
Ireland’s Data Protection Commission has issued a €403 million fine against Google over breaches of GDPR (General Data Protection Regulation) related to how the company processed users’ location data, a case that took more than six years to reach a conclusion.
GDPR is the European Union’s main data protection law, which sets out strict rules on how companies may collect, store and use personal information about people living in the European Economic Area (EEA). Under GDPR, companies must process personal data lawfully, fairly and transparently.
What the Google GDPR location data fine is about
The DPC (Data Protection Commission) launched its inquiry into Google Ireland in response to complaints from multiple European consumer rights organisations about how the tech company handled location data. The investigation examined three specific settings: “web and app activity”, “location history” and “location accuracy”, covering the period between 25 May 2018 and 4 February 2020.
The DPC found that Google users could have been unaware that their location data was being used to influence them with adverts or to infer their interests. Deputy commissioner Graham Doyle explained the core concern: “Location data can bring both benefits and harms to individuals. It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private.”
Doyle added that, as a result of Google’s failures, “individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data.” He also stated that “the retention of users’ location data for longer than necessary aggravated this loss of control.”
Alongside the fine, the DPC has ordered Google to bring its processing into compliance within six months. The commission describes this as the fourth largest fine it has issued since GDPR came into effect.
When Google must pay, and what happens next
The fine is not yet collectable. According to The Hacker News, a DPC fine only becomes payable after an Irish court formally confirms it. Google also has the right to appeal the decision to the High Court, and must do so within 28 days of receiving formal notice of the ruling. The road from decision to payment could therefore take considerably longer than the six-month compliance window suggests.
The decision itself arrived more than 6.5 years after the inquiry first opened, a timeline that reflects the complexity of cross-border data protection cases involving large technology companies operating across multiple EU member states.
Google’s response and the changes it has already made
A Google spokesperson said: “This case centres around historical policies that have since been updated. From 2019 onwards, we’ve significantly evolved our practices and launched robust tools that make managing location data simple.”
The company pointed to several changes it has introduced. Users can now set their accounts to automatically delete location and activity data on a rolling three-, 18-, or 36-month basis. Settings have also been introduced allowing users to turn off personalised ads entirely, and to manage how their location data is used for advertising purposes.
Google’s “Timeline” feature, which previously stored movement history in the cloud, now keeps that data directly on users’ own devices. The company also stated that it does not store precise device location in users’ Web and App Activity when searches are made, saving instead an “estimated general area.”
The DPC currently has three other large-scale statutory inquiries open that concern Google, all described as being at an advanced stage. The outcome of any High Court challenge, should Google choose to file one within the 28-day window, will determine when the €403 million penalty is actually collected.



