“Location data can bring both benefits and harms to individuals. It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private,” Deputy Commissioner Graham Doyle said.
Irish Data Protection Commission issues a €403m fine
The Irish Data Protection Commission (DPC) has fined Google €403m ($460m) for violating the European Union’s General Data Protection Regulation (GDPR) in how it processed users’ location data. The penalty follows a formal inquiry that opened in February 2020 and examined Google’s handling of location information from the GDPR effective date of 25 May 2018 through 4 February 2020.
Three Google features were the focus of the inquiry
The DPC’s investigation concentrated on Google’s processing of location data in three specific features: Web & App Activity, Location History and Location Accuracy. The Commission said that users of services such as Google Maps and Android’s location accuracy features could have been unaware their location was being used to influence them with ads or to infer their interests, raising the possibility of a loss of control over personal data.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadFour GDPR breaches the DPC identified
The DPC concluded that Google breached the GDPR in four distinct ways during the period under review:
- The lawfulness and fairness of its processing of location data in Web & App Activity and Location History;
- Failure to meet accountability obligations by being unable to demonstrate compliance with the lawfulness, fairness and transparency principle regarding Location Accuracy;
- Breaches of transparency obligations in respect of all three features; and
- Retention of location data in Web & App Activity and Location History for longer than necessary.
The DPC’s orders and Google’s response
Alongside the fine, the DPC ordered Google to bring its processing approach into compliance within six months. The DPC highlighted the “highly sensitive nature of location data” and the “potentially serious implications” when an individual’s location can be inferred.
A Google spokesperson responded to the judgement, saying: “This case centers around historical policies that have since been updated. From 2019 onwards, we’ve significantly evolved our practices and launched robust tools that make managing location data simple.” The company did not dispute the existence of the earlier policies referenced by the inquiry in the text provided.
What this means for end users, regulators, and Google
- End users: The DPC framed the issue as one of control and awareness — users of Google Maps and Android location features may have had their locations used for advertising and interest inference without clear transparency, according to the Commission’s findings.
- Regulators: The DPC used the GDPR’s accountability, transparency and retention rules as the basis for its penalties, and it has set a six‑month compliance deadline. That timetable creates a concrete enforcement step other regulators can reference when assessing remedial measures tied to historic processing.
- Google: The company acknowledged the issues as tied to “historical policies” and pointed to changes implemented from 2019 onward. The DPC’s decision and the six‑month remediation requirement place a regulatory demand on Google to demonstrate that those changes sufficiently address the specific GDPR breaches identified for the 2018–2020 period.
The fine follows a November 2022 settlement in the United States, in which Google agreed to pay $391.5m to resolve a lawsuit alleging it harvested location data without the knowledge of most consumers. Together, those outcomes underline that the handling and retention of location information has remained a subject of legal and regulatory scrutiny across jurisdictions.
The DPC’s ruling squarely ties its sanction to a defined window — 25 May 2018 through 4 February 2020 — while Google points to changes made from 2019 onwards. The DPC has given Google six months to align its processing; how those timelines and reforms map onto the Commission’s findings will determine whether the company satisfies the order and avoids further enforcement steps.
Source: Infosecurity Magazine — Google Hit with €403m GDPR Fine Over Location Data Practices




