Ireland's Data Protection Commission has imposed a €403 million penalty on Google following a six-year investigation into how the technology company processed users' location information. The regulator determined that Google had manipulated users into enabling constant mobile phone tracking and failed to obtain valid consent for using location data to target advertisements and infer personal interests.
The fine represents the fourth-largest penalty ever issued by the Irish watchdog, which holds EU-wide enforcement authority over major US technology companies headquartered in Ireland. According to reporting on the decision, the DPC found that Google's practices breached the General Data Protection Regulation on four separate counts: lawfulness, fairness, transparency and accountability.
The investigation was triggered by complaints from seven European consumer organisations, including the European Consumer Organisation (BEUC), which alleged that Google employed dark patterns and unfair design practices to push users toward enabling location-sharing features. According to those complaints, the company had systematically tracked every movement users made on their mobile devices.
What is location data and why does it matter?
Location data represents one of the most sensitive categories of personal information that technology companies collect. The DPC's investigation examined three specific Google features: Web and App Activity, Location History and Location Accuracy, scrutinising how the company processed and retained this information between 25 May 2018 and 4 February 2020.
Graham Doyle, a deputy commissioner at the DPC, explained the dual nature of location tracking:
Location data is a type of personal data which is processed by way of location tracking, and includes data collected or processed by Google, which by itself or in conjunction with other information an individual's location can be inferred. Location data can bring both benefits and harms to individuals. It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private.
The regulator's investigation revealed that location information can expose deeply personal details about users' lives. Tracking visits to places of worship can reveal religious beliefs, monitoring attendance at demonstrations can indicate political leanings, hospital visits can suggest health conditions, and visits to certain venues can infer sexual orientation. Holiday-makers have long been familiar with location-targeted advertisements, but the investigation showed Google's practices extended far beyond such obvious commercial applications.
How did Google manipulate users into sharing location data?
The investigation found that Google users could have remained entirely unaware that their location was being used to influence them with personalised advertisements or to build detailed profiles of their health status and interests. The company's practices meant individuals lost meaningful control over their personal data, particularly because Google retained location information for longer than necessary.
Doyle stated:
As a result of Google's failures in this regard, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data. The retention of users' location data for longer than necessary aggravated this loss of control.
The European Consumer Organisation characterised geolocation data as
one of the most invasive forms of consumer surveillance, highlighting the severity of the infringement. Finn Myrstad, director of digital policy at the Norwegian Consumer Council, which conducted research underpinning the complaints, emphasised the importance of informed consent:
Today marks an important milestone in the effort to protect our rights online. People must be able to understand what they are agreeing to without being deceived or manipulated into making choices they otherwise would never have made.
How does this fine compare to other penalties?
The €403 million penalty ranks as the fourth-largest fine imposed by the Irish Data Protection Commission. The regulator has previously sanctioned Meta with a €1.2 billion fine, TikTok with €530 million, and Instagram (also owned by Meta) with €405 million. The fine underscores the escalating enforcement of data protection rules against technology giants.
However, Agustín Reyna, director general of BEUC, welcomed the ruling while criticising the pace of enforcement:
The time needed to come to this conclusion is disproportionate with the seriousness of the infringement, arguing late enforcement can be as harmful as no enforcement at all.
What has Google said in response?
A Google spokesperson responded to the DPC's decision by emphasising that the practices under investigation were historical and have since been updated. The company stated:
This case centres around historical policies that have since been updated. From 2019 onwards, we've significantly evolved our practices and launched robust tools that make managing location data simple.
The company's response suggests it has already begun modifying its approach to location data handling, though the DPC's formal compliance order now mandates specific changes within a defined timeframe.
What happens next?
The DPC has ordered Google to bring its location data processing into full compliance with GDPR requirements within six months, meaning the company must implement the necessary changes by approximately March 2027. According to the Irish regulator's announcement, the decision was made by commissioners Des Hogan, Dale Sunderland and Niamh Sweeney.
Beyond this case, the DPC has three other ongoing statutory large-scale inquiries concerning Google, all of which are at an advanced stage. These investigations suggest further enforcement action against the company may be forthcoming.
Key Facts
- The €403 million fine is the fourth-largest penalty issued by Ireland's Data Protection Commission
- Google breached GDPR on four counts: lawfulness, fairness, transparency and accountability
- The investigation examined Google's practices between May 2018 and February 2020 across three features: Web and App Activity, Location History and Location Accuracy
- Google must comply with the regulator's order within six months, with a deadline of approximately March 2027
- Three additional major investigations into Google remain ongoing at the DPC






