Google hit with €403m fine by Irish data watchdog over GDPR violations

In one of the most significant penalties issued by Irish data privacy authorities to date, tech giant Google has been fined €403 million (£345 million) by the Republic of Ireland’s Data Protection Commission (DPC) over long-standing violations in its handling of user location data. The landmark penalty caps a six-year investigation launched after multiple European consumer advocacy groups submitted formal complaints against the company, shining a fresh spotlight on Big Tech’s compliance with European Union privacy rules.

The DPC’s inquiry, which concluded this week, focused on Google’s processing of location information across three core user features: Web & App Activity, Location History, and Location Accuracy. The investigation covered the period from May 25, 2018 — the exact date the EU’s General Data Protection Regulation (GDPR) came into force — through February 4, 2020. The regulator found that Google’s processing practices during this window failed to meet three core GDPR requirements: they were not lawful, not fair, and not transparent to users.

Location data, a category of personal information that can pinpoint an individual’s whereabouts at any given time, carries uniquely sensitive privacy risks. In an official statement announcing the ruling, DPC Deputy Commissioner Graham Doyle emphasized that this type of data “can reveal a significant amount of information about an individual, including information that is inherently private.”

Doyle reiterated that the GDPR establishes strict, uniform data protection standards across the entire European Economic Area (EEA), mandating that all processing of personal user data adhere to the core principles of lawfulness, fairness, and transparency. He added that Google’s systemic failures left users in the dark about how their location information was being used, including for targeted advertising and building user interest profiles. This lack of clarity stripped users of meaningful control over their own personal data, a violation compounded by Google’s practice of retaining location data far longer than required for its stated purposes.

Beyond the substantial financial penalty, the DPC has ordered Google to bring all of its location data processing operations into full compliance with GDPR requirements within a six-month timeline.

Google has pushed back on the ruling by framing the violations as tied to outdated policies that the company has already overhauled. In its own public statement, the company noted that the case centers on historical practices that it began updating as early as 2019. “From 2019 onwards, we’ve significantly evolved our practices and launched robust tools that make managing location data simple,” the company said.

Google highlighted a series of data protection improvements it has rolled out in recent years to address privacy concerns. These include industry-first auto-delete controls that allow all users to set their accounts to automatically delete location and activity data on rolling three, 18, or 36-month cycles. The company also pointed to simplified ad management tools that let users opt out of personalized advertising entirely, as well as increased transparency measures, including consolidated, easy-to-access information about Google’s location data practices and simplified account privacy settings.