Google fined €403 million over location data privacy violations

Google Fined €403 Million Over Location Data Privacy Violations, Raises Concerns About User Control

In a significant blow to Google’s data collection practices, the Irish Data Protection Commission (DPC) has fined the tech giant €403 million for violating General Data Protection Regulation (GDPR) rules related to processing users’ location data. The fine, which amounts to approximately $463 million, is one of the largest ever imposed under GDPR.

The DPC launched an investigation in February 2020 after receiving multiple complaints from consumer rights organizations regarding Google’s handling of user location data. The agency examined three key features that were active during the GDPR application period: Web and App Activity, Location History, and Location Accuracy. These features allowed Google to process users’ web activity, location history, and device positioning, potentially including browsing history, search history, and location data.

The investigation found that Google processed location data through Web & App Activity and Location History without meeting the GDPR’s transparency requirements. Furthermore, the company failed to demonstrate compliance with GDPR principles when processing personal data through Location Accuracy. The DPC also alleged that Google retained location data collected through these features for longer than necessary, exacerbating users’ loss of control over their personal data.

“This case highlights concerns about user control and transparency in data collection,” said Deputy Commissioner Graham Doyle. “Individuals may have been unaware that their location was being used to influence them with ads or infer their interests, and could lose control over their personal data.” The retention of users’ location data for longer than necessary only aggravated this loss of control.

The DPC has imposed administrative fines totaling €403 million and demands that Google bring its user data processing into compliance within the next six months. In response to the fine, Google stated that it has updated its practices and policies since 2019, implementing robust tools that make managing location data simple. The company claims to have added controls that allow users to define a specific timeline for automatically deleting data in their account.

However, this development raises important questions about user control over personal data. With the increasing reliance on mobile devices and online services, it is crucial for individuals to be aware of how their location data is being collected, processed, and used. As the DPC’s fine demonstrates, companies must prioritize transparency and accountability in data collection practices.

To avoid similar issues, users should remain vigilant about managing their location data. Google provides tools that allow users to define a specific timeline for automatically deleting data in their account, but it is essential to regularly review and update these settings. Furthermore, users should be cautious when using services that collect location data, ensuring they understand how this information will be used and stored.

Ultimately, the DPC’s fine serves as a warning to companies about the importance of prioritizing user control and transparency in data collection practices. As technology continues to advance, it is crucial for individuals and organizations alike to prioritize accountability and respect for users’ rights to their personal data.


Source: Bleeping Computer — 2026-09-21