Google has been fined €403 million ($463 million) by the European Union for violating the bloc’s privacy rules related to users’ location data, the EU’s data privacy watchdog announced on Monday. The fine follows an investigation by Ireland’s Data Protection Commission, which found that Google mishandled location data collected through its Web & App Activity and Location History services, as well as the Location Accuracy feature on Android devices.
The probe, initiated six years ago, examined Google’s compliance with the EU’s General Data Protection Regulation (GDPR) from its implementation in 2018 until February 2020. Ireland’s Data Protection Commission, acting as the lead regulator for Google in the EU due to the company’s Dublin headquarters, concluded that Google did not lawfully or fairly process personal location data and lacked transparency in its handling of such information. Google responded by stating that the case focused on historical policies that have since been updated and highlighted improvements made since 2019, including new tools to help users manage location data.
The fine underscores the EU’s stringent enforcement of data privacy laws, particularly regarding sensitive personal information like location data. This penalty is one of the largest levied under GDPR against a major technology company for privacy violations. It reflects ongoing regulatory scrutiny of how tech giants collect and use personal data, emphasizing the need for transparency and user control. The case adds to a series of actions by EU regulators targeting data practices of U.S.-based technology firms.
The investigation covered Google’s practices over nearly two years following GDPR’s enforcement, concluding in early 2020. The €403 million fine is part of the EU’s broader effort to hold companies accountable for data privacy compliance, with Ireland’s Data Protection Commission playing a central role due to its jurisdiction over Google’s European operations.