Morning Edition ·
Regulation DUBLIN

Ireland Fines Google $463 Million Over Years of Location-Data Tracking

The country's privacy regulator found Google unlawfully processed users' location history for nearly two years, the latest in a string of EU penalties against the company's data practices.

Ireland Fines Google $463 Million Over Years of Location-Data Tracking
European Union flags fly outside a building in Brussels. Ireland's Data Protection Commission, the EU's lead privacy regulator for Google, issued the €403 million fine. — Photograph: Carl Gruner / Unsplash
SHARE X f in

Ireland's Data Protection Commission fined Google €403 million, or about $463 million, on Monday after ruling that the company unlawfully processed users' location data across three product features for close to two years, the regulator announced.

The DPC's decision covers conduct between May 2018 and February 2020 across Google's Web & App Activity setting, its Location History service, and the Location Accuracy feature built into Android. Investigators found Google failed to process the data lawfully, fairly or transparently, that users were often unaware their location information was being used for targeted advertising and interest inference, and that the data was retained for longer than necessary.

Ireland's Outsized Enforcement Role

Because Google's European headquarters sits in Dublin, the DPC serves as the company's lead regulator under the EU's General Data Protection Regulation, giving Irish enforcement decisions outsized weight across the 27-country bloc. Deputy Commissioner Graham Doyle framed the ruling in a statement:

Location data can greatly enhance utility of online services, but can also reveal significantly private information about individuals.

Graham Doyle, Deputy Commissioner, Data Protection Commission

The inquiry traces back to complaints filed by European consumer-rights organizations in February 2020, which prompted the DPC to open a formal examination of how Google's location-tracking settings were presented to users and how long the resulting data was kept on file. It adds to a lengthening list of GDPR penalties Google has faced from EU regulators over the past several years, part of a broader pattern in which Dublin's rulings on Google, Meta and other U.S. platforms have become de facto standards for data-protection enforcement across all 27 member states.

Google, in a statement responding to the ruling, said the case centers on "historical policies that have since been updated," noting that the company has introduced automatic-deletion settings, new ad-management tools and increased transparency around location data since 2019. The company indicated it plans to appeal, focusing on legal questions it says require clarification beyond the specifics of this case.

The DPC has given Google six months to bring its data processing into compliance. An appeal, if filed, could delay when the fine becomes final, but the decision adds fresh momentum to European regulators' continued scrutiny of how the company handles personal data — a pressure point that has repeatedly shaped Google's product design across the continent, from consent prompts to the granularity of the location controls now built into Android and Google Maps.

SHARE THIS ARTICLE X Facebook LinkedIn Copy link
Claire Fontaine · Technology & Regulation Correspondent

Reports on technology and its regulation for UBStandard, with a focus on Brussels, AI policy and Europe's digital economy.

[email protected]
Related coverage Front page →