Ireland’s data protection watchdog has fined Google €403 million for improperly using users’ location data.
The Data Protection Commission (DPC) announced the fine on Monday. The penalty is the fourth-largest the Irish regulator has imposed.
The DPC oversees Google at the European Union (EU) level because the company has its European headquarters in Ireland. The regulator said Google breached the EU’s General Data Protection Regulation between May 2018 and February 2020.
It found that Google failed to process location data lawfully and fairly through its web and app activity and location history services. DPC Deputy Commissioner Graham Doyle said some users may not have known how Google used their location data.
“As a result of Google’s failures, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests,” Doyle said. He added that keeping users’ location data longer than necessary further reduced their control over the information.
Alongside the fine, the DPC ordered Google to comply with EU data protection rules within six months. Google said the case focused on “historical policies that have since been updated”.
“From 2019 onwards, we’ve significantly evolved our practices and launched robust tools that make managing location data simple,” the company said.

The case followed coordinated complaints filed in November 2018 by consumer groups in eight European countries. The complaints were lodged through the European Consumer Organisation (BEUC).
BEUC welcomed the decision but criticised the length of the enforcement process. BEUC Director General Agustin Reyna called the ruling “an important decision” nearly eight years after the complaints were filed.
“The decision is good news for consumers, as it holds Google accountable and confirms the illegality of the way the tech giant obtained consent to use peoples’ location data,” Reyna said.
However, he warned that delayed enforcement could weaken consumer protection.
“Late enforcement can be as harmful as no enforcement at all. Consumers’ fundamental rights need to be upheld faster and better,” he added.
Read More : Google Says Gemini AI Conducted Cyberattacks
BEUC described geolocation data as one of the most invasive forms of commercial surveillance. It said such data can reveal sensitive information, including religious beliefs, health conditions, political opinions and sexual orientation.
The DPC said Google is also facing three other investigations, all at an advanced stage. One investigation, opened in September 2024, is examining whether Google failed to assess the impact of using Europeans’ personal data to train its artificial intelligence systems.
The DPC imposed its largest fine on Meta in 2023. The regulator fined the Facebook owner €1.2 billion for transferring users’ data to the United States.
Trending 







