Ireland's Data Protection Commission fined Google €403 million ($462 million) this week for violating the European Union's General Data Protection Regulation in the way three of its products handled location data, the regulator's first-ever penalty against the company and one of the largest GDPR fines against a major technology firm this year.
The decision caps a six-year inquiry into three features — Web & App Activity, Location History and Location Accuracy — that Google Ireland Limited ran between May 25, 2018, the day GDPR took effect, and February 4, 2020, when the DPC opened its investigation after complaints from European consumer-rights organizations. The commission found the company could not demonstrate that its processing of that data was lawful, fair or transparent, and that it retained location signals for longer than necessary.
What the regulator found
Investigators concluded that Web & App Activity and Location History processed location data unlawfully and unfairly, that Google failed to meet GDPR accountability requirements for Location Accuracy, and that transparency obligations were breached across all three features. Users, the DPC said, may not have realized their location was being used to target them with ads or infer their interests.
Location data can greatly enhance utility of online services, but it can also reveal significant information about an individual, including inherently private data.
Graham Doyle, DPC Deputy Commissioner
Google has six months to bring its data processing into compliance. At €403 million, the penalty ranks as the fourth-largest the DPC has ever issued, though it is the commission's first fine specifically against Google — a company that, unlike Meta and TikTok, had largely avoided major Irish GDPR penalties until now.
Google's response and the broader pattern
Google described the underlying practices as outdated. "From 2019 onwards, we've significantly evolved our practices and launched robust tools that make managing location data simple," a company spokesperson said, noting the case concerns policies that predate current controls such as auto-delete settings and on-device Timeline storage.
The ruling extends a pattern of aggressive GDPR enforcement out of Dublin, where the DPC serves as lead regulator for most large U.S. tech companies operating in the EU under the bloc's one-stop-shop mechanism. Meta and TikTok have each faced multiple nine-figure penalties from the same office in recent years over data practices and international transfers, and privacy advocates who filed the original complaints argued the Google decision was overdue given how central location tracking has become to online advertising.
Coverage of the decision, including from The Record, noted the case predates the rise of AI assistants that now also draw on location context, raising questions about how regulators will scrutinize newer products like Gemini's location-aware features.
Google has not said whether it will appeal. Under GDPR's cross-border enforcement rules, the decision was reviewed by data protection authorities across the EU before being finalized, and any appeal would go through the Irish courts. For now, the six-month compliance clock — and the prospect of similar scrutiny landing on Google's newer AI products — is what regulators and rivals will be watching next.