Ireland’s Data Protection Commission (DPC) has fined Google €403 million ($463 million) for violating the European Union’s General Data Protection Regulation (GDPR) by mishandling users’ location data, the watchdog announced Monday. The investigation, which spanned from May 2018 to February 2020, found that Google failed to lawfully, fairly, and transparently process location information across several of its services.
Specifically, regulators identified breaches related to Google’s Web & App Activity setting, which tracks users’ browsing and search histories, as well as Location History, a feature that logs users’ movements via mobile devices. The DPC also found that Google’s processing of personal data through its Location Accuracy feature on Android phones did not meet the standards required by the GDPR.
As Google’s European headquarters are in Dublin, Ireland serves as the lead data protection authority for the company within the 27-member EU. The fine is among the largest ever imposed by the DPC and follows a six-year inquiry into Google’s compliance with the bloc’s privacy laws since the GDPR came into effect in 2018.
Graham Doyle, deputy commissioner of the DPC, stated that Google’s shortcomings meant users could have been unaware their location details were being used to influence advertising or infer personal interests. He further noted that retaining location data longer than necessary intensified the users’ loss of control over their personal information. The regulator has ordered Google to bring its data processing practices into compliance within six months.
In response to the ruling, Google said the case concerns policies that have since been changed. The company emphasized that starting in 2019, it made significant updates to its location data practices and introduced enhanced tools to simplify how users manage their location information.
The fine highlights ongoing scrutiny of major technology companies within the EU over data privacy issues, underscoring the bloc’s commitment to enforcing its GDPR framework. Google has previously faced multiple regulatory actions over data handling and transparency, reflecting the challenges global tech firms face in aligning with stringent European privacy standards.
