Google fined $462 million by EU for location
Ireland's Data Protection Commission has fined Google over €403 million for GDPR violations related to its processing of location data.

Ireland's Data Protection Commission (DPC) will fine Google more than €403 million ($462 million). The regulator concluded an inquiry, begun in February 2020, into the tech giant's processing of location data.
Google has also been ordered to fix its data processing practices within six months. The DPC acts as the European Union's lead supervisory authority for Google because the company's European headquarters are in Dublin.
The inquiry started over six years ago after several European consumer rights groups requested an investigation. They alleged Google's practices violated the EU's General Data Protection Regulation (GDPR).
Scope of the GDPR investigation
The DPC's inquiry focused on how Google processes location data for three specific services and features. These were web and app activity, location history, and location accuracy. Investigators examined the company's data processing norms from May 2018, when GDPR became law, through February 2020.
The regulator assessed whether Google's practices were legal and fair. It also probed the company's compliance with GDPR transparency and accountability requirements. A key part of the investigation involved Google's retention of location data within its web and app activity and location history features.
The sensitivity of location data
The DPC emphasized the particular sensitivity of location information. DPC Deputy Commissioner Graham Doyle stated that location data, by itself or combined with other information, can infer an individual's location. He said it can reveal a significant amount of private information about a person.
According to the regulator's press release, Google's failures meant individuals could have been unaware their location was being used. This data could influence them with targeted ads or infer their interests. The retention of location data for longer than necessary worsened this loss of control, the DPC said.
Regulatory context and company response
This fine marks the first time the DPC has punished Google. Other tech giants like TikTok and Meta have previously faced fines of hundreds of millions of euros on multiple occasions. It remains unclear if Google still processes any of the data deemed illegal or if it has since updated its approach.
A spokesperson for Google did not reply to a request for comment from the source, The Record. The GDPR is a notably tough data protection law enforced throughout the European Economic Area, granting citizens significant data rights.
The inquiry was triggered by complaints from consumer groups. The DPC's final decision and the substantial fine show the ongoing regulatory scrutiny of major technology companies' data handling practices in Europe.





