Ireland’s Data Protection Commission has fined Google more than 403 million euro (462 million dollars) for the way it processed location data and ordered the company to bring that processing into compliance within six months. The decision, announced on Monday 21 September, closes an inquiry the DPC opened in February 2020.
It is the first time the DPC has penalised Google, according to The Record, despite the regulator acting as the company’s lead supervisory authority in the EU because Google’s European headquarters sit in Dublin. The Irish Times puts it fourth on the DPC’s list of GDPR fines behind Meta’s 1.2 billion euro in 2023, TikTok’s 530 million euro and Instagram’s 405 million euro.
The Case Started With a Report From Oslo
Forbrukerradet, the Norwegian Consumer Council, published research in November 2018 under the title Every Step You Take, documenting how Google’s interface design nudged Android users into leaving location collection switched on. On 27 November 2018, seven consumer organisations coordinated by BEUC filed complaints with their national data protection authorities on the back of it. The signatories came from Norway, the Netherlands, Greece, the Czech Republic, Slovenia, Poland and Sweden. Sveriges Konsumenter was one of them. Denmark and Finland were not.
The DPC opened its own-volition inquiry on 4 February 2020.
What the Decision Covers, and What It Does Not
The inquiry examined three Google features, Web & App Activity, Location History and Location Accuracy. The window runs from 25 May 2018, when the GDPR became applicable, to 4 February 2020. The DPC found that Google processed location data unlawfully and unfairly through Web & App Activity and Location History and that it failed to demonstrate compliance with the lawfulness, fairness and transparency principle for Location Accuracy. Holding the data longer than necessary was treated as an aggravating factor rather than a separate technical breach.
Deputy Commissioner Graham Doyle said location data can reveal information about a person that is “inherently private”. The decision was taken by Commissioners Des Hogan, Dale Sunderland and Niamh Sweeney and the DPC says the full text will follow.
Everything after February 2020 sits outside the inquiry. The Record reports that it is unclear whether Google still processes any of the data in the way the DPC found unlawful. Google told RTE that the case concerns historical policies and that it has changed its practices since 2019, adding auto-delete settings and ad management controls. That is a claim about a period the regulator did not examine and the six-month compliance order exists precisely because the DPC is not taking it on trust.
Six Years Is the Part Worth Reading
BEUC director general Agustin Reyna welcomed the outcome, telling The Irish Times it holds Google accountable and confirms the consent practices were unlawful. He is right on the substance. He is also describing a case that took six years and one month from complaint to decision covering conduct that stopped being examined before the pandemic.
For a Nordic compliance officer, that timeline is the practical lesson rather than the sum. Whatever your organisation decided about telemetry, consent flows and retention in 2026 will be judged against a standard that has not yet been written by a regulator that may not look at it until 2032. The Irish Times understands Google may appeal parts of the decision which would push the endpoint further out still.
Three Questions For Your Own Location Data
- Where does location or device telemetry enter your systems and on what lawful basis? The DPC’s finding was about lawfulness and fairness first. Retention came second.
- How long do you keep it and can you show why that period is necessary? Keeping it longer than needed was what the DPC said deepened the loss of control for users.
- Can a user switch it off once in one place? The 2018 complaint’s central allegation was design that kept asking until people gave in.
Google has six months and a regulator watching. Nobody is setting you a deadline until an inquiry lands on your desk.
References
- EU Data Regulator Fines Google More Than $460 Million for Location Data Violations
- Data Protection Commission Fines Google 403 Million Euro Following Inquiry Into Google’s Processing of Location Data
- Irish Data Protection Watchdog Fines Google 403m Over GDPR Breaches
- Every Step You Take
- Google Fined 403m Euro By Irish Watchdog Over Location Data
This post is also available in:

