Skip to main content
Advertisement

Google fined €403m by Irish regulator for unlawful location data handling

Ireland's Data Protection Commission has fined Google €403m for unlawful handling of location data, finding the company breached GDPR transparency and fairness requirements. Google must comply within six months.

By The UK Pulse Editorial Team··5 min read·How we work
The word 'Google' is stuck to a plain wooden surface, the letters in simple font and in block colours blue, red, yellow and green.

Google has been hit with a €403m (£345m) penalty by the Republic of Ireland's Data Protection Commission (DPC) over its management of user location data, marking one of the largest sanctions ever imposed by the Irish watchdog. The enforcement action concluded a six-year investigation that began in February 2020 after complaints from European consumer rights groups including BEUC, and found that the technology company had processed personal data in ways that violated fundamental data protection principles.

On Monday, the DPC announced that its inquiry had identified breaches of the General Data Protection Regulation (GDPR), which took effect on 25 May 2018. The investigation specifically examined how Google handled location information through three features—Web & App Activity, Location History and Location Accuracy—during the period from 25 May 2018 to 4 February 2020. According to reporting on the decision, the DPC found Google's practices breached GDPR on four separate counts: lawfulness, fairness, transparency and accountability.

The commissioners who reached the decision—Des Hogan, Dale Sunderland and Niamh Sweeney—determined that Google's conduct had infringed the regulation's core requirements. DPC deputy commissioner Graham Doyle explained the significance of the violation in a statement released on Monday:

The GDPR provides a high level of protection of personal data throughout the European Economic Area, and requires that the processing of personal data must be carried out in a lawful, fair and transparent manner.

What is location data and why does it matter?

Location data encompasses any information that can be used to determine or infer where a person is situated. Graham Doyle emphasised that such data carries particular sensitivity, noting it can

reveal a significant amount of information about an individual, including information that is inherently private
. The DPC's investigation revealed that users could have remained unaware their location was being processed to personalise advertisements or infer their interests, and that they had lost meaningful control over their personal information.

According to accounts of the investigation, consumer complaints had alleged that Google employed dark patterns and unfair practices designed to encourage users to enable location-sharing capabilities. The extended retention of location data beyond what was necessary compounded this loss of control, the DPC found, as users could not easily understand or manage how long their information was being stored.

Advertisement

What specific violations did the DPC identify?

The regulator's investigation centred on Google's data processing practices rather than the act of collection alone. The DPC examined how Google processed and retained location data across the three named features, determining that the company had failed to meet GDPR's transparency requirements. Users were not given sufficiently clear information about what data was being collected, how it would be used, or how long it would be kept.

Doyle stated that the consequences of Google's failures were substantial:

As a result of Google's failures... individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data
. He added that
the retention of users' location data for longer than necessary aggravated this loss of control
.

How has Google responded to the fine?

In a statement, Google acknowledged that the case concerned historical policies that have since undergone substantial revision. The company stated:

This case centres around historical policies that have since been updated. From 2019 onwards, we've significantly evolved our practices and launched robust tools that make managing location data simple.

Google highlighted several measures it says it has introduced to strengthen data protection. These include what the company describes as

industry-first auto-delete controls
, which allow users to
set your account to automatically delete your data on a rolling three, 18, or 36-month basis
. The company has also implemented
simple ads management
, enabling users to
turn off personalized ads entirely
, and expanded
increased transparency
through
consolidated detailed information about our location data practices and account settings
.

What must Google do now?

In addition to paying the €403m fine, Google has been ordered to bring its data processing practices into full compliance with GDPR requirements within six months. This compliance deadline means the company must implement the necessary changes by approximately March 2027. The enforcement order represents a significant constraint on how Google can continue to collect, process and retain location data from users in the European Economic Area.

This penalty arrives amid a broader pattern of substantial fines against major technology companies by European regulators. Earlier in 2026, Google was fined €890m by the EU under the Digital Markets Act for allegedly favouring its own apps and services over rivals, and Europe's top court upheld a €4.1bn fine against Google for using Android to block competitors, marking the largest penalty ever imposed by the European Commission on the technology giant.

Key Facts

  • The €403m fine concerns Google's handling of location data through Web & App Activity, Location History and Location Accuracy features between May 2018 and February 2020
  • The DPC found Google breached GDPR on four counts: lawfulness, fairness, transparency and accountability
  • Google must bring its data processing into compliance within six months, with a deadline of approximately March 2027
  • The investigation was initiated in February 2020 following complaints from European consumer rights organisations
  • This is one of several major fines Google has faced from European regulators in 2026 alone

This article was sourced from bbc

Advertisement

Related News