Bbc iconBbcSep 21, 2026 ~2 min source read

Google fined €403m by Ireland's Data Protection Commission over location-data practices

Ireland's Data Protection Commission found Google's handling of location information in three account features breached the GDPR for processing that ran from May 25, 2018 to February 4, 2020; the company has six months to comply.

Google hit with €403m fine by Irish data watchdog over GDPR violations

Share this story

Send the public story page.

Useful takeaways from this story.

The DPC imposed a €403 million administrative fine after finding Google processed location data unlawfully, unfairly and non-transparently.

The inquiry covered three features: Web & App Activity, Location History and Location Accuracy between 25 May 2018 and 4 February 2020.

The DPC said retention of location data for longer than necessary aggravated users' loss of control over their personal data.

Google processed location data in a manner that was not "lawful", "fair" or "transparent". It said location data can reveal inherently private information about an individual, and that as a result of Google's failures "individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data." The DPC also said retention of users' location data for longer than necessary aggravated this loss of control.

Alongside the fine, the DPC ordered Google to bring its data processing into compliance within six months. The decision is one of the larger penalties the Irish watchdog has imposed, and the DPC said a fuller decision will be published later.

Google listed measures it says it introduced since, including "industry-first auto-delete controls" that allow users to set automatic roll-off periods for data (three, 18 or 36 months), "simple ads management" to turn off personalized ads, and "increased transparency" through consolidated information about location data practices and account settings.

What this covers and what it does not

The DPC's findings relate specifically to the three named features and the defined period. The watchdog described the scope as processing of location data linked to those features and concluded that the processing breached the GDPR's requirements on lawfulness, fairness and transparency, and on data minimisation/retention.

Practical implications for users and companies

  • Users: The decision highlights that location settings and background processing can lead to broader use of location data than people expect, including for ad targeting. Where available, account-level controls such as auto-delete and ad personalization settings change what data providers can retain and use.
  • Companies: Regulators will scrutinize how location data is presented to users, the lawful basis for processing it, how long it is kept, and whether users can reasonably understand and control that processing.

Google. The full DPC decision will provide additional detail on specific breaches and the measures required. Other national and EU-level scrutiny of large tech companies' data practices continues to be active.

More context around this story.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app