European privacy regulators have imposed a €403 million penalty—roughly $463 million—on Google after concluding that its handling of users’ location information violated the European Union’s General Data Protection Regulation. Ireland’s Data Protection Commission, which serves as Google’s lead EU privacy regulator because the company’s European headquarters are in Ireland, examined practices involving Web & App Activity, Location History, and Android’s Location Accuracy feature between May 25, 2018, and February 4, 2020. Regulators found problems involving lawfulness, fairness, transparency, accountability, and how long some location information was retained. The DPC said users could have been unaware that location information was being used to influence advertising or infer their interests. Google maintains that the investigation concerns historical practices that it has substantially changed since 2019, pointing to improved location controls, automatic deletion and reduced storage of precise location information. Beyond the financial penalty, Google has been ordered to bring the affected processing into compliance with GDPR requirements within six months. The case underscores an increasingly consequential question in digital privacy: whether merely giving consumers settings and consent mechanisms provides meaningful control when the underlying collection and use of personal information is complicated, dispersed across services, and difficult for an ordinary user to understand.
Key Takeaways
- The €403 million penalty resulted from findings concerning three Google features—Web & App Activity, Location History, and Location Accuracy—with regulators identifying violations involving transparency as well as the lawfulness, fairness, accountability, and retention of location data.
- The case reaches beyond a dispute over technical privacy disclosures. Location histories can reveal patterns about where people live, work, travel, worship, shop, and seek services, giving governments and technology companies strong reasons to demand particularly clear rules governing collection, retention, and commercial use.
- Google says the disputed practices are historical and that it has substantially changed its location-data systems since 2019. The DPC nevertheless ordered the company to bring the processing covered by its decision into compliance within six months, illustrating Europe’s willingness to impose substantial penalties years after the underlying conduct occurred.
In-Depth
Europe’s €403 million penalty against Google illustrates both the power and the limitations of aggressive government regulation of Big Tech. Ireland’s Data Protection Commission concluded that Google’s location-data practices violated GDPR requirements during a period stretching from May 2018 through February 2020. The investigation covered Web & App Activity, Location History and Location Accuracy, services capable of generating substantial information about where users go and how they use their devices.
The fundamental issue is meaningful consent. Regulators concluded that Google’s processing was deficient in areas including lawfulness, fairness and transparency, while also finding problems with accountability and retention. The DPC warned that users could have been unaware their location was helping influence advertisements or infer interests. That raises a legitimate concern about whether consumers can exercise genuine control when data practices are buried within complex ecosystems of settings, permissions and interconnected services.
Google counters that the ruling focuses on old policies. The company says it has substantially revised its practices since 2019, including providing stronger management tools and changing how location information is retained.
There is also reason to scrutinize regulators themselves. The inquiry began in 2020 and followed complaints dating to 2018, meaning enforcement took years. Privacy rules lose deterrent value when final decisions arrive long after technology and corporate practices have changed. Effective oversight should protect individual privacy without allowing regulation to become an endlessly expanding government bureaucracy. The enduring principle should be straightforward: companies collecting intimate information should clearly tell consumers what they collect, why they collect it, how long they keep it, and provide meaningful control over its use.
Sources
- https://www.dataprotection.ie/en/news-media/latest-news/data-protection-commission-fines-google-eu403-million-following-inquiry-googles-processing-location
- https://www.reuters.com/business/media-telecom/irish-regulator-fines-google-403-million-over-location-data-processing-2026-09-21/
- https://apnews.com/article/3447a228ad95b17c53e990dd0b4afd43
- https://www.bleepingcomputer.com/news/security/google-fined-403-million-over-location-data-privacy-violations/

