US Edition
Your source for latest news
TechnologyRegulation

Ireland fines Google €403 million over years of unlawful location tracking

The Data Protection Commission found Google failed to lawfully disclose or limit how it used location data gathered through Android and its own apps between 2018 and 2020, in the regulator's fourth-largest GDPR penalty to date.

PT
By PressTemps Technology DeskPublished Today, 05:59 ET · 5 min read
Ireland fines Google €403 million over years of unlawful location tracking
Google's European headquarters campus in Dublin, where the company's Irish subsidiary — the entity fined by Ireland's Data Protection Commission — is based. Illustrative image; not from the announcement itself. Photo by Fabian.aichwald via Wikimedia Commons (CC0).
What to know
Ireland's Data Protection Commission fined Google Ireland Limited €403 million ($463 million) for unlawfully processing location data through Web & App Activity, Location History and Location Accuracy between May 2018 and February 2020.
It is the DPC's fourth-largest GDPR fine, behind its €1.2 billion Meta penalty, €345 million TikTok penalty and ahead of its €91 million Meta penalty.
Google has six months to bring its practices into compliance and has signaled it will appeal to Ireland's High Court within the 28-day window Irish law allows.
Google says the practices at issue are historical and were significantly overhauled starting in 2019, but the ruling adds to a lengthening EU enforcement record on Android's default data settings.

Ireland's Data Protection Commission fined Google €403 million ($463 million) on Monday, concluding a six-year investigation into how the company collected and used location data through Android phones and its own apps, and finding that Google processed that data unlawfully for nearly two years after Europe's privacy law took effect.

The decision, announced by the DPC, targets Google Ireland Limited, the entity that handles data protection compliance for the company across the European Economic Area. It is the regulator's fourth-largest fine to date and adds to a run of penalties against major platforms that has made the Irish watchdog the most consequential enforcer of the General Data Protection Regulation in the bloc.

Three features, one finding

The inquiry, opened in February 2020 after complaints from consumer groups, examined three Google features that touch location data: Web & App Activity, an account setting that logs searches and browsing alongside location signals; Location History, the service behind Google Maps' Timeline function, which maps where a device has been; and Location Accuracy, an Android system feature that pulls in Wi-Fi and sensor data to sharpen GPS readings.

Covering the period from May 2018, when the GDPR came into force, through February 2020, the DPC found that Google did not process data lawfully or fairly in Web & App Activity and Location History, kept that data longer than necessary, and failed to meet the law's transparency requirements across all three features. Regulators also concluded Google could not demonstrate accountability for how Location Accuracy handled personal data, a separate GDPR obligation requiring companies to be able to show, not just assert, that their processing complies with the law.

Deputy Commissioner Graham Doyle said the case turned on how invisible the tracking was to the people it affected.

"Location data can greatly enhance online services, but also reveals significant private information about individuals," Doyle said, adding that users "could have been unaware their location was being used to influence them with ads" or to infer their interests, and could lose control over their personal data as a result.

The finding was made by a decision-making panel of three commissioners, Des Hogan, Dale Sunderland and Niamh Sweeney. Google has six months to bring its practices into compliance with the ruling.

A familiar playbook for Big Tech enforcement

Because Google, Meta, TikTok and most other large US technology companies route their European operations through Irish subsidiaries, the DPC has become the primary GDPR regulator for the industry, and its fines have climbed steadily since the law took effect in 2018. The Google penalty follows the DPC's €345 million fine against TikTok over its handling of children's data and a €91 million fine against Meta for storing user passwords in plain text, both issued within the past three years. The commission's largest penalty remains the €1.2 billion it levied against Meta in 2023 over the transfer of European user data to the United States.

The pattern across these cases has been consistent: long investigations, findings centered on the GDPR's core principles of lawfulness, fairness and transparency, and appeals that stretch the enforcement timeline by years. Of roughly €4 billion in fines the DPC has imposed since 2018, only a small fraction has actually been paid, because companies including Meta have challenged rulings in the Irish courts, sometimes reducing the final amount or delaying payment indefinitely.

Who the ruling reaches, and what Google says

The decision applies to location data Google collected from users across the European Economic Area between 2018 and 2020, a period during which Location History and Web & App Activity were enabled for many Android users through default account settings rather than an explicit, separate choice. The DPC's finding that Google failed the law's transparency and accountability standards means the practical effect for those users was that ad targeting and personalization built on their movements ran with less disclosure than the law required.

Google disputed the outcome. A spokesperson said the case "centres around historical policies that have since been updated," noting that "from 2019 onwards, we've significantly evolved our practices and launched robust tools that make managing location data simple," pointing to features such as auto-delete settings for location history and expanded controls introduced in the years after the period under investigation. The company has indicated it will appeal, focusing on what it has described as legal questions that go beyond the specifics of this case. Under Irish law, a company facing a fine above €75,000 can appeal to the High Court within 28 days of the decision, a step Google's past challenges to DPC rulings suggest is likely.

What happens next

The DPC said it plans to publish the full decision in the coming weeks, which will lay out its legal reasoning in more detail than Monday's summary. In the meantime, Google's six-month compliance clock is running regardless of any appeal, unless a court grants a stay. Coverage of the decision by RTÉ and Euronews both noted that the case is one of several ongoing DPC inquiries into Google's data practices, meaning Monday's fine is unlikely to be the last word on how the company handles European users' data under the regulation.

For Google, the immediate financial impact is modest relative to its annual revenue, but the finding joins a lengthening record of EU rulings against the company's data practices, adding to the pressure the DPC's decisions have placed on how Android's default settings handle personal data across the bloc.

More on this story

All Technology