VMTech
Discuss a project

Irish regulator imposes €403 million fine on Google location processing

Irish regulator imposes €403 million fine on Google location processing

Ireland’s Data Protection Commission (DPC) has imposed a €403 million fine on Google for GDPR violations connected with location-data processing between May 2018 and February 2020. The decision concerns Web & App Activity, Location History and Android’s Location Accuracy feature, and the regulator has ordered Google to bring the processing into compliance within six months.

The penalty is the fourth-largest issued by the DPC. It is not yet payable: an Irish court must confirm the fine, and Google can appeal to the High Court within 28 days of receiving formal notice. The DPC has said its full decision will be published later and has not publicly identified the specific processing covered by its compliance order.

Three features, different findings

Web & App Activity is an account setting that enables Google to process activity from its sites and apps, including location data. Location History is an opt-in setting that records where signed-in users take their mobile devices, including when they are not using a Google service.

For both of those features, the DPC found breaches of GDPR requirements for lawful and fair processing and transparency. It also found that location data was retained for longer than necessary. Location Accuracy, an Android capability that supplements GPS to establish a more precise device location, is available to people with or without a Google account.

For Location Accuracy, the regulator’s findings focused on transparency and accountability. Google could not demonstrate that the processing was lawful, fair and transparent, the DPC said. Deputy Commissioner Graham Doyle said the failures could leave people unaware that their location was being used, including to influence advertising or infer interests, and could reduce their control over personal data.

Changes cited, but compliance remains unresolved

Google told the Associated Press that the case concerns historical policies that have since been updated and that its practices have changed significantly since 2019. In May 2019, it announced automatic deletion controls for Location History and Web & App Activity, allowing deletion after three or 18 months.

In June 2020, Google made 18-month automatic deletion the default for new Web & App Activity accounts and for people enabling Location History for the first time. In December 2023, it said Timeline, the Google Maps view of Location History, would keep data on users’ devices, with a three-month auto-delete default for new Location History users. The DPC has not publicly stated whether those measures satisfy its order.

The inquiry began in February 2020 after complaints from European consumer groups, including BEUC, whose member groups had submitted complaints to national authorities in November 2018. The investigated period ended on 4 February 2020, the day the inquiry was announced, making the decision more than 6.5 years in the making.

What organisations should take from the decision

The enforcement action sits alongside the wider Google security and platform context reflected in Chrome vulnerabilities and SaaS attack trends reporting on Chrome vulnerabilities and attacks affecting SaaS and DNS services, while demonstrating that governance exposure can arise from routine product telemetry as well as technical compromise.

For businesses, the practical implication is to inventory every location-data collection path, document the purpose and legal basis for each one, give users clear information, apply retention periods that can be justified, and preserve evidence that accountability obligations are being met.

#gdpr#dataprivacy#google#compliance
Open analytics
On the site 1 views
min read 4 21.09.2026
Instagram

Irish regulator imposes €403 million fine on Google location processing

Open the post on Instagram ↗