’s handling of location information through three features:

•    Web & App Activity
•    Location History
•    Location Accuracy

The DPC examined the processing of location data through these services between May 25, 2018 and February 4, 2020.

According to the regulator, Google failed to meet GDPR requirements relating to the lawfulness and fairness of location-data processing through Web & App Activity and Location History.

The DPC also found issues with Google’s transparency obligations across all three features, as well as its accountability obligations in relation to Location Accuracy.

The regulator additionally found that location information associated with Web & App Activity and Location History had been retained for longer than necessary.


Why Location Data Raised Privacy Concerns

Location information can reveal significant details about a person’s movements, activities and interests.

The Irish regulator said failures in transparency could mean some users were unaware that their location information was being used for purposes such as influencing advertising or inferring their interests.

The DPC said retaining location information longer than necessary could further reduce users’ control over their personal data.


Google Ordered to Comply Within Six Months

Alongside the €403 million financial penalty, the DPC has ordered Google to bring the affected location-data processing operations into compliance with GDPR requirements within six months.

The investigation was launched by the Irish regulator in February 2020 after complaints from several European consumer-rights organisations, including the European Consumer Organisation, BEUC.

Ireland acts as the lead European privacy regulator for Google and several other major technology companies because many of their European operations are headquartered in the country.


Google Says Practices Have Changed

Google said the investigation concerned historical policies and that it had significantly changed its approach to location information since 2019.

According to the company, newer privacy tools allow users to automatically delete certain personal information, store Timeline data directly on their devices and exercise greater control over how data, including location information, is used for advertising.

Google also said it now stores an estimated general area rather than a precise device location in certain circumstances when users conduct Google searches.


One of Ireland’s Largest Big Tech Fines

Reuters reported that the €403 million penalty is the fourth-largest fine imposed by Ireland’s DPC on a major technology company since GDPR enforcement began in 2018.

The Irish regulator has imposed more than €4 billion in fines on major US technology companies under the European privacy framework.

The latest ruling highlights the continuing regulatory scrutiny surrounding how major technology platforms collect, retain and use sensitive personal information such as users’ location data.
 

Comments