Tech • AI • Robotics • Game

VIDEO
ENFR

Daily Podcast full article

Google fined €403 million in Ireland

Ireland’s Data Protection Commission has imposed a €403 million GDPR penalty on Google over location-data practices and ordered the company to bring the processing into compliance within six months, turning a long-running privacy inquiry into a fresh warning for platforms, advertisers and app developers that geolocation controls are no longer a checkbox exercise [1].

Generated September 25, 2026 at 10:15 AM UTC1386 words
AI-generated illustration

The ruling in brief

Google has been fined €403 million in Ireland after regulators concluded that the company breached EU privacy rules in the way it processed users’ location data through several core features . The European Data Protection Board’s summary says the Irish Data Protection Commission, acting as Google’s lead supervisory authority in the EU, announced a final decision against Google Ireland Limited after an inquiry into “Web & App Activity,” “Location History” and “Location Accuracy” .

The order is not just financial. Google must bring the relevant processing into compliance within six months, meaning the case now becomes a product, engineering and governance deadline as much as a legal sanction . The compliance order is especially important because location data is embedded in the way many digital services work: maps, search, ads, mobile operating systems, app analytics and nearby recommendations all depend on some version of place-based inference.

The case examined the period from 25 May 2018, when the GDPR became applicable, to 4 February 2020 . That historical window matters because Google has said the case concerns older policies and that it has evolved its location-data practices since 2019 . But the penalty still lands in 2026 with present-day consequences: regulators are judging past designs, and companies are learning that old consent flows can create liabilities years later.

What the DPC found

The DPC’s findings, as summarized by the EDPB, were broad. Regulators found infringements linked to the lawfulness and fairness of Google’s processing of location data in Web & App Activity and Location History . They also found that Google failed in its accountability obligations because it could not demonstrate compliance with the lawfulness, fairness and transparency principle for personal data processed through Location Accuracy .

Transparency was another core issue. The DPC found infringements of transparency obligations across all three features, and it also identified retention problems involving location data in Web & App Activity and Location History . In practical terms, this means the case was not limited to whether Google had a toggle or a policy page. It went to whether people were adequately told what location data was being collected, how it was being used, how long it was kept and which settings actually controlled which processing.

The Associated Press report, republished by The Economic Times, described Web & App Activity as a Google account setting that tracks browsing and search history, while Location History maps places users have been with their mobile devices . Regulators also found problems in Google’s processing of personal data through Location Accuracy, an Android feature used to improve device-location estimates .

The DPC’s deputy commissioner Graham Doyle said location data can improve online services but can also reveal highly private information about an individual . That framing is central to the case: geolocation is useful precisely because it is intimate. A route to work, a medical visit, a place of worship, a political event or a repeated late-night stop can all become behavioral signals when combined with other data.

Why €403 million matters

The penalty ranks among the largest privacy sanctions issued by the Irish watchdog. AP reported that it is the fourth biggest EU privacy fine issued by the DPC, behind larger penalties previously imposed on TikTok and Meta, including Meta’s €1.2 billion fine . The amount also reflects Ireland’s outsized role in European technology regulation, because many large U.S. technology companies have their European headquarters in Dublin and therefore fall under the DPC as lead regulator for cross-border GDPR cases .

For Google, €403 million is not an existential sum. For the digital advertising and mobile ecosystem, however, the signal is more expensive than the fine. The case tells product teams that the legal quality of consent and transparency must match the technical reality of data flows. If disabling one location-related setting does not stop all location-related collection, the user interface, explanations and retention rules must make that distinction clear.

Malwarebytes, in its September 24 analysis, emphasized the confusion between Location History and Web & App Activity: turning off Location History did not necessarily turn off location collection associated with Web & App Activity [3]. That point is why the ruling matters beyond Google. Many services split data controls across account settings, device settings, app permissions, diagnostics settings and advertising preferences. If those controls overlap poorly, users may believe they have opted out when a parallel data stream is still active.

The six-month clock

The six-month compliance order is the operational heart of the decision. A fine punishes past conduct, but a compliance order forces current systems to change or to prove that they already meet the standard . For a company operating at Google’s scale, that can require legal review, user-interface changes, data-retention adjustments, documentation updates, audit trails and possibly new internal controls for how location signals are reused.

Tech Policy Law’s September 22 brief noted that the DPC found failures of transparency, lawfulness and data retention and ordered compliance within six months [4]. The same brief also observed that the DPC’s release did not state whether Google intended to appeal [4]. That leaves two parallel tracks: Google may contest aspects of the decision, but the compliance deadline still creates pressure to show regulators that location-data processing is now demonstrably lawful, fair and transparent.

Google’s public response has focused on the age of the practices. According to AP, the company said the case centered on historical policies that had been updated and that, from 2019 onward, it had significantly evolved its practices and launched tools to make location-data management simpler . That argument may matter in any appeal or mitigation discussion, but it does not erase the regulatory conclusion that the assessed practices breached GDPR obligations.

Implications for advertisers and app developers

Advertisers should pay attention because the DPC explicitly connected location data to influence, interest inference and advertising. Malwarebytes reported that, during the period reviewed, Google collected users’ location data without making clear that it could be used to infer interests and shape the ads they saw [3]. If location signals feed audience segmentation, conversion measurement or personalization, advertisers inherit reputational and compliance risk even when the platform collects the data.

App developers face a related lesson. A mobile app may rely on platform-level location services, advertising identifiers, analytics SDKs or account-level settings it does not fully control. The Google case shows that regulators can look across the stack, not only at a single permission prompt. If an app tells users that location is used for navigation or nearby features, but the broader ecosystem uses related signals for profiling or ad targeting, the transparency burden becomes harder.

Cloud customers should read the decision as a governance warning rather than a direct indictment of cloud infrastructure. The ruling concerns Google’s own consumer-facing data practices, not a finding that Google Cloud customers processed data unlawfully . Still, customers using location analytics, mobility insights or advertising integrations should expect procurement and privacy teams to ask sharper questions about lawful basis, retention periods, controller-processor roles and proof of compliance.

The bigger GDPR message

This decision reinforces a maturing phase of GDPR enforcement. Early compliance often focused on banners, privacy notices and formal consent language. The Google fine shows regulators are looking deeper: whether the actual product architecture corresponds to what users reasonably understand, whether data is kept longer than necessary and whether a company can prove that its processing meets GDPR principles .

The case also narrows the gap between privacy design and business design. Location data is valuable because it improves services and advertising, but that value increases the compliance burden. A platform cannot treat geolocation as ordinary telemetry if it can reveal where people live, travel, worship, work or seek care.

The simplest takeaway for the wider tech sector is blunt: settings must mean what users think they mean. If a location control is partial, conditional or overridden by another setting, that must be explained clearly at the moment it matters. Even Google Maps cannot route around the GDPR boss battle; the road now runs through consent, retention, transparency and proof.

Comments

Be the first to comment.

Sources from the last 72 hours

  1. [1]The Irish Data Protection Commission fines Google 403 000 000 EUR following Inquiry into Google’s processing of location dataSep 23, 2026, 12:00 AM UTC
  2. [2]Google’s location data privacy failures draw a €403 million fineSep 24, 2026, 12:00 AM UTC

AI-generated article based on recent web research, then preserved as a dated editorial snapshot.