background image blur
background image
  • Blog
    >
  • News
    >
  • Ireland Fined Google €403M for Unlawful Location Data Processing

Ireland Fined Google €403M for Unlawful Location Data Processing

Image of author
By Tech Writer and VPN Researcher Gintarė Mažonaitė
clock icon
Last updated: 22 September, 2026
A tiny padlock on a laptop keyboard

Key Takeaways

  • Ireland's Data Protection Commission fined Google €403 million on Monday — one of the largest fines the Irish watchdog has issued — following an inquiry launched six years ago after complaints from European consumer rights organizations.
  • The DPC found that Google processed location data unlawfully, unfairly, and without transparency across three features: Web & App Activity, Location History, and Location Accuracy, between May 25th, 2018 and February 4th, 2020.
  • The DPC's deputy commissioner said users could have been unaware their location was being used to influence them with ads or infer their interests, and that retaining location data longer than necessary aggravated the loss of control.
  • In addition to the fine, Google has been ordered to bring its data processing practices into compliance within six months.
  • Google said the case concerns historical policies that have since been updated, pointing to auto-delete controls, simplified ads management, and increased transparency about location data practices it has introduced since 2019.

What Google Did and What the DPC Found

Ireland's Data Protection Commission opened an inquiry into Google's location data practices in 2018, following complaints from several European consumer rights organizations. The inquiry focused on three specific features — Web & App Activity, Location History, and Location Accuracy — during the period from May 25th, 2018, the date GDPR came into force, through February 4th, 2020.

The DPC's conclusion, published Monday alongside the €403 million fine, is that Google processed location data in a manner that was not lawful, fair, or transparent — three of the fundamental requirements GDPR places on any processing of personal data. 

The DPC's deputy commissioner, Graham Doyle, explained the practical consequence: users could have been unaware that their location data was being used to influence them with advertising or to infer their interests, and had no meaningful control over how long that data was retained. Retaining location data for longer than necessary, Doyle said, aggravated that loss of control.

Location data is any data that can be used to infer a person's physical location, and the DPC noted that it can reveal a significant amount of inherently private information about an individual — patterns of movement, visits to medical facilities, places of worship, political gatherings, or private addresses. Processing it without clear legal basis and without telling users what it is being used for is, on the DPC's reading, a straightforward violation of GDPR's core requirements.

Google's Response and What Has Changed

Google responded by pointing to the historical nature of the practices at issue. The company said the case concerns policies that have since been updated, and that from 2019 onwards it significantly evolved its data practices. 

The changes it cited include auto-delete controls that let users set their accounts to automatically delete data on a rolling three, 18, or 36-month basis; simplified ad management tools allowing users to turn off personalized ads entirely; and consolidated transparency documentation about its location data practices and account settings.

The six-month compliance order that accompanies the fine means the DPC is not satisfied that Google's existing practices fully meet GDPR's requirements — the historical-policy framing does not end the matter. Google will need to demonstrate, within six months, that its current processing of location data meets the standard the DPC is applying.

Six Years Is a Long Time to Wait for Accountability

The complaints that triggered the inquiry were filed in 2018. The DPC opened the inquiry the same year. The fine was issued in September 2026 — six years later. The practices at issue ran for less than two years. The enforcement process ran for six.

That gap isn’t unique to this case. GDPR enforcement in Ireland has been slow by the standards of other EU regulators, partly because Ireland is the European headquarters of most major US tech companies, making the Irish DPC the lead supervisory authority for an outsized share of the continent's most significant data processing operations. The volume and complexity of the cases, combined with the resources required to investigate companies at Google's scale, has produced a pattern of inquiries that take years to resolve.

The €403 million figure is large in absolute terms and modest relative to Google's scale. GDPR allows fines of up to 4% of global annual turnover for the most serious violations; this fine, while significant, falls well short of that ceiling. Whether fines at this level are sufficient to change the data practices of companies for whom location data is a core part of the advertising business model is a question enforcement actions alone are unlikely to answer.


Share on
Facebook share Twitter share Reddit share Linkedin share

Be part of the resistance, quietly.

Get Mysterium VPN Arrow icon
awareness campaign banner img
Image of author
Gintarė Mažonaitė
Tech Writer and VPN Researcher

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats in editorial pieces. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.

Read our editorial policy here.

Read more by this author
© Copyright 2026 UAB "MN Intelligence"