EU data regulator fines Google more than $460 million for location data violations

Updated 9/22 at 9:58 a.m. with a statement from Google.
Ireland’s Data Protection Commission (DPC) will fine Google more than €403 million ($462 million) for the tech giant’s processing of location data, the regulator said Monday, concluding an inquiry into the company that began in February 2020.
Google has also been ordered to fix its data processing practices within six months, according to the regulator’s press release. The DPC is the European Union’s lead supervisory authority charged with overseeing Google’s data protection practices because the platform’s European headquarters are based in Dublin.
The inquiry began more than six years ago after several European consumer rights groups asked the DPC to look into Google’s practices, which allegedly violated Europe’s General Data Protection Regulation (GDPR).
The inquiry focused on how Google processes location data in connection with three of its services and features: web and app activity, location history and location accuracy, the DPC said. Google’s practices allegedly violated GDPR due to how it tracked and stored the location data.
The inquiry examined Google’s data processing norms beginning in May 2018 — when GDPR became law — through February 2020.
Monday’s fine marks the first time the DPC has punished Google, though other tech giants like TikTok and Meta have been fined hundreds of millions on multiple occasions.
A spokesperson for Google said in a statement that the DPC case focuses on “historical policies that have since been updated. From 2019 onwards, we've significantly evolved our practices and launched robust tools that make managing location data simple.”
The DPC inquiry focused on whether Google’s data processing norms were legal and fair and whether the tech company complied with transparency and accountability requirements under the GDPR. Investigators also probed the company for retaining location data in its web and app activity and location history features.
The DPC highlighted the sensitivity of location data, “which by itself or in conjunction with other information an individual’s location can be inferred,” DPC Deputy Commissioner Graham Doyle said in a statement.
“It can also reveal a significant amount of information about an individual, including information that is inherently private.”
The GDPR is a notably tough data protection law enforced throughout the European Economic Area (EEA), which gives citizens significant data protection rights.
“As a result of Google’s failures in this regard, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data,” the press release said. “The retention of users’ location data for longer than necessary aggravated this loss of control.”
References in this story
- Data Protection Commission www.dataprotection.ie The Data Protection Commission (DPC) has today announced its final decision following an Inquiry into Google Ireland Limited (“Google”).
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
- Suzanne Smalley (@suzannesmalley.bsky.social) bsky.app Reporter covering digital privacy and cybersecurity policy for The Record. Mom. Pub trivia queen. Crossword enthusiast. Literary fiction connoisseur. Idiosyncratic. Signal: Suzanne.236 Email…



