Google fined €403 million over location data privacy violations

Google’s €403 Million Fine Highlights Location Data Privacy Concerns

In a major blow to Google’s data collection practices, Ireland’s Data Protection Commission (DPC) has imposed a record-breaking fine of €403 million on the tech giant for violating the General Data Protection Regulation (GDPR). The hefty penalty is the result of an investigation that exposed Google’s mishandling of location data from millions of users.

The DPC launched its probe in February 2020, following complaints from consumer rights organizations regarding three Google features that were active during the GDPR’s application period. These features – Web and App Activity, Location History, and Location Accuracy – allowed Google to collect and process location data from users’ devices without their explicit consent.

Web and App Activity, for instance, enabled Google to track users’ browsing history, search history, and location data across its services. Location History was an opt-in feature that used compatible mobile devices to infer visited places, activities, and routes, even when the user wasn’t actively using a Google service. Meanwhile, Location Accuracy helped devices determine their position more accurately than GPS alone – without the need for a Google Account.

The DPC found that Google failed to meet transparency obligations and retained location data collected through Web & App Activity and Location History longer than necessary. The investigation also revealed that Google didn’t demonstrate compliance with GDPR principles when processing personal data through Location Accuracy. This lack of transparency meant that users could be unaware of how their location data was being used, potentially influencing them with targeted ads or inferring their interests.

“This case highlights the importance of transparency and user control over their personal data,” said Deputy Commissioner Graham Doyle. “Individuals should be aware of what’s happening to their location data and have the ability to manage it effectively.”

Google has acknowledged that its practices have evolved since 2019, with new tools allowing users to easily manage their location data. However, the DPC’s fine serves as a stark reminder of the need for tech companies to prioritize user privacy.

The €403 million penalty is not only a significant financial blow but also a warning sign for other tech giants that must adhere to strict data protection regulations. As our reliance on digital services grows, so does the importance of safeguarding personal data and respecting users’ right to control it.

To avoid falling victim to similar data collection practices, users should be cautious when granting permissions to apps and services. Review your account settings regularly, and take advantage of built-in features that allow you to delete or manage location data. By staying informed and vigilant, you can protect your personal data from being misused by companies like Google.


Source: Bleeping Computer — 2026-09-21