Cryptelio

Compliance

Ireland Fines Google €403 Million for GDPR Violations on Location Data

Cryptelio Editorial Published 21 Sep 2026 · 10:16 UTC

The Data Protection Commission (DPC) of Ireland has issued a substantial €403 million fine against Google for breaching the General Data Protection Regulation (GDPR) in its management of user location data. This penalty, equivalent to approximately $463 million, is one of the largest fines the DPC has levied since the regulation's inception.

The investigation, which covered the period from May 25, 2018, to February 4, 2020, was initiated following complaints from various European consumer rights organizations. These groups argued that Google failed to adequately inform users about how their location data was collected, stored, and utilized for targeted advertising purposes.

According to the DPC, Google violated key principles of GDPR, including lawfulness, fairness, transparency, and accountability. Deputy Commissioner Graham Doyle emphasized the importance of user control over personal data, stating, “Location data is personal data, and users must maintain control over how it is utilized by corporations like Google.”

This ruling requires Google to align its location data practices with GDPR standards within six months. The fine represents the DPC's fourth-largest under GDPR, amidst ongoing scrutiny of its enforcement actions against major tech companies.

Google has acknowledged the ruling and noted that it has made significant changes to its location data management practices since 2019. However, the DPC's decision reflects broader concerns regarding the transparency and legality of data practices among tech giants operating in Europe.

FAQ

What was the reason for the €403 million fine imposed on Google by the Data Protection Commission of Ireland?

The fine was imposed for breaching the General Data Protection Regulation (GDPR) in its management of user location data, specifically for failing to adequately inform users about how their location data was collected, stored, and utilized.

What period did the investigation into Google's location data practices cover?

The investigation covered the period from May 25, 2018, to February 4, 2020.

What are some key principles of GDPR that Google violated according to the DPC?

Google violated key principles of GDPR including lawfulness, fairness, transparency, and accountability.

What actions must Google take following the ruling by the DPC?

Google is required to align its location data practices with GDPR standards within six months of the ruling.

Has Google acknowledged the ruling and made any changes since the investigation?

Yes, Google has acknowledged the ruling and noted that it has made significant changes to its location data management practices since 2019.

Read story →