Skip to content
Tech News
← Back to articles

Google fined €403 million over location data privacy violations

read original more articles
Why This Matters

This fine underscores the EU's continued aggressive enforcement of GDPR against major tech companies, particularly around opaque data collection practices that consumers may not fully understand or control. It signals to the tech industry that location data—often quietly gathered through default settings—remains a major regulatory flashpoint, likely prompting other companies to reassess their own transparency and retention practices.

Key Takeaways

Ireland’s Data Protection Commission (DPC) has fined Google €403 million ($463M) for multiple GDPR violations related to processing users’ location data.

The agency launched an investigation in February 2020 after receiving multiple complaints from consumer rights organizations. It examined three Google features that were active during the GDPR application period from May 25, 2018, through February 4, 2020.

The features cover permissions that allowed Google to process users’ web and app activity, location history, and location accuracy data:

Web and App Activity – A setting for Google Account holders that allows Google to process activity across its services, potentially including browsing history, search history, and location data.

Location History – An opt-in service that tracks users carrying compatible mobile devices. It can infer visited places, activities, and routes, and displays this information through a private Google Maps Timeline, even when the user is not actively using a Google service.

Location Accuracy – An Android feature that helps a device determine its position more accurately than GPS alone. It is available regardless of whether the user has a Google Account.

The DPC found that Google processed location data through Web & App Activity and Location History without meeting the GDPR’s requirements. At the same time, the company failed to demonstrate compliance with GDPR principles when processing personal data through Location Accuracy.

The Irish authority alleges that Google failed to meet transparency obligations for all three features and retained location data collected through Web & App Activity and Location History longer than necessary.

“[...] individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data,” stated Deputy Commissioner Graham Doyle.

“The retention of users’ location data for longer than necessary aggravated this loss of control.”

... continue reading