Politics Business Culture Technology Environment Travel World
Home Technology Feature
Technology · Exclusive

Google fined €403m by Irish regulator over location data breaches

Google fined €403m by Irish regulator over location data breaches
Technology · 2026
Photo · Kai Lindgren for European Pulse
By Kai Lindgren Technology Editor Sep 21, 2026 4 min read

Ireland's Data Protection Commission (DPC) has imposed a €403 million fine on Google, concluding a six-year investigation into the company's handling of users' location data. The penalty, announced on Thursday, marks one of the largest GDPR fines ever levied against a tech firm and underscores the growing regulatory pressure on Big Tech in Europe.

The DPC, which acts as Google's lead supervisory authority in the European Union, opened its inquiry in February 2020 after complaints from several European consumer rights groups, including the Brussels-based BEUC. The investigation examined three Google features—Web & App Activity, Location History, and Location Accuracy—covering the period from 25 May 2018, when the GDPR came into force, to 4 February 2020.

Multiple GDPR breaches found

In its decision, the DPC concluded that Google had violated the GDPR on several fronts. The company failed to process location data lawfully and fairly through Web & App Activity and Location History, and did not demonstrate compliance with the lawfulness, fairness, and transparency principles for Location Accuracy. The regulator also found that Google fell short of its transparency obligations across all three features and retained users' location data for longer than necessary.

Deputy Commissioner Graham Doyle highlighted the sensitivity of location data, noting that it can reveal deeply personal information about individuals, even when combined only indirectly with other data Google holds. "As a result of Google's failures in this regard, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data," Doyle said. "The retention of users' location data for longer than necessary aggravated this loss of control."

The fine adds to a lengthening list of penalties that Brussels and national regulators have imposed on Google in recent years, spanning antitrust, advertising, and data protection. It also comes amid broader European efforts to rein in the power of digital platforms, including the EU's Digital Markets Act and the ongoing rollout of the EU digital ID wallet, which aims to give citizens more control over their personal data.

Compliance deadline and next steps

Alongside the fine, the DPC has ordered Google to bring its data processing practices into compliance within six months. The decision was made by the Commissioners for Data Protection, Des Hogan, Dale Sunderland, and Niamh Sweeney, and follows cooperation with peer supervisory authorities across the EU. The DPC said it would publish the full decision in due course.

Google has not yet indicated whether it will appeal the decision. The company has previously faced similar fines in Europe, including a €50 million penalty from France's CNIL in 2019 for lack of transparency in its consent processes.

The ruling is a significant moment for data protection enforcement in Europe, where regulators are increasingly willing to use the GDPR's full weight. It also highlights the role of Ireland, home to the European headquarters of many US tech giants, as a key battleground for privacy rights. The decision comes as Ireland's government has been active on other fronts, from energy security concerns to trade relations, but the DPC's actions remain a cornerstone of the country's regulatory influence in the digital sphere.

For consumers, the fine serves as a reminder that location data is a valuable commodity, often used for targeted advertising and user profiling. The DPC's decision reinforces the principle that companies must be transparent about how they collect and use such data, and that they must not hold onto it indefinitely.

As the EU continues to tighten its digital rules, this penalty may set a precedent for future enforcement actions against other tech companies operating in the bloc. The message is clear: privacy is not optional, and regulators are prepared to act.

More from this story

Next article · Don't miss

Russian drones hit Zaporizhzhia after Kyiv's massive aerial response

Russian drones hit apartment blocks, a university, and a shopping mall in Zaporizhzhia, wounding five. The attack came a day after Ukraine fired more than 1,000 drones at Russia, including hundreds aimed at Moscow. Diplomatic efforts remain stalled as leaders

Read the story →
Russian drones hit Zaporizhzhia after Kyiv's massive aerial response