Ireland's DPC fines Google €403 million over location-data GDPR violations
Ireland's Data Protection Commission fined Google Ireland Limited €403 million (roughly $459–463 million) for unlawful location-data processing and ordered compliance within six months.
Ireland's Data Protection Commission fined Google Ireland Limited €403 million on September 21, 2026, for GDPR violations in processing users' location data, and ordered the company to bring that processing into compliance within six months. The inquiry opened in February 2020 after complaints, including November 2018 complaints from BEUC and other consumer groups, and examined Web & App Activity, Location History, and Android Location Accuracy from May 25, 2018, through February 4, 2020. Reports describe unlawful or unfair processing, transparency failures, excessive retention, and accountability gaps; Security Affairs and The Record add that users may not have known location data was used for ads, profiling, and sensitive inferences. Reports disagree on the scope of the findings: The Hacker News limits lawfulness, fairness, and storage-limitation breaches to Web & App Activity and Location History and attributes only transparency and accountability failures to Location Accuracy, while SecurityWeek says all three features failed lawfulness, fairness, and transparency. Dollar conversions range from about $459 million (Malwarebytes) to $460 million (Infosecurity), $462 million (The Record), and $463 million (Help Net Security, SecurityWeek). Most outlets describe an exact €403 million fine that ranks as the DPC's fourth-largest EU privacy penalty, but The Record says the penalty exceeds €403 million and is the regulator's first fine against Google. The Record says Google had not commented, while several others quote Google calling the case one of historical policies updated since 2019. The Hacker News adds that the fine is payable only after an Irish court confirms it and that Google may appeal within 28 days; SecurityWeek says three further Google investigations remain open; Cyber Security News says the full decision and penalty breakdown were not yet published. Malwarebytes reports that location data continued to be collected through Web & App Activity even when users disabled Location History — first revealed by a 2018 Associated Press investigation and confirmed by Princeton researchers — and roughly $1.9 billion in prior U.S. payouts, including $1.38 billion to Texas, about $392 million to 40 states (Infosecurity cites $391.5 million for the 2022 settlement), and a $425 million class-action verdict.
- Ireland's DPC fined Google Ireland Limited €403 million on September 21, 2026; dollar conversions range from about $459 million (Malwarebytes) to $460 million (Infosecurity), $462 million (The Record), and $463 million (Help Net Security,…
- The inquiry opened in February 2020 after complaints including November 2018 complaints from BEUC and other consumer groups, and examined processing from May 25, 2018, through February 4, 2020 — roughly a six-year investigation.
- The case covered three features: Web & App Activity, Location History, and Android Location Accuracy.
- Findings cited failures of lawfulness, fairness, transparency, accountability, and excessive retention; Security Affairs and The Record note users may not have known location data was used for ads, profiling, and sensitive inferences.
- Reports disagree on scope: The Hacker News attributes lawfulness, fairness, and storage-limitation breaches only to Web & App Activity and Location History (transparency and accountability failures for Location Accuracy), while…
- Google was ordered to bring its location-data processing into compliance within six months.
- The Hacker News, SecurityWeek, and Security Affairs call the fine the DPC's fourth-largest EU privacy penalty; The Record alone says the fine exceeds €403 million and is the DPC's first fine against Google.
- The Hacker News reports the fine is payable only after an Irish court confirms it and that Google may appeal within 28 days.
Coverage timelineoldest first · each row is one article
- · 5d agoGoogle hit with €403 million GDPR fine over location tracking
Help Net Security· 64
Ireland’s DPC fined Google €403 million over unlawful processing of users’ location data.
- · 5d agoGoogle Hit with €403m GDPR Fine Over Location Data Practices
Infosecurity Magazine· 58
Ireland's DPC fined Google €403 million for unlawful GDPR processing and retention of user location data.
- · 5d agoGoogle fined €403 million over location data privacy violations
BleepingComputer· 10
Ireland’s Data Protection Commission fined Google €403 million for processing location data violating GDPR.