Ireland’s privacy regulator has fined Google €403 million over GDPR violations involving location tracking, transparency and data retention across three major services.

Ireland Fines Google €403 Million Over Location Data Processing and Privacy Failures

The420 Web Correspondent
6 Min Read

Ireland’s privacy regulator has fined Google €403 million, around ₹4,200 crore, after finding that the technology giant violated European Union privacy rules in the way it collected, used and retained users’ location information.

The Data Protection Commission said its investigation covered Google’s handling of location data between May 25, 2018 and February 4, 2020. Google has also been ordered to bring the affected processing into full compliance with the EU’s General Data Protection Regulation within six months.

The case examined three Google features: Web & App Activity, Location History and Location Accuracy.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

Regulator says users could lose control over location data

The DPC found problems with the lawfulness and fairness of Google’s processing through Web & App Activity and Location History.

It also found failures in transparency across all three services and said Google had not demonstrated compliance with GDPR requirements in relation to Location Accuracy. The regulator additionally criticised how long some location data was retained.

Location information can reveal far more than a person’s position on a map.

Over time, repeated location records may show where someone lives and works, which shops they visit, their travel routines and other aspects of daily life. Combined with other information, such data can also be used to infer interests and behaviour.

The DPC said users could have been unaware that location information was being used for purposes including influencing advertising or inferring their interests.

That lack of awareness could reduce their ability to control how their personal data was being used.

What Google’s three location settings actually do

Web & App Activity is a Google Account setting that can store activity from Google services, websites and applications. Depending on settings and usage, that information can include search, browsing and location-related data.

Location History records where compatible devices have travelled when a user has enabled the service. The information can appear through Google Maps’ Timeline feature, allowing people to look back at places they have visited and routes they have travelled.

Location Accuracy works differently.

It is an Android feature intended to improve a device’s ability to determine where it is by using information beyond GPS alone. Unlike the other two settings, it can apply to Android users even when they do not have a Google Account.

The privacy issue was therefore not simply whether Google possessed location information. European regulators examined whether people were properly informed, whether the processing had a valid legal basis and whether the data was retained longer than necessary.

Google says investigation covers older policies

Google said the investigation concerned practices from several years ago and argued that its products and privacy controls have changed significantly since then.

The company told Reuters that it has introduced clearer controls, automatic deletion features and changes designed to store less precise location information.

The DPC nevertheless concluded that the practices examined during the 2018-2020 period breached GDPR requirements.

Google must now ensure the relevant data processing complies with the regulator’s decision within six months.

The €403 million penalty is the fourth-largest fine Ireland’s privacy authority has imposed on a major technology company, according to Reuters. Since GDPR enforcement began, the Irish regulator has issued more than €4 billion in penalties against large US technology companies.

Ireland plays a major role in policing Big Tech

Ireland has become one of Europe’s most important technology regulators because many large US technology companies operate their European headquarters there.

Under GDPR’s cross-border enforcement system, Ireland’s DPC frequently acts as the lead privacy regulator for companies whose main European operations are based in the country.

That has placed companies including Google, Meta and other global platforms under repeated Irish regulatory scrutiny.

The Google case began after complaints from European consumer organisations, including BEUC, prompted the DPC to open its own inquiry in February 2020.

The penalty reflects a wider regulatory shift around digital tracking.

Location features can improve maps, recommendations and other personalised services, but regulators increasingly expect companies to explain clearly what is being collected, why it is needed and how long it will remain stored.

For users, that means privacy settings cannot be treated simply as technical switches buried inside an account menu. Regulators increasingly view meaningful understanding and control as central parts of data protection.

What this means for you

Review the location and activity controls linked to your Google Account and Android phone, including saved history and automatic deletion settings. Turning off one location feature does not necessarily mean every form of location-related processing has stopped.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected