Google fined €403 million by EU privacy regulator over location data misuse
Synopsis
Key Takeaways
Ireland's Data Protection Commission (DPC) on Monday, 21 September imposed a €403 million fine on Google, ordering the tech giant to bring its location data processing practices into compliance within six months. The ruling marks one of the most significant GDPR enforcement actions against a major US tech firm operating through its European headquarters in Dublin.
What the DPC Found
The Commission's decision — taken by Commissioners Dr Des Hogan, Dale Sunderland, and Niamh Sweeney — determined that Google breached the General Data Protection Regulation (GDPR) on multiple counts. Specifically, Google was found to have infringed GDPR rules on the lawfulness and fairness of processing location data through two of its services: Web & App Activity and Location History. The regulator also found failures relating to Location Accuracy and Google's accountability obligations to demonstrate compliance with the transparency principle.
Additionally, Google was found to have retained users' location data in both Web & App Activity and Location History for longer than permitted under data protection law.
What Is Location History and Why It Matters
'Location History' is a Google service that continuously tracks a user's whereabouts while they carry compatible mobile devices. Users must actively opt in to the service, which then processes location data to infer place visits, activities, and movement paths between locations. The DPC's concern is that this data — even when opt-in — was processed and retained in ways that stripped users of meaningful control.
Deputy Commissioner Graham Doyle stated: 'Location data is a type of personal data which is processed by way of location tracking, and includes data collected or processed by Google, which by itself or in conjunction with other information an individual's location can be inferred. Location data can bring both benefits and harms to individuals. It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private.'
Impact on Users
The DPC warned that Google's failures meant individuals may have been unaware that their location data was being used to target them with advertisements or to infer their personal interests — without their knowledge. Doyle noted: 'As a result of Google's failures in this regard, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data. The retention of users' location data for longer than necessary aggravated this loss of control.'
This is a particularly sensitive issue given that location data can, when cross-referenced with other datasets, expose an individual's home address, workplace, medical visits, religious affiliations, and personal relationships — information that is, as the DPC itself noted, inherently private.
Compliance Timeline and What Comes Next
Google has been ordered to rectify its location data processing practices within six months. The DPC said it will publish the full decision in due course. This ruling follows a broader pattern of Irish regulators — who oversee many US tech giants' EU operations due to Dublin's status as their European base — issuing major GDPR penalties. Meta and WhatsApp have faced similar enforcement in recent years. The fine adds to mounting regulatory pressure on Google globally, as data privacy enforcement tightens across the European Economic Area (EEA).