· via Hacker News – Front Page (native)
Irish DPC fines Google €403 million over GDPR breaches in location data processing
Ireland's Data Protection Commission has fined Google €403 million over GDPR breaches in its handling of location data across three services, and ordered the company to bring its processing into compliance within six months.

Ireland's Data Protection Commission (DPC) has fined Google €403 million after an inquiry found the company breached the GDPR in how it processed users' location data, and has ordered it to bring the affected processing into compliance within six months.
According to the DPC, the decision concludes an own-volition inquiry opened in February 2020, when the regulator — acting in its role as Lead Supervisory Authority for Google — responded to complaints from several European consumer rights organisations, including BEUC. The investigation covered three Google features — Web & App Activity, Location History and Location Accuracy — and examined processing between 25 May 2018, the date the GDPR took effect, and 4 February 2020.
What the DPC found
The decision, made by Commissioners Dr Des Hogan, Dale Sunderland and Niamh Sweeney, identifies four areas of infringement:
- the lawfulness and fairness of Google's processing of location data in Web & App Activity and Location History;
- its accountability obligations, having failed to demonstrate compliance with the lawfulness, fairness and transparency principles for Location Accuracy;
- its transparency obligations across all three features; and
- its retention of location data in Web & App Activity and Location History.
The three features under scrutiny
The DPC's background material sets out what each feature does. Web & App Activity is a Google Account setting that processes information about a user's activity across Google services, sites and apps, including browsing history, search history and location data.
Location History is an opt-in service that tracks a user's location through their mobile device and infers place visits, activities and the paths between them. Its Timeline feature displays a private map via Google Maps, and that map continues to record where a signed-in device goes even when the user is not actively using a Google service.
Location Accuracy is different in kind. It is an Android OS feature that lets a device determine its position more precisely than GPS alone, and it is available to Android users regardless of whether they hold a Google Account.
The regulator's reasoning
Deputy Commissioner Graham Doyle said location data can make online services more useful but can also reveal a significant amount of inherently private information about an individual. The core problem, in the DPC's view, is that Google's failures meant individuals could have been unaware their location was being used, for instance to influence them with ads or to infer their interests, and could consequently lose control over their personal data. Retaining that location data for longer than necessary, the DPC added, aggravated the loss of control.
The regulator also thanked its peer supervisory authorities for their cooperation and assistance, and said the full decision will be issued in due course.
What happens next
Alongside administrative fines totalling €403 million, the DPC has ordered Google to bring its processing into compliance within six months — meaning changes to how the three features handle consent, disclosure and retention, not just a financial penalty.
Why it matters
This is a major GDPR enforcement action against one of the largest data processors in the world, and it concerns a data category — location — that sits at the heart of online advertising and personalisation. The findings go beyond consent alone: the DPC also held Google to account on transparency, retention limits and its ability to demonstrate compliance, which widens the set of obligations regulators are prepared to enforce in significant decisions.
Because the DPC acted as Lead Supervisory Authority with input from peer regulators across Europe, the decision carries weight beyond Ireland and will shape how the GDPR is applied across the EEA. For web companies of any size that collect location signals through account settings or platform-level features, the message is that bundling tracking into defaults, keeping disclosures vague or holding data longer than needed now carries material financial and product-level consequences.
- #gdpr
- #privacy
- #data-protection
- #regulation