Google fined €403 million over location data
Ireland's Data Protection Commission found Google broke GDPR rules on transparency, fairness and retention of location data in three features.
By Priya Nair · Published · Updated · 8 min read

Ireland's Data Protection Commission (DPC) has fined Google €403 million over how it processed users' location data, the DPC announced.
What the inquiry covered
The DPC began investigating in February 2020 after complaints from European consumer groups, including BEUC. It looked at three Google features between May 2018 and February 2020:
- Web & App Activity
- Location History
- Location Accuracy
The inquiry was a six-year investigation, with the DPC acting as Google's lead EU supervisory authority under the GDPR's one-stop-shop mechanism, which means the decision applies across the whole European Economic Area rather than country by country (Irish Independent).
What the DPC found
Google broke the GDPR on:
- Lawfulness and fairness of processing location data in Web & App Activity and Location History
- Accountability, by failing to show its Location Accuracy processing complied with the rules
- Transparency across all three features
- Retention — keeping location data too long
The decision was made by the Commissioners for Data Protection, Dr Des Hogan, Mr Dale Sunderland and Ms Niamh Sweeney (Data Protection Commission). It is the DPC's first major fine against Google specifically, even though the regulator has fined other big technology firms repeatedly over the past five years.
The Guardian reports the complaints alleged Google manipulated users into agreeing to constant tracking, and the DPC found users may not have known their data was used to target ads.
What officials said
DPC deputy commissioner Graham Doyle said location data "can reveal a significant amount of information about an individual, including information that is inherently private," and added: "The GDPR provides a high level of protection of personal data throughout the EEA, and requires that the processing of personal data must be carried out in a lawful, fair and transparent manner" (BBC News). Doyle went on to say that as a result of Google's failures, "individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data."
The DPC's wider record against big tech
The Irish Independent reported that this latest penalty brings the total value of fines imposed by the DPC on major technology companies over the past five years to more than €4.4 billion. Notably, the report says that under €20 million of that total has actually been paid so far, with the rest still tied up in judicial appeals — a reminder that headline fine figures against large multinational platforms often take years, if ever, to be collected in full. Under the EU's regulatory structure, fines imposed by the DPC are paid to the Irish state, even though the underlying harm is spread across users throughout the EU.
Why it matters
Location history reveals where you live, work, worship and seek medical care. This is one of the largest GDPR fines ever and a reminder that "agree" buttons do not make data collection lawful if people are not properly informed.
Google has said it has improved its data protection practices in the years since the period covered by the inquiry, according to the BBC's report, though the company's current level of compliance with these specific findings has not been independently verified in the sources reviewed for this article.
Background: how location tracking works on Android and Google services
Google's "Web & App Activity" setting records searches and activity across Google services and partner apps, "Location History" (now branded "Timeline" in Google Maps) logs where a signed-in device has been over time, and "Location Accuracy" uses networks such as Wi-Fi and Bluetooth beacons to sharpen GPS positioning. Together these features can build a detailed picture of a person's daily movements, which is valuable both for personalizing services like traffic predictions and for targeting advertising — the exact dual use at the heart of the DPC's finding that users were not adequately informed about which purpose their data was really serving.
How to check your own settings
- Visit myactivity.google.com to review and delete Web & App Activity.
- Turn off or auto-delete Timeline (Location History) in Google Maps settings.
- Check the "Location Accuracy" toggle under your device's location settings if you want to limit how precisely your position is estimated.
- Review which apps have been granted background location permissions on your phone, since many apps request this by default.
What readers should do
- Go to myactivity.google.com and delete or set auto-delete periods for your Web & App Activity history.
- Open Google Maps' Timeline settings and turn off Location History if you do not need it, or set it to auto-delete after three months.
- Periodically audit which apps on your phone have "always allow" location permission, and downgrade this to "while using the app" where possible.
- Read privacy prompts carefully rather than clicking "agree" by default — the DPC's findings specifically concerned whether users understood what they were consenting to.
- If you are an EU resident, you can complain to your national data protection authority if you believe a company is still not providing clear information about how your data is used.
Sources
Regulatory context: GDPR enforcement in Europe
The GDPR came into force on 25 May 2018 and gives EU data protection authorities the power to fine companies up to 4% of global annual turnover for serious infringements. Ireland's DPC is the lead regulator for many major US technology firms because they base their EU operations in Dublin, which has made the DPC one of the most consequential — and most criticized — privacy enforcers in the world. Consumer groups and other EU regulators have at times argued the DPC moves too slowly or imposes fines too low relative to the scale of the companies involved, a criticism that resurfaces with large multi-year investigations like this one, which took roughly six years from initial complaint to final decision.
Previous GDPR enforcement against Google has focused on similarly opaque consent flows and dark patterns, where options to decline tracking are harder to find or use than options to accept it. Privacy advocates say the pattern in this case — a long counter burning years before enforcement lands, followed by appeals that can stretch out even longer — shows why critics argue GDPR fines alone are not yet changing how the largest platforms design default settings for ordinary users.


