Now Reading
Google Faces €403 Million GDPR Penalty in Ireland Over Location Data Handling

Google Faces €403 Million GDPR Penalty in Ireland Over Location Data Handling

Google Faces €403 Million GDPR Penalty in Ireland Over Location Data Handling - International

Google has been hit with a substantial €403 million (£345 million) fine by the Republic of Ireland’s Data Protection Commission (DPC) for its practices concerning the processing of user location data. This penalty, one of the largest levied by the Irish data watchdog, stems from an inquiry initiated six years ago following complaints lodged by several European consumer rights organisations.

The DPC’s investigation concluded that Google processed data in a manner that failed to meet the General Data Protection Regulation’s (GDPR) core principles of being “lawful,” “fair,” or “transparent.” The inquiry specifically scrutinised Google’s handling of location data across three key features: Web & App Activity, Location History, and Location Accuracy, covering the period from May 25, 2018, to February 4, 2020. Location data, defined as any information that can infer an individual’s whereabouts, carries significant privacy implications, as it can “reveal a significant amount of information about an individual, including information that is inherently private,” according to DPC deputy commissioner Graham Doyle.

The DPC’s findings indicate that Google’s practices “infringed” the GDPR, the comprehensive data privacy and security legislation that came into effect across the European Union on May 25, 2018. Doyle emphasised that the GDPR mandates that personal data processing must be conducted lawfully, fairly, and transparently to ensure a high level of protection throughout the European Economic Area (EEA). The DPC highlighted that Google’s failures meant individuals could have been unaware that their location data was being used for purposes such as targeted advertising or inferring their interests, thereby losing control over their personal data. The prolonged retention of users’ location data beyond what was necessary further exacerbated this loss of control.

See Also
AliExpress Faces Record €550 Million EU Fine Under Digital Services Act for Illegal Goods - International

In addition to the financial penalty, Google has been mandated to bring its data processing operations into compliance with GDPR requirements within a six-month timeframe. Responding to the ruling, Google stated that the case pertains to “historical policies that have since been updated.” The company asserts that its practices have significantly evolved since 2019, with the introduction of robust tools designed to simplify location data management. Google also pointed to recent data protection enhancements, including “industry-first auto-delete controls” and simplified ad management options, alongside increased transparency measures regarding its location data practices and account settings.

View Comments (0)

Leave a Reply

Your email address will not be published.

© Copyright 2025 All Rights Reserved | Designed by Renix Consulting

Scroll To Top