Excerpt from Reuters, Published on September 21, 2026
Ireland’s Data Protection Commission (DPC) has imposed a €403 million penalty on Google over its processing of users’ location data, marking a major EU fine against Google under the General Data Protection Regulation (GDPR). The penalty is equivalent to about $463 million.
The DPC said its inquiry examined Google’s “Web & App Activity,” “Location History,” and “Location Accuracy” features during the period from May 25, 2018, to February 4, 2020. The regulator found infringements involving the lawfulness and fairness of processing, transparency, accountability, and the retention of location data.
According to the DPC, Google’s practices could have left individuals unaware that their location information was being used to influence advertising or infer interests, limiting their control over personal data. The inquiry began in 2020 following complaints from European consumer rights organizations, including BEUC. The decision requires Google to bring its location-data processing into compliance within six months.
Google said the case concerns historical policies and that it has significantly changed its approach to location data since 2019. The company said it has introduced tools for automatic deletion, on-device storage of Timeline data, and greater control over how location information is used for advertising. It also said it now uses a general area rather than precise device location for Google searches.
The EU fine Google received highlights the governance requirements that apply when organizations collect, use, retain, and infer information from location data. The case shows why privacy controls need to address not only collection, but also transparency, retention periods, user controls, and the organization’s ability to demonstrate compliance. The penalty was the DPC’s fourth-largest fine and brings the regulator’s total penalties against major U.S. technology companies to more than €4 billion since GDPR enforcement began.
Organizations handling location or similarly sensitive personal data should review whether processing purposes are clearly communicated, retention is justified, user controls are effective, and compliance can be demonstrated through documented governance and operational evidence.
Source: For additional information, visit Reuters and Ireland’s Data Protection Commission.




