Google fined over €400m for location data misuse
Ireland’s Data Protection Commission fined Google €403 million for improperly processing users’ location data. The decision followed complaints from European consumer groups and an investigation into how Google tracked and used location history. The fine, the fourth largest imposed by the regulator…
By Felo News Desk · Published
On 15 September 2024, Ireland’s Data Protection Commission (DPC) announced a record fine of €403 million against Google for the unlawful processing of users’ location data. The penalty, the fourth largest imposed by the regulator, reflects the company’s failure to obtain a valid legal basis and to inform users about how their data was used to target advertising and infer personal interests.
How the Investigation Began
The inquiry began six years ago after a wave of complaints from European consumer organisations. They argued that Google’s tracking of every step users took—through location history, web and app activity, and location accuracy—constituted a breach of privacy. The complaints were backed by research from the Norwegian consumer agency Forbrukerrådet, which suggested that location data could reveal sensitive information such as religious beliefs, political leanings, health conditions, and sexual orientation.
Key Findings of the DPC Inquiry
The DPC’s investigation examined data collected between 25 May 2018 and 4 February 2020. Deputy Commissioner Graham Doyle explained that location data is a type of personal data that, when combined with other information, can infer an individual’s private details. He noted that while location tracking can enhance online services, it also poses significant privacy risks if not handled lawfully.
The regulator found that many users were unaware that their location was being used to influence advertising or to build detailed profiles of their interests. Moreover, Google’s retention of location data for longer than necessary was identified as a further violation of GDPR principles of data minimisation and purpose limitation.
The Fine and Compliance Requirements
Under the General Data Protection Regulation (GDPR), the DPC ordered Google to bring its processing of location data into compliance within six months. The €403 million fine is the largest penalty the Irish regulator has levied against a U.S. tech giant, following earlier fines of €1.2 bn against Meta, €530 m against TikTok, and €405 m against Instagram.
Google is required to overhaul its data handling practices, provide clearer user consent mechanisms, and ensure that location data is processed transparently and lawfully. Failure to comply could trigger further enforcement actions.
Broader Implications for Tech Companies
The ruling signals a broader trend of EU regulators tightening scrutiny over how big tech firms collect and use personal data. Three other large‑scale investigations into Google are already underway, indicating that the company’s compliance challenges are far from over.
For consumers, the decision highlights the importance of understanding how location services work and the need to review privacy settings on devices and apps. For businesses, it underscores the necessity of aligning data practices with GDPR requirements to avoid costly penalties.
As privacy concerns continue to rise, regulators across the EU are expected to adopt a more proactive stance, ensuring that companies cannot rely on opaque “tricks” to gather user data without explicit consent.
Google’s next steps will involve demonstrating tangible changes to its data processing framework and engaging with the DPC to confirm compliance. The outcome of this case will likely influence how other tech firms approach location data in the European market.
What Happens Next?
Google has six months to implement the required changes and submit evidence of compliance to the DPC. The regulator will monitor the company’s progress and may impose additional sanctions if the company fails to meet the stipulated deadlines. Meanwhile, consumer organisations will continue to advocate for stronger privacy protections, and other tech giants will likely review their own data practices in light of this precedent.
In the coming months, the EU’s data protection landscape is expected to evolve further, potentially leading to new guidelines on location data usage and stricter enforcement of existing GDPR provisions.
Overall, the fine serves as a stark reminder that even the most powerful tech companies must adhere to privacy laws and respect users’ rights to control their personal information.
Key facts
- Google fined €403m by Ireland’s DPC for unlawful location data use
- Investigation spanned data from 2018‑2020 and highlighted privacy breaches
- The fine is the fourth largest imposed by the regulator, after Meta, TikTok, and Instagram
- Google must overhaul consent mechanisms and comply within six months
- Three other large‑scale investigations into Google are ongoing
- The case signals stricter EU enforcement of GDPR for tech firms
Why it matters
The fine underscores the EU’s commitment to enforcing GDPR and protecting user privacy, setting a precedent for how tech giants handle location data.
Frequently asked questions
What is the Data Protection Commission (DPC)?
The DPC is Ireland’s national authority responsible for enforcing data protection laws, including the EU’s General Data Protection Regulation (GDPR).
Why was Google fined for location data?
Because it processed users’ location data without a valid legal basis, failed to inform users, and retained data longer than necessary, violating GDPR principles.
What must Google do to comply?
Google must change its data handling practices, provide clearer user consent, and demonstrate compliance to the DPC within six months.
Sources
- [1] theguardian.com — originally reported as “Google is fined more than €400m by Irish regulator over its use of location data”





