Ireland’s Data Protection Commission fined Google 403 million euro on Sept. 21 after a six-year investigation into how the company processed the location data of people using Android phones and Google’s own apps and services. The penalty closes an inquiry the commission opened in February 2020 after several European consumer rights groups, including BEUC, complained about how Google handled that data through three specific features: Web and App Activity, Location History and Location Accuracy.
The Data Protection Commission, acting as Google’s lead supervisory authority under the European Union’s General Data Protection Regulation, examined Google’s conduct across those three features between May 25, 2018, when the regulation took effect, and Feb. 4, 2020. Commissioners Des Hogan, Dale Sunderland and Niamh Sweeney signed off on the final decision, which the regulator says it will publish in full at a later date.
Three location features drove a six-year Irish inquiry
Web and App Activity is a Google account setting that, once enabled, lets the company process a user’s activity across its sites and apps, including browsing history, search history and location data. Location History is a separate, opt-in service that tracks a signed-in user’s location through compatible devices to build a private “Timeline” map inside Google Maps, saving where a person went even when they were not actively using a Google service at the time. Location Accuracy is a feature built into the Android operating system that sharpens a device’s location beyond what GPS alone provides, using nearby Wi-Fi networks and cell towers rather than relying on the device’s GPS chip alone, and it applies to any Android user regardless of whether they hold a Google account. The Data Protection Commission’s decision covers how all three operated together.
The commission opened its inquiry on its own initiative in February 2020, rather than waiting for a single formal complaint, after several European consumer rights organizations flagged concerns about how the three features handled people’s location data. That own-initiative structure let the commission examine Google’s practices across the full window the regulation had then been in force, from the day it took effect in May 2018 through the inquiry’s launch less than two years later.
Regulators say Google buried what it was doing with location data
The commission found Google breached the General Data Protection Regulation on four separate grounds: the lawfulness and fairness of processing location data through Web and App Activity and Location History; a failure to demonstrate compliance with lawfulness, fairness and transparency requirements specifically for Location Accuracy; transparency failures across all three features; and retaining location data from Web and App Activity and Location History longer than necessary. Deputy Commissioner Graham Doyle said location data can be inferred by Google alone or combined with other information, and that it “can bring both benefits and harms to individuals,” enhancing online services while also revealing information that is “inherently private.”
Doyle said Google’s failures meant individuals could have been unaware their location was being used to influence them with ads or infer their interests, and that they could lose control over their personal data as a result, a loss of control the commission says the extended data retention made worse.
The fine carries a six-month deadline to fix it
The 403 million euro penalty comes with a six-month deadline, running to roughly March 2027, for Google to bring its location-data processing into compliance. The fine is worth about $463 million at current exchange rates. Ireland regulates Google’s European operations because the company’s regional headquarters sits in Dublin, an arrangement that has made the Data Protection Commission the lead authority under the GDPR’s one-stop-shop mechanism for most of Silicon Valley’s biggest names, coordinating with peer regulators in other EU member states before finalizing a cross-border decision like this one.
The 403 million euro penalty extends a pattern rather than starting one. The commission previously issued a record $400 million fine against Instagram’s parent company over how it handled children’s data, among other large penalties levied against major U.S. technology platforms since the GDPR took effect in 2018.
Google says the policies under scrutiny are already retired
Google has said the case centers on policies that applied years ago and that the company has since overhauled, telling reporters it has significantly changed its practices since 2019 and rolled out tools that make it simpler for people to manage what location data Google collects and stores about them.
That timeline means the practices the Data Protection Commission fined Google over predate most of the location controls Android and Google account holders see today, though the six-month compliance order gives the commission a fresh checkpoint to confirm the current versions of Web and App Activity, Location History and Location Accuracy actually meet the transparency and retention standards the decision lays out.
Whether that checkpoint satisfies the commission will not be clear until Google’s revised practices come back under review sometime around March 2027, when the six-month clock runs out and the regulator has to decide whether the changes Google has already made since 2019 go far enough to close the case for good.
More from Morning Overview
- Herbal supplements are landing Americans in the hospital with liver damage, doctors warn
- Long-term use of common heartburn pills is linked to kidney and dementia risk
- 9 pickup trucks with a reputation for falling apart after 100,000 miles
- Consumer Reports names the 2026 models it expects to break down the most
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.