Ireland’s Data Protection Commission (DPC) has handed Google a €403 million ($463 million) fine over the Google location data fine case, a set of GDPR violations related to how the company processed users’ whereabouts through three distinct account features. The decision caps an investigation that began in February 2020 and examined Google’s practices during the GDPR application period from 25 May 2018 to 4 February 2020.
According to Help Net Security, the DPC launched the inquiry on its own initiative after receiving complaints from several European consumer-rights organisations, including the European Consumer Organisation (BEUC). That’s a notable origin for an enforcement action of this scale: it started not with a regulator’s own audit, but with pressure from advocacy groups watching how Google was handling location signals across its ecosystem.
Three features, one investigation
The DPC scrutinised three Google features that were live during the relevant period. The first, Web and App Activity, is a setting for Google Account holders that allows Google to process activity across its services, potentially including browsing history, search history, and location data. The second, Location History, is an opt-in service that tracks users carrying compatible mobile devices, inferring visited places, activities and routes and surfacing that information through a private Google Maps Timeline, even when the user is not actively using a Google service. The third, Location Accuracy, is an Android feature that helps a device determine its position more precisely than GPS alone and is available regardless of whether the user holds a Google Account.
The DPC found that Google processed location data through Web and App Activity and Location History without meeting GDPR requirements. For Location Accuracy, the company failed to demonstrate compliance with GDPR principles when handling personal data. Across all three features, the regulator found Google had not met its transparency obligations. On top of that, Google retained location data collected through Web and App Activity and Location History for longer than was necessary, a point the DPC treated as an aggravating factor.
What the Google location data fine covers
Deputy Commissioner Graham Doyle put the concern in plain terms: ‘individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data. The retention of users’ location data for longer than necessary aggravated this loss of control.’
Beyond the €403 million in administrative fines, the DPC has ordered Google to bring its user data processing into compliance within six months. The full decision has not yet been published, though the DPC has stated it will be released in due course.
Google’s response, shared with BleepingComputer, frames the case as a matter of history rather than current practice. ‘This case centers around historical policies that have since been updated. From 2019 onwards, we’ve significantly evolved our practices and launched robust tools that make managing location data simple,’ a Google spokesperson said. Google added that it has added controls allowing users to set a specific timeline for automatically deleting account data, and that Google Maps Timeline information is now stored on the device and automatically removes data older than three months. The company also says it no longer saves precise device location in Web and App Activity, storing only an estimated general area instead.
Whether those post-2019 changes will satisfy the DPC’s six-month compliance order is a question the regulator’s full ruling will need to address. The Data Protection Commission has signalled it will publish the complete decision at a future date, at which point the precise scope of what Google is required to change (and what it may already have covered) will become clearer.

