
Ireland’s Data Protection Commission (DPC) has fined Google €403 million — roughly $462 million — for unlawful processing of users’ location data, closing an inquiry that began in February 2020. The DPC serves as Google’s lead EU data regulator because the company’s European headquarters are in Dublin. The inquiry examined how Google handled location data across three features: web and app activity, location history, and location accuracy — reviewing practices that date back to May 2018, when GDPR took effect.
The violations center on transparency and accountability failures. According to the DPC, users may have been unaware that their location data was being used to serve targeted advertising or infer their interests, and the company retained location data longer than was necessary. DPC Deputy Commissioner Graham Doyle emphasized the sensitivity of the data: location information “can reveal a significant amount of information about an individual, including information that is inherently private.” In addition to the fine, Google has been ordered to bring its processing practices into compliance within six months. The ruling marks the first time the DPC has penalized Google — other major platforms such as Meta and TikTok have faced multiple large fines from the same regulator.
