Google has been fined €403m by the Republic of Ireland’s Data Protection Commission over failures in processing location data, according to an enforcement decision announced by the regulatory body. According to the Data Protection Commission, the penalty addresses findings that users could lose control over personal data and remain unaware that location tracking influenced targeted advertising or inferred personal interests between May 2018 and February 2020.
Regulatory Findings and GDPR Infringements
According to the Data Protection Commission, the inquiry found that Google processed location data in a manner that violated the requirement for lawful, fair, and transparent handling under the General Data Protection Regulation. The investigation focused on three core features: Web & App Activity, Location History, and Location Accuracy across services like the Google search engine, Google Maps, and Android location settings.
According to DPC Deputy Commissioner Graham Doyle, location data can reveal inherently private details about an individual. Doyle stated that retaining users’ location data for longer than necessary aggravated this loss of control, leaving people unaware of how their movements were tracked to influence them with ads or to infer their interests.
Investigation Origins and Timeline
According to the Data Protection Commission, the inquiry was launched in February 2020 after the agency received complaints from several European consumer rights organizations regarding Google’s data processing practices. The formal decision was issued by the Commissioners for Data Protection, Dr Des Hogan, Dale Sunderland, and Niamh Sweeney.
The €403m penalty ranks among the largest of its kind imposed by the Irish data watchdog authority. Alongside the financial sanction, the Data Protection Commission ordered Google to bring its data processing operations into full compliance with European privacy rules within a six-month window.
Did you know? The General Data Protection Regulation (GDPR) came into effect on May 25, 2018, establishing strict privacy and security standards across the European Union that require all personal data handling to be transparent and fair.
Google’s Response and Historical Policy Changes
According to a statement issued by Google, the enforcement case centers around historical policies that the tech company has since updated. A company spokesperson noted that Google has significantly evolved its practices and launched robust tools for managing location data since 2019.
According to Google, these implemented changes include automated data deletion settings, improved ad management controls, and greater transparency regarding how user data is utilized. It is understood that Google will appeal the ruling focused on legal issues that require clarification beyond this case.
Frequently Asked Questions
Why was Google fined €403m?
According to the Data Protection Commission, the fine was issued because Google failed to process location data in a lawful, fair, and transparent manner under GDPR guidelines.

What services were included in the investigation?
According to regulatory findings, the inquiry examined location settings across Google Maps, the Google search engine, and Android location accuracy features between May 2018 and February 2020.
What must Google do next?
According to the regulatory order, Google must bring its data processing practices into compliance with GDPR requirements within six months.
Take Action: Want to stay informed on the latest data privacy enforcement actions and tech regulations? Subscribe to our newsletter or explore our archive for more breaking coverage.