Ireland’s Data Protection Commission (DPC) has fined Google €403 million ($463M) for multiple GDPR violations related to processing users’ location data.
The agency launched an investigation in February 2020 after receiving multiple complaints from consumer rights organizations. It examined three Google features that were active during the GDPR application period from May 25, 2018, through February 4, 2020.
The features cover permissions that allowed Google to process users’ web and app activity, location history, and location accuracy data:
The DPC found that Google processed location data through Web & App Activity and Location History without meeting the GDPR’s requirements. At the same time, the company failed to demonstrate compliance with GDPR principles when processing personal data through Location Accuracy.
The Irish authority alleges that Google failed to meet transparency obligations for all three features and retained location data collected through Web & App Activity and Location History longer than necessary.
“[…] individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data,” stated Deputy Commissioner Graham Doyle.
“The retention of users’ location data for longer than necessary aggravated this loss of control.”
For these failures, the DPC has imposed administrative fines totaling €403 million and demands that Google bring its user data processing into compliance within the next six months.
The DPC has not published its full decision yet, but promised to do so in the future.
In a statement for BleepingComputer, Google said that it has updated its practices and policies, and implemented a mechanism for easy location data management.
“This case centers around historical policies that have since been updated. From 2019 onwards, we’ve significantly evolved our practices and launched robust tools that make managing location data simple,” a Google spokesperson said.
Over the years, the company has added controls that let users define a specific timeline for automatically deleting data in their account. Google Maps Timeline information is now stored on the device and automatically removes data older than three months.
Additionally, Google says that it does not save precise device location in Web & App Activity, but an estimated general area.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Android 17 adds ECH support to make web browsing harder to track
French hospital fined €500,000 after breach exposes data of 727,000
Microsoft tests new privacy controls for Windows 11 desktop apps
TikTok reaches $400M settlement with US over COPPA violations
Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
North Korean WaterPlum hackers infected 30,000 devices worldwide
Researchers escape OpenAI Codex sandbox to run commands on host
Automate Onboarding and Access Reviews with No-Code IGA: See how it works
Overdue a password health-check? Audit your Active Directory for free
Find out how long recovery really takes — and what it costs. Read the 2025 BCDR Report.
Overdue a password health-check? Audit your Active Directory for free
Watch a working exploit hit live controls and see exactly what blocks, detects, or misses
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.


