Google fined $463 million for breaching EU location data rules
Ireland's Data Protection Commission fined Google €403 million for unlawfully processing users' location data. The company must bring its practices into GDPR compliance within six months.

Ireland's Data Protection Commission (DPC), Google's lead EU regulator since the company's European headquarters is based in Dublin, has fined the tech giant €403 million (about $463 million) over violations of the General Data Protection Regulation (GDPR) related to location data handling.
The investigation, which began in 2020 following complaints from consumer rights groups, examined how Google handled location data between May 2018 and February 2020. Regulators focused on three features: Web & App Activity, which logs user activity across multiple Google services; Location History, an opt-in feature showing a timeline of a user's past locations; and Location Accuracy, which pinpoints an Android device's location more precisely than GPS alone.
The DPC found that Google did not process data fairly or lawfully in the Web & App Activity and Location History features. Regarding Location Accuracy, the company failed to demonstrate compliance with GDPR's lawfulness, fairness and transparency principle. All three features were found to violate transparency requirements, while Web & App Activity and Location History also breached data retention rules.
Google told the Associated Press that the case concerns historical policies that have since been updated, adding that since 2019 it has significantly evolved its practices and introduced simple tools for managing location data.
This is not the first time Google has faced EU regulatory action. This summer, the company lost its final appeal against a $4.7 billion Android antitrust fine imposed in 2018. In July, the European Commission fined Google $1 billion for unfairly favoring its own services in Search results, and this month the company agreed to make changes to Search to help reduce that fine.
The DPC said three other large-scale inquiries into Google remain open and are at an advanced stage. This fine is the fourth largest the DPC has issued since GDPR took effect — the largest being a $1.3 billion fine against Meta for transferring EU citizens' Facebook data to servers in the United States.


