← Back to Feed

Google Fined €403 Million Over GDPR Violations Tied to Location Data

September 21, 2026 · The Hacker News · Severity: MEDIUM

Google has been  fined 403 million  for breaking the EU's data protection law, the GDPR, in the way three of its features handled people's location data from May 2018 to February 2020. Ireland's Data Protection Commission (DPC), Google's lead regulator in the EU, also ordered the company to make its processing comply with the law within 6 months. The DPC has not said publicly which processing the order covers, and it says its full decision will be published later. The three features ar.

Google has been  fined 403 million  for breaking the EU's data protection law, the GDPR, in the way three of its features handled people's location data from May 2018 to February 2020. Ireland's Data Protection Commission (DPC), Google's lead regulator in the EU, also ordered the company to make its processing comply with the law within 6 months. The DPC has not said publicly which processing the order covers, and it says its full decision will be published later. The three features are Web & App Activity, Location History and Location Accuracy. Web & App Activity is a Google account setting that, when turned on, lets Google process data about a user's activity on its sites and apps. That data can include location. Location History, which users must opt in to, keeps track of where they go with their signed-in mobile devices, even when they are not using a Google service. For both cases, the DPC found that Google breached the GDPR's rules on lawful and fair processing and on transparency, and that it retained location data longer than necessary. Location Accuracy is an Android feature that works out a device's location more precisely than GPS alone, and it is available to Android users with or without a Google account. The DPC's findings for this feature are narrower. Google broke the transparency rules and the GDPR's accountability rules because it could not demonstrate that this processing was lawful, fair and transparent. DPC Deputy Commissioner Graham Doyle said these failures meant people could have been unaware that their location was being used, for example, to influence them with ads or to infer their interests. They could also lose control of their personal data, and keeping it for so long made that worse. At 403 million, the fine is the fourth-largest the DPC has issued. It cannot be collected yet, because a DPC fine becomes payable only after  an Irish court confirms it . Google can  appeal to the High Court within 28 days  of receiving formal notice of the decision. In a statement  reported by the Associated Press , Google said the case "centers around historical policies that have since been updated" and that it has changed its practices significantly since 2019. In May 2019, during the period the DPC examined, Google  announced auto-delete controls  for Location History and Web & App Activity. They let users have that data deleted automatically after 3 or 18 months. In June 2020, Google  made 18-month auto-delete the default  for Web & App Activity on new accounts and for anyone turning on Location History for the first time. In December 2023, Google announced that Timeline, the Google Maps feature that shows Location History on a map, would  keep its data on users' devices . Auto-delete would also default to 3 months for anyone turning on Location History for the first time. The DPC has not publicly said whether these changes are sufficient to meet its order. The DPC opened its inquiry in February 2020 after complaints from European consumer groups, including BEUC, the European Consumer Organization. BEUC's member groups had  filed the complaints  with national data protection authorities in November 2018. The period the DPC examined ends on 4 February 2020, the day it announced the inquiry. The decision came more than 6.5 years after the inquiry opened. In comments  reported by NewsIreland.EU , BEUC director general Agustín Reyna welcomed it but criticized how long it took. "Late enforcement can be as harmful as no enforcement at all," he said. Found this article interesting? Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post.

Key Takeaways

  • Google has been fined €403 million over GDPR violations tied to location data privacy practices, representing one of the largest penalties under Europe's data protection framework.
  • The substantial fine reflects ongoing regulatory scrutiny of Big Tech location tracking practices and the financial risk of non-compliance with GDPR data processing requirements.
  • Organizations collecting location or behavioral data should review their consent mechanisms and data processing disclosures to ensure compliance with GDPR requirements.
☕ Buy a Coffee