Google fined €403 million by EU privacy regulator over location data misuse

Share:
Audio Loading voice…
Google fined €403 million by EU privacy regulator over location data misuse

Synopsis

Ireland's data privacy watchdog has slapped Google with a €403 million GDPR fine — one of the largest yet — over how its Location History and Web & App Activity services collected, used, and retained user location data without adequate transparency. Google now has six months to fix its practices or face further action.

Key Takeaways

Ireland's Data Protection Commission (DPC) fined Google €403 million on 21 September for GDPR violations.
Google was found to have infringed GDPR rules on Location History , Web & App Activity , and Location Accuracy processing.
Google also retained location data for longer than permitted under data protection law.
Deputy Commissioner Graham Doyle warned users may not have known their location was used to target them with ads or infer personal interests.
Google has been ordered to bring its location data practices into compliance within six months .
The DPC said the full decision will be published separately.

Ireland's Data Protection Commission (DPC) on Monday, 21 September imposed a €403 million fine on Google, ordering the tech giant to bring its location data processing practices into compliance within six months. The ruling marks one of the most significant GDPR enforcement actions against a major US tech firm operating through its European headquarters in Dublin.

What the DPC Found

The Commission's decision — taken by Commissioners Dr Des Hogan, Dale Sunderland, and Niamh Sweeney — determined that Google breached the General Data Protection Regulation (GDPR) on multiple counts. Specifically, Google was found to have infringed GDPR rules on the lawfulness and fairness of processing location data through two of its services: Web & App Activity and Location History. The regulator also found failures relating to Location Accuracy and Google's accountability obligations to demonstrate compliance with the transparency principle.

Additionally, Google was found to have retained users' location data in both Web & App Activity and Location History for longer than permitted under data protection law.

What Is Location History and Why It Matters

'Location History' is a Google service that continuously tracks a user's whereabouts while they carry compatible mobile devices. Users must actively opt in to the service, which then processes location data to infer place visits, activities, and movement paths between locations. The DPC's concern is that this data — even when opt-in — was processed and retained in ways that stripped users of meaningful control.

Deputy Commissioner Graham Doyle stated: 'Location data is a type of personal data which is processed by way of location tracking, and includes data collected or processed by Google, which by itself or in conjunction with other information an individual's location can be inferred. Location data can bring both benefits and harms to individuals. It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private.'

Impact on Users

The DPC warned that Google's failures meant individuals may have been unaware that their location data was being used to target them with advertisements or to infer their personal interests — without their knowledge. Doyle noted: 'As a result of Google's failures in this regard, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data. The retention of users' location data for longer than necessary aggravated this loss of control.'

This is a particularly sensitive issue given that location data can, when cross-referenced with other datasets, expose an individual's home address, workplace, medical visits, religious affiliations, and personal relationships — information that is, as the DPC itself noted, inherently private.

Compliance Timeline and What Comes Next

Google has been ordered to rectify its location data processing practices within six months. The DPC said it will publish the full decision in due course. This ruling follows a broader pattern of Irish regulators — who oversee many US tech giants' EU operations due to Dublin's status as their European base — issuing major GDPR penalties. Meta and WhatsApp have faced similar enforcement in recent years. The fine adds to mounting regulatory pressure on Google globally, as data privacy enforcement tightens across the European Economic Area (EEA).

Point of View

And GDPR's consent and transparency requirements sit awkwardly against that model. The €403 million figure, while large in absolute terms, is modest relative to Google's annual revenues — the real teeth of this decision lie in the compliance order, which could force genuine changes to how Location History and Web & App Activity are designed and disclosed. Ireland's DPC has faced years of criticism for slow-walking enforcement against Big Tech; this ruling, alongside past fines on Meta and WhatsApp, signals a more assertive posture. The key question now is whether the six-month remediation window leads to substantive product changes or merely cosmetic consent-screen tweaks.
NationPress
21 Sept 2026

Frequently Asked Questions

Why was Google fined €403 million by the EU privacy regulator?
Ireland's Data Protection Commission fined Google €403 million for violating GDPR rules on how it processed and retained user location data through its Location History and Web & App Activity services. The regulator found Google failed to meet lawfulness, fairness, transparency, and accountability obligations under EU data protection law.
What is Google's Location History service?
Location History is a Google service that tracks a user's whereabouts while they carry a compatible mobile device. Users must opt in, after which the service processes data to infer place visits, activities, and movement paths — but the DPC found Google used and retained this data in ways that breached GDPR.
What must Google do following this ruling?
Google has been ordered to bring its location data processing practices into compliance within six months of the DPC's decision. The full text of the decision is yet to be published by the Commission.
How were ordinary users affected by Google's violations?
According to Deputy Commissioner Graham Doyle, users may have been unaware their location data was being used to target them with advertisements or infer personal interests. Retaining location data beyond the permissible period further eroded user control over their personal information.
Is this the first major GDPR fine against a US tech giant in Ireland?
No. Ireland's DPC has previously issued major GDPR penalties against Meta and WhatsApp, among others, since many US tech companies base their EU operations in Dublin. The Google ruling is part of a broader pattern of escalating enforcement by European data protection authorities against large technology platforms.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 1 month ago
  2. 2 months ago
  3. 2 months ago
  4. 2 months ago
  5. 2 months ago
  6. 5 months ago
  7. 1 year ago
  8. 1 year ago
Google Prefer NP
On Google