Google fined €403m by Irish regulator over GDPR location data breaches
The ruling forces Google to fix how it handles location data in the EU within six months, tightening scrutiny of its data practices.
Ireland’s Data Protection Commission has fined Google €403 million ($463 million) for GDPR breaches in how it handled users’ location data between May 25, 2018 and February 4, 2020. The ruling covers three features — Web & App Activity, Location History and Android’s Location Accuracy — which regulators say processed location data without meeting GDPR requirements for lawfulness, fairness, transparency and retention limits. Google has been ordered to bring its location data processing into GDPR compliance within six months. The DPC says these practices could leave users unaware their location data was used for ad targeting or profiling, and that excessive retention worsened the loss of control over personal data. Google says the case concerns older policies and that since 2019 it has changed practices and shipped tools like automatic deletion timelines and on‑device storage for Maps Timeline data.
Why it matters
This decision reinforces that EU regulators expect strict adherence to GDPR rules on how location data is collected, used and retained. Google must now adjust how key services handle this data, after findings that users could have been tracked and profiled for ads without clear awareness and that information was stored longer than needed. As Google’s lead EU regulator, Ireland’s move signals how other large platforms handling personal and location data in Europe may be policed.
Signal or noise?
Does this story matter, or is it hype? Decide before you see what everyone else thinks.