Ireland’s Data Protection Commission (DPC), acting as the lead regulator for Google across the European Union, announced on Monday that the tech giant will be fined €403 million ($462 million). The penalty addresses improper handling of user location data and marks the fourth-largest sanction issued by the DPC to date.
The investigation stems from complaints filed by consumer groups starting in 2018. The regulator determined that Google breached the EU’s General Data Protection Regulation (GDPR) between May 2018 and February 2020. Specifically, the DPC found that the company failed to ensure the lawfulness and fairness of processing location data collected through web and app activities.
Graham Doyle, deputy commissioner at the DPC, stated that Google’s failures meant individuals were often unaware their location was being used to target advertisements or infer personal interests. He noted that retaining this data for longer than necessary further exacerbated the loss of user control.
In addition to the financial penalty, the DPC has ordered Google to comply with GDPR requirements within six months. Google responded by emphasizing that its current practices have changed. “The case centres around historical policies that have since been updated,” the company said in a statement, adding that it has “significantly evolved our practices” since 2019 to provide users with better tools for managing their location data.
The ruling follows coordinated complaints received by the DPC in November 2018 from consumer organizations in the Czech Republic, Denmark, Greece, the Netherlands, Norway, Poland, Slovenia, and Sweden. Agustin Reyna, director general of the European Consumer Organisation (BEUC), welcomed the decision as a significant step toward accountability but criticized the timeline.
“However, the time needed to come to this conclusion is disproportionate with the seriousness of the infringement,” Reyna said. He warned that “late enforcement can be as harmful as no enforcement at all” and highlighted that geolocation data is among the most invasive forms of surveillance, capable of revealing sensitive details such as health status, political opinions, and religious beliefs.
Google currently faces three other advanced investigations by the DPC. These include proceedings launched in September 2024 regarding whether the company failed to conduct impact assessments for using European personal data to train its artificial intelligence models. The largest fine ever imposed by the DPC was €1.2 billion against Meta in 2023 for transferring user data to the United States.
Google calls it ‘historical,’ but that’s barely a year ago. €403 million is pocket change for them compared to the ad revenue generated from this data.
Eight years is an eternity in tech. Glad justice came, but this delay sets a terrible precedent for future GDPR enforcement.