Ireland’s Data Protection Commission (DPC) has slapped Google with a €403 million ($463 million) fine for violating the European Union’s strict privacy regulations, specifically for mishandling users’ location data. The penalty, announced Monday, is the fourth-largest GDPR fine issued by the Irish watchdog, which serves as the lead regulator for Google in the 27-nation bloc due to the company’s Dublin-based European headquarters.
The investigation, which began six years ago, examined Google’s processing of location data from the time the General Data Protection Regulation took effect in 2018 until February 2020. Regulators found that Google failed to lawfully and fairly process location data in its Web & App Activity setting—which tracks browsing and search history—and in its Location History feature, which maps places users have visited via their mobile phones. Additionally, the DPC determined that Google did not meet the GDPR’s requirements for lawfulness, fairness, and transparency when processing personal data through its Location Accuracy feature in the Android operating system.
“Location data can bring both benefits and harms to individuals,” said Deputy Commissioner Graham Doyle. “It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private.”
Google responded to the decision by emphasizing that the case concerns historical practices. “This case centers around historical policies that have since been updated,” a company spokesperson said. “From 2019 onwards, we’ve significantly evolved our practices and launched robust tools that make managing location data simple.”
The fine is part of a broader crackdown by European regulators on U.S. tech giants over data privacy. The Irish DPC has previously levied larger penalties against other platforms, including a €1.2 billion fine against Meta and a substantial fine against TikTok. The regulator confirmed it still has three other ongoing privacy investigations involving Google.
Google’s location data practices have drawn scrutiny not only in Europe but also in the United States, where lawmakers have raised concerns about how tech companies handle sensitive user information. The fine underscores the EU’s willingness to enforce its privacy rulebook aggressively, even as critics argue that enforcement has been slow and uneven.
As the digital economy continues to expand, the intersection of technology and policy remains a flashpoint. The DPC’s action signals that regulators are prepared to hold even the largest platforms accountable for how they collect and use personal data. For Google, the penalty adds to a growing list of compliance costs in Europe, where it already faces rigorous oversight under the GDPR.
The decision also highlights the role of national regulators in shaping global privacy standards. With Ireland acting as the lead authority for many U.S. tech firms, its rulings carry weight far beyond the EU’s borders. The fine serves as a reminder that location data—often collected silently in the background—can expose deeply private details about individuals’ lives, making its protection a priority for watchdogs worldwide.
