Ireland’s Data Protection Commission (DPC) has fined Google €403 million ($463 million) after finding that the company violated European Union privacy rules in its handling of users’ location data.
The regulator announced its final decision on Monday following an investigation into location data processing by Google Ireland Limited under the EU’s General Data Protection Regulation (GDPR).
The DPC opened the inquiry on its own initiative in February 2020 after receiving complaints from several European consumer rights organisations.
Investigators examined Google’s handling of location information between May 2018 and February 2020 across three features: Web & App Activity, Location History and Location Accuracy.
The commission concluded that Google breached GDPR requirements relating to the lawfulness and fairness of data processing as well as its accountability obligations.
It also found shortcomings in the company’s transparency practices across all three features and determined that some users’ location information had been retained for longer than necessary.
The DPC imposed administrative fines totalling €403 million and ordered Google to bring the affected data-processing practices into compliance with GDPR requirements within six months.
DPC Deputy Commissioner Graham Doyle highlighted the sensitivity of location information, warning that it can reveal inherently private details about an individual and that improper processing can result in people losing control over their personal data.
Doyle added that retaining users’ location information for extended periods further aggravated that loss of control.


