Google News

Google fined €403 million in Ireland for breaking privacy rules on location data

Google fined €403 million in Ireland for breaking privacy rules on location data FAYFO Media © fayfo.com
Google fined €403 million in Ireland for breaking privacy rules on location data © fayfo.com
Ireland’s data regulator has fined Google €403 million for mishandling users’ location data. The case zeroes in on how Google got user consent and shows regulators are turning up the heat on tech giants.

Google just took a €403 million hit from Ireland’s Data Protection Commission. The regulator found Google broke GDPR rules in how it handled location data. For anyone running a business on Google’s platforms, this isn’t just another privacy story. It’s a warning: the rules around user data are getting stricter, and the price for getting it wrong is climbing fast.

The DPC announced the fine after looking at how Google managed location data from May 2018 to February 2020. The case started with a complaint from a European consumer rights group. Investigators focused on three features: Web & App Activity, Location History, and Location Accuracy. Commissioners Des Hogan, Dale Sunderland, and Niamh Sweeney found Google kept location data in ways that broke GDPR. This happened in Web & App Activity and Location History, even when users thought their data would be deleted or not tracked.

The DPC has given Google a six-month deadline to bring its location data practices into full compliance with GDPR requirements.

Reuters

The DPC defines location data as any information that can show where a person is. This makes it valuable for advertisers and a big concern for privacy advocates. The fine is tied to what Google called “historical policies,” which the company says it has since changed. But the DPC’s decision shows that old practices can still lead to big penalties. This €403 million fine is now the fourth-largest the DPC has ever handed out. Only Meta’s €1.2 billion fine in 2023, TikTok’s €530 million, and Instagram’s €405 million were bigger, according to a Reuters financial review.

Agustín Reyna, director general of BEUC, the European consumer group that helped start the investigation, called the ruling a win for consumers. He said it proves Google’s consent process for location data broke EU law. But Reyna also said enforcement took too long, which can weaken the protection of people’s rights. The DPC has three more major investigations into Google underway. One, opened in September 2024, is looking at how Google handles data from artificial intelligence platforms and whether it did the required Data Protection Impact Assessment.

The DPC’s investigation was launched in February 2020 following complaints from BEUC, the European consumer organization, which sought scrutiny of Google’s consent mechanisms for collecting geolocation data.

ReutersNews Agency

For digital publishers and content creators, the message is clear. Regulators are watching data practices closely. The risks are real, not just on paper. Fines now run into the hundreds of millions. The damage to reputation can be just as bad as the financial hit. Google says it has changed its policies to address some of the DPC’s concerns. But with more investigations ongoing, it’s clear the bar for compliance keeps rising.

This case shows the DPC is willing to go after old data practices, not just what companies are doing now. If you manage audience data, old systems and outdated consent flows can still get you in trouble. Google has huge legal and technical resources, but it still got caught breaking the rules. Smaller publishers and startups face even more risk. The industry should expect tougher oversight, faster investigations, and less room for mistakes on user consent and data retention. Treating privacy as a one-time task is risky. Regulators are not backing down.

Ken Doctor Media analyst FAYFO Media
Media Analyst

Ken Doctor

An American media analyst, journalist, and publishing strategist