The Data Protection Commission announced a €403 million administrative fine against Google after determining the company infringed core principles of the General Data Protection Regulation in its handling of location information. According to the DPC decision, the violations spanned Web and App Activity, Location History and Location Accuracy settings over a 20-month period that began when GDPR took effect. Reuters reported that the Irish regulator, acting as lead supervisory authority for the search giant in the European Union, launched the probe in February 2020 following complaints lodged by several consumer rights groups including BEUC. The watchdog found that Google’s practices left individuals potentially unaware that their location details were being leveraged to tailor advertising or draw inferences about personal interests.
The Irish Times noted this penalty ranks as the fourth-largest imposed by the DPC since the EU privacy law entered force, behind a €1.2 billion sanction against Meta in 2023 and penalties of €530 million and €405 million against TikTok and Instagram respectively. POLITICO described the action as the first significant fine levied directly against Google by the Irish authority despite the company facing three additional inquiries. The DPC also directed Google to overhaul its data processing activities to achieve full compliance within six months. Euractiv highlighted that the extended timeline from initial complaints to final ruling has drawn criticism from privacy advocates concerned about enforcement speed.
European consumer organisations that triggered the investigation welcomed the enforcement move as a step toward stronger accountability for technology platforms. BEUC, one of the groups involved, stated that the outcome reinforces the need for genuine consent mechanisms rather than default settings that harvest sensitive data. The Guardian reported that complainants had accused Google of designing interfaces that effectively manipulated users into enabling continuous location tracking on mobile devices. Such data, when retained longer than necessary, compounds the loss of individual control according to the DPC’s analysis.
In a statement responding to the ruling, Google said the case centres around historical policies that have since been updated. The company pointed to the rollout from 2019 of industry-first auto-delete controls that let users automatically erase location data on a rolling three-month, 18-month or 36-month cycle. Google also cited new tools for disabling personalised ads entirely and consolidated transparency disclosures about its location practices. The tech giant added that these changes have made managing privacy settings simpler for its global user base.
The cumulative fines issued by the DPC now exceed €4 billion according to tallies compiled by multiple outlets covering EU data regulation. This latest penalty arrives amid broader regulatory pressure on Alphabet, whose European headquarters sit in Dublin, making Ireland the frontline supervisor for its GDPR compliance. Help Net Security detailed that the breaches included failures in demonstrating accountability for the Location Accuracy feature alongside transparency shortfalls across all three services examined. The regulator stressed that location information can expose highly private aspects of people’s lives when combined with other datasets.
Deputy Commissioner Graham Doyle said the GDPR demands that personal data processing occur in a lawful, fair and transparent manner throughout the European Economic Area. Doyle added that retention of location data beyond what was necessary had aggravated the erosion of user control in this instance. The DPC decision, issued by Commissioners Des Hogan, Dale Sunderland and Niamh Sweeney, stops short of requiring specific product changes but mandates corrective action within the stipulated timeframe. Google indicated it would study the full ruling while maintaining its focus on delivering privacy-forward tools.
ع