Google Fined €403 Million in Ireland Over Location Data Privacy Violations

Abeerah Hashim  - Security Expert
Last updated: September 22, 2026
Share
Google Fined €403 Million by Ireland Over Location Data Processing
  • The Data Protection Commission in Ireland fined Google €403 million over location data practices examined within a two-year period.
  • The investigation covered Web & App Activity, Location History, and Location Accuracy under the GDPR.
  • Google says it has changed its privacy practices and is expected to challenge the decision.

Google has received a €403 million penalty from the Irish Data Protection Commission for the way it handled location data. The regulator stated that Google did not meet the essential privacy principles set out in European legislation.

The case deals with location practices for a period of two years, 2018-2020. The regulator claims that users could have been unaware of Google’s use of their location data for targeting ads or deducing their preferences.

The regulator of Ireland finds GDPR breaches

The Data Protection Commission, or DPC, announced the penalty on September 21 this year. It reached the decision after a six-year investigation into Google Ireland. The DPC began the inquiry in February 2020. Several European consumer groups had raised complaints about the location data practices of Google.

The investigation focused on three Google features. These included Web & App Activity, Location History, and Location Accuracy. In addition to this, the DPC reported issues regarding legality, fairness, and transparency. It also found that Google failed to meet some accountability duties.

The regulator also raised concerns about how long Google kept certain location information. It said longer retention could increase loss of control of users over their personal data. The case is under the regulation of the General Data Protection Regulation (GDPR) which mandates that organizations must use the data people fairly, legally, transparently, and responsibly.

According to the DPC, location information has the potential to disclose sensitive information about a person – it can reveal where someone lives, works, travels, or spends time. That information can also help companies infer personal interests.

Therefore, regulators treat location data as an important form of personal information. The DPC ordered Google to bring its processing into full compliance within six months. The company may also challenge the decision through the legal process.

Three Google features came under review

Web & App Activity allows Google Account users to save information from Google services. That information can include search activity, browsing details, and location data. Location History works differently. It can record the movements of a user when the feature remains enabled on a compatible device.

Google uses Location History to build information about places people visit. It can also show journeys through the Timeline feature in Google Maps. The third feature, Location Accuracy, helps Android devices determine a more precise position. It can use several signals instead of relying only on GPS.

The DPC examined how these features handled location information during the investigation period. It found that Google did not meet GDPR standards in several areas. The regulator also said users could have lacked a clear understanding of how their information worked. This issue affected their ability to control their personal data.

The findings do not mean every Google user had their location secretly tracked. Instead, they concern how Google processed location information through specific settings. The investigation also focused on information that could help influence advertising.

The DPC said users might not have understood this use. Furthermore, the regulator found concerns around the retention of location data. Keeping such information beyond necessary periods can increase privacy risks.

Google says its practices have changed 

Google has argued that the investigation concerns historical practices. The company said it has made major changes to its location data systems since 2019. Those changes include stronger controls for managing location information. Google has also introduced automatic deletion options for some types of data.

The company has added tools that give users more control over advertising. It has also made changes intended to provide clearer information about data use. However, those later changes did not remove the findings of the regulator about the earlier period. The DPC based its decision on practices between May 2018 and February 2020.

Google is expected to appeal the ruling, according to reports. The company has indicated that the case raises legal questions that it wants clarified. The €403 million penalty also ranks among the DPC’s largest fines. It represents another major enforcement action against a major technology company under European privacy rules.

The DPC has imposed several large penalties against major technology firms since GDPR enforcement began. Ireland plays an important role because many large technology companies maintain European operations there.

The fine also shows how regulators can examine long-running data practices. Businesses should take into account laws protecting privacy when they collect, utilize, and save the personal data of individuals.

What the decision means for users

The case highlights the amount of information that location services can generate. The location data can tell you much more than a single point on the map. Regular collections of this data can show your habits and places a person often visits as well. Those patterns can help build a detailed picture of an individual’s activities.

For users, privacy settings remain an important part of controlling location information. People can review which Google services collect location data through their account settings. They can also check Location History and Web & App Activity settings. Automatic deletion tools can help limit how long some information remains available.

However, privacy controls cannot change the DPC’s findings about the earlier period. The regulator has already concluded that Google breached GDPR requirements during that period. The decision also reinforces a wider privacy principle.

Other European regulators have also taken action against companies over their handling of personal information, including Italy’s €2.2 million-plus fine against data broker Lusha. Businesses must clarify how they collect and utilize personal information; they must obtain lawful grounds to process such data.

Clear choices can help users understand what they allow companies to collect. For Google, the next stage will involve compliance and any appeal. The DPC has given the company six months to address the required changes. The case therefore remains significant beyond the financial penalty. It shows that regulators can scrutinize how location data supports advertising and other digital services.

Share this article

About the Author

Abeerah Hashim

Abeerah Hashim

Security Expert

Abeerah is a passionate technology blogger and cybersecurity enthusiast. She yearns to know everything about the latest technology developments. Specifically, she’s crazy about the three C’s; computing, cybersecurity, and communication. When she is not writing, she’s reading about the tech world.

More from Abeerah Hashim

Comments

No comments.