FFC 6 September 728/250

Google Fined €403 Million Over EU Location Data

Google Hit With €403 Million Fine Over EU Privacy Breach

NEW YORK: (News Desk) -Ireland’s Data Protection Commission (DPC), acting as the European Union’s lead privacy regulator for Google, has fined the technology giant €403 million ($462 million) over its handling of users’ location data.

The penalty is the fourth-largest fine ever imposed by the Irish regulator, which oversees Google at the European level because the company has its European headquarters in Ireland.

According to the DPC, Google breached the European Union’s General Data Protection Regulation (GDPR) between May 2018 and February 2020 by failing to properly process location data collected through its web and app activity and location history services.

The regulator said its final decision followed an investigation launched in February 2020. It concluded that Google had violated GDPR requirements concerning the lawfulness and fairness of its processing of users’ location information.

DPC Deputy Commissioner Graham Doyle said Google’s failures may have left users unaware that their location information could be used to influence advertising or infer their interests.

He added that retaining users’ location data for longer than necessary further reduced their control over how the information was used.

In addition to the €403 million fine, the DPC ordered Google to bring its practices into compliance with EU data protection rules within six months.

FFC 6 September 728/90

Google said the case concerned “historical policies that have since been updated”, adding that the company had significantly changed its practices since 2019 and introduced tools designed to make managing location data easier.

The case dates back to November 2018, when the DPC received coordinated complaints from consumer organisations in the Czech Republic, Denmark, Greece, the Netherlands, Norway, Poland, Slovenia and Sweden.

The European Consumer Organisation (BEUC), which coordinated the complaints, welcomed the regulator’s decision but criticised the length of time taken to reach a conclusion.

BEUC Director General Agustin Reyna described the ruling as an important decision that holds Google accountable over the way it obtained consent to use consumers’ location data.

However, Reyna said the delay was disproportionate to the seriousness of the alleged infringement, arguing that late enforcement could be nearly as damaging as a lack of enforcement.

BEUC also described geolocation information as one of the most intrusive forms of commercial surveillance because it can reveal sensitive details about individuals, including their religious beliefs, health information, political views and sexual orientation.

The DPC said Google is also facing three other investigations, all of which are at an advanced stage. One of them, opened in September 2024, examines whether Google failed to conduct an impact assessment concerning the use of Europeans’ personal data to train its artificial intelligence systems.

The largest fine previously imposed by the DPC was €1.2 billion against Facebook owner Meta in 2023 over the transfer of users’ data to the United States.

Comments are closed, but trackbacks and pingbacks are open.