Google fined €403 million by Irish DPC over unlawful location data processing
Key Takeaways
- •Ireland's Data Protection Commission imposed a €403 million ($463 million) fine on Google for processing location data without a valid legal basis under the GDPR.
- •The decision covered three services—Web & App Activity, Location History and Location Accuracy—which the regulator found were handled in a way that was not lawful, fair or transparent.
- •The case originated from complaints by seven European consumer organizations, drawing on 2018 research by Norway's consumer agency showing that location tracking can expose sensitive details such as religious beliefs, political views, health conditions and sexual orientation.
- •Google has six months to bring its practices into GDPR compliance and may challenge the decision before national courts, with the company stating it changed its practices from 2019 onward and introduced tools for managing location data.
- •The penalty is the fourth-largest issued by the Irish regulator, following fines against Meta, TikTok and Instagram, and three additional investigations into Google are already at an advanced stage.

Ireland's Data Protection Commission (DPC) has imposed a €403 million ($463 million) fine on Google over its handling of location data from Android and Google account users. The regulator found that the company lacked a legal basis for processing the information and failed to give users sufficient clarity about what they were agreeing to.
The DPC determined that Google did not process location data lawfully, fairly or transparently across three products: Web & App Activity, Location History and Location Accuracy. The first two can track browsing and search activity as well as the places a user's device has previously been, while Location Accuracy is a setting within the Android operating system. The ruling turns on one of the core requirements of the General Data Protection Regulation (GDPR), the EU's comprehensive privacy law: companies must have a valid legal basis, such as consent, before processing personal data, and must be transparent about what that processing involves.
The watchdog also highlighted the extensive privacy risks associated with location tracking. Deputy Commissioner Graham Doyle said location data can make online services more useful, but can also reveal highly private and sensitive information about a person. According to the Guardian, Doyle noted that users may not have known their whereabouts were being used to target advertising or infer what their interests could be. He added that keeping the information for longer than necessary further reduced users' control over their data.
The inquiry ran from the date the GDPR took effect on May 25, 2018, until February 4, 2020 — a period of almost two years.
A complaint rooted in Norway
The case began with complaints from seven European consumer organizations accusing Google of tracking users throughout their daily lives. Their concerns drew on 2018 research by Norway's consumer agency, the Forbrukerrådet, which argued that Google used "various tricks" to keep Location History and Web & App Activity enabled.
The research also set out how and why location tracking can expose far more than the geographical places a person has been. Visits to places of worship can reveal religious beliefs, attendance at demonstrations can point to political views, hospital visits can indicate health conditions, and the venues someone frequents can reveal their sexual orientation.
Finn Myrstad, digital policy director at the Norwegian Consumer Council, described the ruling as a milestone. According to the Guardian, Myrstad said people should be able to understand what they are agreeing to without being misled or pressured into choices they would not otherwise make.
The European Consumer Organisation, known as BEUC, likewise described geolocation as one of the most invasive forms of consumer surveillance.
Six years after the investigation began
BEUC director general Agustín Reyna welcomed the decision but criticized the time it took to reach, describing the delay as "disproportionate with the seriousness of the infringement" and warning that "late enforcement can be as harmful as no enforcement at all." The DPC opened its investigation six years ago.
Google, for its part, has pointed to changes the company says it has made since the period covered by the inquiry. A spokesperson said the case concerns historical policies that have since been updated, adding that the company notably changed its practices from 2019 onward and introduced tools to make location data easier to manage.
The DPC has given Google six months to bring its processing practices into compliance with the GDPR. Under the regulation, companies can challenge such decisions before national courts.
Why Ireland is leading the case
Google's European headquarters are in Dublin, making the Irish watchdog its lead regulator across the 27-member EU. The DPC holds the same role for most major US technology companies with their European bases in Ireland.
The €403 million penalty is the fourth-largest fine issued by the Irish regulatory commission. According to the Guardian, the DPC has previously fined Meta €1.2 billion, TikTok €530 million and Meta-owned Instagram €405 million. The GDPR's penalty framework allows regulators to impose fines of up to 4% of a company's total worldwide annual turnover, or €20 million, whichever is higher.
The latest decision may not be the regulator's final action against Google this year, with three other investigations into the company already at an advanced stage.