Monday, 21 September 2026NewsWorldBusinessTech
Latest

Google Fined €403m by Irish Regulator for Location Data Violations

Google has been fined €403 million by Ireland’s Data Protection Commission (DPC) for processing users’ location data in ways that violated the EU’s General Data Protection Regulation (GDPR). The fine, the fourth-largest imposed by the DPC since GDPR came into effect, stems from an investigation into how the tech giant handled location data through features such as web and app activity, location history, and location accuracy between May 2018 and February 2020. The DPC found that Google’s practices left users potentially unaware their data was used for targeted advertising or to infer personal interests, undermining their control over sensitive information.

Google Fined €403m by Irish Regulator for Location Data Violations

The DPC’s deputy commissioner, Graham Doyle, stated that location data—collected or processed by Google—can reveal a significant amount of information about an individual, including information that is inherently private. This includes details about health, religious beliefs, and political opinions. The regulator emphasized that Google’s retention of location data for longer than necessary exacerbated the loss of user control. The fine was imposed after complaints from seven European consumer organizations, including the European Consumer Organisation (BEUC), which cited research by the Norwegian Consumer Council alleging Google used “various tricks” to ensure users remained tracked.

Google’s Response and Changes to Data Practices

Google acknowledged the ruling but defended its practices, stating the case centered on historical policies that have since been updated. The company highlighted that since 2019, it has introduced tools to simplify location data management, including auto-delete controls that allow users to set data retention periods of three, 18, or 36 months. Additionally, Google updated its location history feature in 2023 to store timelines directly on users’ devices, reducing centralized data storage. A spokesperson noted that the company no longer stores precise location data in web and app activity and provides transparency tools for ad personalization.

Google Fined €403m by Irish Regulator for Location Data Violations
Photo: RTE

Despite these changes, the DPC ordered Google to bring its processing into compliance with GDPR within six months. The regulator also noted that Google may appeal the decision, as it is understood to be contesting legal aspects of the ruling. The fine adds to a series of penalties faced by tech giants under the DPC’s oversight, including a €1.2 billion penalty for Meta in 2023 and €530 million for TikTok in 2024. The DPC’s investigation, launched in 2020, marked the culmination of a six-year probe into Google’s data practices.

Broader Implications and Ongoing Scrutiny

The ruling underscores the DPC’s role as the lead EU regulator for major tech companies headquartered in Ireland, including Google, Meta, and Apple. It also highlights the EU’s strict enforcement of GDPR, particularly around sensitive data like location tracking. BEUC welcomed the decision but criticized the lengthy enforcement process, arguing that late enforcement can be as harmful as no enforcement at all. The organization emphasized that consumers’ fundamental rights require faster and more robust protection.

The DPC said its investigation, which began in 2020, found that Google infringed the GDPR by processing users' location data
Photo: The Irish Times

The DPC’s findings also reveal ongoing scrutiny of Google. Three other large-scale investigations into the company are at an advanced stage, though details about their focus remain unspecified. The fine serves as a warning to tech firms about the consequences of mishandling personal data, even as companies continue to refine their policies in response to regulatory pressure. For now, Google faces the challenge of aligning its practices with GDPR while navigating potential appeals and future oversight.