Ireland Fines Google €403 Million Over GDPR Location Data Violations

The DPC investigation examined Google’s data processing between 25 May 2018, when the GDPR took effect, and 4 February 2020, and the €403 million penalty was described as the regulator’s fourth-highest fine since the GDPR came into force.
The inquiry followed complaints from several European consumer-rights organizations about Google’s processing of location data through the three services.
DPC deputy commissioner Graham Doyle said location data can provide major benefits to digital services but can also “reveal a significant amount of information about an individual, including information that is inherently private.”
The Irish DPC acted as the lead European supervisory authority for Google in the case, coordinating the GDPR enforcement process at European level.
The DPC said three further complaints related to Google’s location-data practices were still being processed, indicating that the €403 million decision did not conclude all related regulatory scrutiny.
Ireland's Data Protection Commission fined Google €403 million for breaking European privacy rules on location data. Yahoo Finance reported the watchdog found shortcomings in how Google disclosed that location information could be used to target ads or infer user interests. The company also kept some data longer than needed, limiting user control over sensitive personal information.
The investigation covered Google's practices from May 2018 through February 2020, when the EU's strict GDPR privacy law was in effect. KFM Radio said this is the DPC's fourth-highest fine since GDPR began. Google must fix its practices within six months, though three more complaints about the company's location data handling are still under review.
Location data reveals far more than just where someone is. Market Screener noted location information can show patterns about a person's habits, health, finances, and beliefs. The Irish DPC stressed that while location services benefit digital tools, they can "reveal a significant amount of information about an individual, including information that is inherently private." Users often don't realize how much they're exposing.
Google's violations centered on three services: "Web & App Activity," "Location History," and "Location Accuracy." Democrata reported the DPC found Google failed to clearly tell users these services would collect their location data for ad targeting. Google also didn't properly explain that location data could be used to infer interests beyond what users explicitly shared. The company stored location information longer than legally necessary.
This fine ranks among Europe's toughest privacy penalties. The investigation was launched six years ago following complaints from European consumer-rights groups about Google's location practices. The Irish DPC acted as the lead authority coordinating enforcement across all of Europe under GDPR rules. Three more complaints about Google's location data are still being processed, suggesting additional fines could follow.
Google said the case involved historical policies and that it has "significantly improved" its location-data controls since 2019. The company must now change its practices to comply with European privacy law, a shift that could affect how it operates globally.
Publishers
53
Articles
302
Reach
355