Google has been fined €403 million ($463 million) by Ireland’s Data Protection Commission (DPC) over how it processed users’ location data between 2018 and 2020.
The regulator said Google breached the European Union’s General Data Protection Regulation (GDPR) through three features, including Web & App Activity, Location History and Location Accuracy. It also ordered the company to bring its location-data processing into compliance within six months.
The DPC opened the investigation in February 2020 after complaints from several European consumer organisations, including the European consumer group BEUC.
The complaints questioned whether Google had a valid legal basis for processing location data and whether it gave users enough information about how that data was handled.
Its investigation covered the period from May 25, 2018, when the GDPR took effect, to February 4, 2020.
According to the DPC, Google’s Web & App Activity and Location History features did not meet GDPR requirements for lawful and fair processing. The regulator also found problems with transparency across all three features and with the retention of location data under Web & App Activity and Location History.
Web & App Activity allows Google Account holders to have information about their activity on Google services processed. That information can include browsing and search history as well as location data.
Location History, meanwhile, records a user’s movements through compatible devices after the feature is enabled. Google uses the information to identify places visited, activities and routes, while its Timeline feature displays those movements on a private map.
Location Accuracy works differently, it helps Android devices determine a more precise location by using information beyond the device’s GPS system. The feature is available to Android users whether or not they have a Google Account.
The DPC said location data can reveal details about a person’s movements, habits and interests. It also said Google’s failures could have left users unaware that their location information could be used for advertising or to infer interests.
“Location data is a type of personal data which is processed by way of location tracking, and includes data collected or processed by Google, which by itself or in conjunction with other information an individual’s location can be inferred,” DPC Deputy Commissioner Graham Doyle said.
The regulator also found that Google kept some location data for longer than necessary, which it said further reduced users’ control over their information.
The €403 million penalty is the fourth-largest fine issued by Ireland’s DPC since the GDPR came into force. The regulator said it has imposed more than €4 billion in fines following its investigations.
Ireland handles many of Europe’s major data protection cases involving large US technology companies because several of them have their European operations there.
Google still faces three other statutory investigations by the DPC, which the regulator said are at an advanced stage.
The DPC has not yet published the full decision. It said the complete document will be issued in due course.
![]()






















































