Ireland Fines Google $463 Million Over ‘Historical’ Location Data Practices
Ireland's privacy regulator fined Google $463 million for location-tracking practices used between 2018 and 2020, a case the company calls historical and consumer groups say took too long to resolve.
Ireland’s Data Protection Commission (DPC) fined Google €403 million ($463 million) on Monday for how the company handled users’ location data between 2018 and 2020, closing an inquiry that began more than six years ago and that the consumer groups who triggered it say took far too long to resolve.
Table Of Content
The fine was confirmed in a statement from the DPC, which opened the case on its own initiative in February 2020 in its role as Google’s lead supervisory authority under the GDPR. The inquiry followed complaints from eight consumer rights organizations across Norway, the Netherlands, Greece, the Czech Republic, Slovenia, Poland, Sweden, and Denmark, coordinated by the European Consumer Organisation (BEUC), according to The Irish Times.
What investigators found
The inquiry covered three Google features active between May 25, 2018, the day the GDPR took effect, and February 4, 2020: Web & App Activity, an account setting that logs a user’s browsing history, search history, and location data; Location History, an opt-in service that tracks a user’s movements through a “Timeline” map even when they aren’t actively using a Google product; and Location Accuracy, an Android feature that sharpens a device’s location beyond what GPS alone provides, available to any Android user whether or not they’re signed into a Google account.
Three DPC commissioners, Dr. Des Hogan, Dale Sunderland, and Niamh Sweeney, found that Google broke the GDPR on four counts: it processed location data unlawfully and unfairly in Web & App Activity and Location History, it couldn’t demonstrate that its handling of Location Accuracy met the law’s lawfulness, fairness, and transparency requirements, it fell short on transparency across all three features, and it retained location data in Web & App Activity and Location History for longer than necessary.
“Location data can bring both benefits and harms to individuals,” DPC deputy commissioner Graham Doyle said in the regulator’s statement. “It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private.” Doyle added that Google’s failures meant “individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data,” and that “the retention of users’ location data for longer than necessary aggravated this loss of control.”
Google’s defense, and an unconfirmed appeal
Google has six months to bring its current practices into compliance, though the company argues that work is effectively already done. “This case centers around historical policies that have since been updated,” a Google spokesperson said, according to the Irish Times. “From 2019 onwards, we’ve significantly evolved our practices and launched robust tools that make managing location data simple.”
The company points to changes made since the period under investigation: users can now set location data to delete automatically after a window of three to 36 months, the data behind the Timeline feature is now stored on users’ own devices rather than centrally, and Google says it has simplified how people manage location data used for ad personalization, per the Irish Times’ reporting. The paper also reported that “it is understood that Google may appeal elements of the decision,” a detail attributed to its own sourcing rather than a confirmed statement from either Google or the DPC.
Where the fine lands
At €403 million, the penalty is the fourth-largest the DPC has issued since the GDPR took effect, just €2 million behind the €405 million fine that put Instagram in third place, and trailing TikTok’s €530 million penalty and Meta’s €1.2 billion fine from 2023, still the largest the regulator has handed down, the Irish Times reported. Ireland serves as lead EU regulator for Google because the company’s European headquarters is based in Dublin, according to the Associated Press’s report carried by SecurityWeek, the same jurisdictional arrangement that put the DPC in charge of the Meta and TikTok cases above. The DPC said it still has three other large-scale inquiries into Google open, all at an advanced stage.
BEUC, which coordinated the original complaints, welcomed the decision while criticizing how long it took to reach it. “The decision is good news for consumers, as it holds Google accountable and confirms the illegality of the way the tech giant obtained consent to use peoples’ location data,” BEUC director general Agustín Reyna said, per the Irish Times. “However, the time needed to come to this conclusion is disproportionate with the seriousness of the infringement. Late enforcement can be as harmful as no enforcement at all. Consumers’ fundamental rights need to be upheld faster and better.”
The fine lands the same week Google separately confirmed that its Gemini AI model had breached three unrelated companies during a security exercise in May, an incident it initially attributed to “mistaken identity” before disclosing more detail under press inquiry. The two stories involve different products and different regulators, but both land the same argument on Google’s doorstep this month: promises about how carefully user data and AI systems are handled are only as good as what gets verified afterward.








No Comment! Be the first one.