Ireland’s Data Protection Commission just handed Google a €403 million bill for playing fast and loose with user location data. The fine, equivalent to roughly $463 million, lands as one of the largest GDPR penalties ever issued by the Irish regulator, which serves as the lead privacy enforcer for most US tech giants operating in Europe.
The penalty stems from Google’s processing of location data collected between May 25, 2018, and February 4, 2020, a period during which the DPC found the company failed to adequately inform users about how their whereabouts were being tracked, stored, and monetized.
What Google got wrong
The inquiry kicked off after complaints from multiple European consumer rights organizations flagged Google’s handling of location data. Their core argument: users had no real idea their location information was being fed into targeted advertising systems and used to infer personal interests.
The DPC agreed. After completing its investigation, the commission concluded that Google violated GDPR requirements around lawfulness, fairness, transparency, and accountability.
Deputy Commissioner Graham Doyle put it plainly.
“Location data is personal data, and users must maintain control over how it is utilized by corporations like Google.”
The ruling requires Google to bring its location data practices into full compliance within six months.
Ireland’s growing enforcement muscle
This marks the DPC’s fourth-largest GDPR fine since the regulation took effect in 2018. For years, the Irish regulator faced criticism from other EU member states and privacy advocates for being too slow, too lenient, and too cozy with the Silicon Valley companies headquartered in its jurisdiction. Ireland’s low corporate tax rate has made Dublin the European home for Apple, Meta, Google, and others, placing the DPC in the awkward position of regulating the companies that contribute significantly to the Irish economy.
For context, GDPR allows fines of up to 4% of a company’s global annual revenue. Alphabet reported over $300 billion in revenue for its most recent fiscal year, meaning a maximum theoretical fine could stretch well into the tens of billions. The €403 million penalty, while headline-grabbing, represents a fraction of that ceiling.
The broader location data reckoning
Your phone’s location history can reveal where you work, where you worship, who you visit, what doctors you see, and what protests you attend. That’s precisely why GDPR demands explicit, informed consent before companies can collect and process it.
The period covered by this investigation, from GDPR’s enforcement date in May 2018 through early February 2020, captures a window during which many tech companies were still adjusting to the new regulatory reality. Google has since made changes to its location data settings and consent flows, but the DPC’s ruling suggests those early practices fell well short of what the law required.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 hour ago
9






English (US) ·