AIO APEX

Ireland fines Google €403 million over GDPR location data breaches

Data Protection Commission (Ireland)
Share:
Ireland fines Google €403 million over GDPR location data breaches

Ireland's Data Protection Commission fined Google €403 million (about $462 million) on September 21st, closing a six-year inquiry into how the company processed location data across three features: Web & App Activity, Location History, and Location Accuracy. The DPC opened the investigation in February 2020 on its own initiative, acting as Google's lead EU supervisory authority under GDPR.

The inquiry examined the period from May 25, 2018, when GDPR took effect, through February 4, 2020, and found four separate breaches: violations of the lawfulness and fairness principle, accountability, transparency, and data retention rules. The DPC's finding centers on a specific harm: people using the three Google features might not have realized their location was shaping the ads they saw or the interests Google inferred about them, meaning they effectively lost control over their own personal data without informed consent.

Google's official decision from the DPC orders the company to bring its data processing into compliance within six months — a deadline that will require concrete changes to how the affected features handle consent and disclosure, not just a fine paid and forgotten.

The €403 million penalty ranks as the fourth-largest fine the DPC has issued since GDPR took effect, trailing Meta's €1.2 billion fine in 2023 (the largest GDPR fine ever issued), TikTok's €530 million penalty, and Instagram's €405 million fine. Ireland's DPC has become the EU's most consequential privacy enforcer almost by default: because Google, Meta, TikTok, and most major US tech companies base their EU operations in Ireland, GDPR's one-stop-shop mechanism makes the Irish regulator the lead authority for nearly every major American tech platform operating in Europe.

The ruling adds to a pattern of scrutiny specifically around location data, which regulators across the EU increasingly treat as a special category requiring stronger consent standards than general behavioral tracking — location history can reveal home addresses, religious practices, health conditions, and other sensitive inferences that ordinary browsing data cannot. Google has faced comparable location-data enforcement actions in multiple EU member states and in several US state attorneys general settlements over the past three years, suggesting the underlying consent architecture challenged here extends well beyond the specific features the DPC examined.

Originally reported by Data Protection Commission (Ireland). Read the original article for additional details.

View original source
Share: