Privacy & Regulation / ARTICLE

Ireland Fines Google €403 Million Over Location Data Handling

Ireland's Data Protection Commission has fined Google €403 million after a six-year inquiry into how three location-related features handled user data under the GDPR.

Why Ireland, and why it took six years

Ireland’s Data Protection Commission (DPC) has fined Google €403 million, concluding that the company’s handling of users’ location data breached the GDPR. The penalty closes a six-year investigation.

Ireland is not an arbitrary venue for this case. Google’s European headquarters are in Dublin, which under the GDPR’s one-stop-shop mechanism makes the DPC its lead supervisory authority across the EU. Most GDPR disputes involving Google land there first.

The inquiry covered a defined window: 25 May 2018 to 4 February 2020. The start date is the day the GDPR took effect, which suggests regulators were examining conduct after the law applied rather than older practices. Three features were named — Web & App Activity, Location History, and Location Accuracy. Together they determine what location signals Google collects, how precise those signals are, and what the company may do with them.

Three settings, and the harm the DPC described

The report points to a specific risk: users may not have realised their location data was feeding targeted advertising or being used to infer interests and preferences. Location traces are unusually revealing. Where someone lives, where they work, which places they visit at the weekend — that alone sketches a fairly complete picture, and combined with other signals an interest profile practically assembles itself. If users don’t know that chain exists, the idea of controlling their own data doesn’t amount to much.

That is part of why the case ran for years instead of months. How each feature was disclosed, what its defaults were, and how consent was obtained all had to be checked, with the regulator asking whether an ordinary user could have anticipated the use. The GDPR requires a lawful basis for processing, and where consent is that basis it has to be informed and specific. The DPC’s finding amounts to saying the transparency requirement was not met for these three features during the period in question.

Google’s response, and the timeline

In a statement, Google said it had adjusted its location data management from 2019 onwards and introduced auto-delete for location data. The timing is worth a look. Auto-delete features sit in the later part of the investigation window, while the fine covers the whole span from May 2018 to February 2020. Google’s position is that it has improved; the DPC’s finding is that the earlier practices were themselves unlawful. The two can coexist — fixing something later does not retroactively answer for what came before.

What the fine settles, and what it doesn’t

At €403 million, the penalty stays well below the GDPR’s ceiling of 4% of global annual turnover, but it is still a substantial sum, and its main value may be as a marker of where regulators are looking. Location data has become a priority area, and a tap on “agree” does not by itself establish that a user understood what would happen next. For teams building location-dependent features, the question worth answering is whether someone can grasp where their data goes before it is collected — not whether a settings page mentions it afterwards.

END