Google has been fined €403 million (£345 million) by Ireland’s Data Protection Commission (DPC) for violating the General Data Protection Regulation (GDPR), a set of European Union rules designed to protect individuals' personal data. The investigation, which began six years ago, was prompted by complaints from several European consumer rights organizations. These groups raised concerns about how Google Ireland processed users’ location data, including tracking web and app activity, location history, and the accuracy of location information between May 25, 2018, and February 4, 2020.
The DPC found that Google may have failed to ensure users were fully aware that their location data was being used to influence them with targeted advertisements and to infer their personal interests. This lack of transparency meant individuals had limited control over how their data was collected and used. The commission has given Google six months to bring its data processing practices into compliance with GDPR requirements.
This fine marks the fourth largest issued by the DPC since GDPR came into effect in 2018. Deputy Commissioner Graham Doyle emphasized that location data is considered personal data under GDPR and can reveal highly sensitive information about an individual’s movements and behaviors. He noted that Google’s practices undermined users’ ability to control their personal data, particularly because the company retained location data for longer than necessary.
In addition to this case, there are three other large-scale investigations into Google currently underway in Ireland, all of which are at an advanced stage. These probes suggest that the DPC is closely examining how major tech companies handle user data under the strict rules of the GDPR.
Google fined 403 million euros for GDPR violations related to location data processing
AI-rewritten from original reportingHow it works
googlegdprdata-protectionfineirelandlocation-data



