Google just took a €403 million hit from Ireland’s Data Protection Commission. The regulator found Google broke GDPR rules in how it handled location data. For anyone running a business on Google’s platforms, this isn’t just another privacy story. It’s a warning: the rules around user data are getting stricter, and the price for getting it wrong is climbing fast.
The DPC has given Google a six-month deadline to bring its location data practices into full compliance with GDPR requirements.
The DPC defines location data as any information that can show where a person is. This makes it valuable for advertisers and a big concern for privacy advocates. The fine is tied to what Google called “historical policies,” which the company says it has since changed. But the DPC’s decision shows that old practices can still lead to big penalties. This €403 million fine is now the fourth-largest the DPC has ever handed out. Only Meta’s €1.2 billion fine in 2023, TikTok’s €530 million, and Instagram’s €405 million were bigger, according to a Reuters financial review.
The DPC’s investigation was launched in February 2020 following complaints from BEUC, the European consumer organization, which sought scrutiny of Google’s consent mechanisms for collecting geolocation data.
For digital publishers and content creators, the message is clear. Regulators are watching data practices closely. The risks are real, not just on paper. Fines now run into the hundreds of millions. The damage to reputation can be just as bad as the financial hit. Google says it has changed its policies to address some of the DPC’s concerns. But with more investigations ongoing, it’s clear the bar for compliance keeps rising.
This case shows the DPC is willing to go after old data practices, not just what companies are doing now. If you manage audience data, old systems and outdated consent flows can still get you in trouble. Google has huge legal and technical resources, but it still got caught breaking the rules. Smaller publishers and startups face even more risk. The industry should expect tougher oversight, faster investigations, and less room for mistakes on user consent and data retention. Treating privacy as a one-time task is risky. Regulators are not backing down.