Irish Regulator Fines Google €403 Million Over Location Data Tracking
Ireland's Data Protection Commission has fined Google €403 million for violating European privacy laws by obscuring how it collected and retained user location data. The ruling concludes a six-year investigation into the company's tracking practices across its Android and web services.
By Sergei Orlov
- Data Protection Regulators
- Argues that tech companies must process personal data transparently and cannot retain it indefinitely.
- Consumer Privacy Advocates
- Argues that users are often manipulated into sharing location data without understanding how it will be used.
- Cybersecurity Analysts
- Focuses on the technical reality that disabling one tracking feature often leaves others active.
Perspectives this story doesn't cover
- Small App Developers
- Digital Advertisers
When the Irish Data Protection Commission fined Meta €1.2 billion in 2023, the penalty centered on the cross-border transfer of user data to the United States. Google’s new €403 million fine, handed down this week by the same regulator, hinges on a different mechanism: the internal architecture of the company's own settings menus. The six-year inquiry concluded that Google violated the General Data Protection Regulation (GDPR) by obscuring how it collected, used, and retained the location data of its European users between May 2018 and February 2020.[1][4]
The investigation, which acts as the lead regulatory action for the European Union, examined three specific Google features: "Web & App Activity," "Location History," and "Location Accuracy." Regulators found that the company failed to meet the GDPR's standards for lawfulness, fairness, and transparency. According to the Data Protection Commission (DPC), Google's interface design left individuals unaware that their location was being used to infer their personal interests and influence the advertisements they were shown.[2][4][7]
The core technical issue involved the interplay between different account settings. Security analysts noted that users who explicitly turned off the "Location History" toggle might have assumed their movements were no longer being tracked. However, the separate "Web & App Activity" setting—which is often enabled by default—continued to collect and store location data in the background. This overlapping architecture meant that disabling a feature marketed as the primary location control did not actually stop the flow of location information to Google's servers.[5][6]
"Location data can bring both benefits and harms to individuals," said Graham Doyle, a deputy commissioner at the DPC. "It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private." The regulator emphasized that retaining this data for longer than necessary further aggravated the users' loss of control over their personal information.[4][7]
"Location data can bring both benefits and harms to individuals," said Graham Doyle, a deputy commissioner at the DPC.
The inquiry was originally prompted in 2018 by complaints from several European consumer rights organizations, including the European Consumer Organisation (BEUC) and the Norwegian Consumer Council. These groups argued that Google was using deceptive design practices to manipulate users into agreeing to constant mobile tracking. The resulting €403 million penalty is the fourth-largest fine ever issued by the Irish regulator, which oversees many of the major U.S. technology companies that maintain their European headquarters in Dublin.[1][2][5]
Google has responded to the ruling by emphasizing that the DPC's findings relate to legacy systems. A company spokesperson stated that the case centers around historical policies that have since been updated, noting that Google has significantly evolved its practices since 2019. The company highlighted the introduction of new tools designed to make managing location data simpler, including auto-delete options and less precise location storage. However, the DPC's compliance order indicates that the regulator still requires formal verification that these newer tools fully resolve the underlying transparency failures.[2][3][4]
Despite these updates, the regulatory order requires Google to bring all of the data processing covered by the decision into full compliance with the GDPR within six months. The ruling adds to a growing list of location-data settlements for the company, which previously agreed to pay nearly $400 million to a coalition of 40 U.S. states in 2022 over similar tracking practices. Google now has until March 2027 to demonstrate to the DPC that its current location architecture meets the transparency standards established by this €403 million penalty.[4][5][6]
For the broader technology industry, the DPC's decision signals that regulators will increasingly penalize companies that rely on fragmented or confusing privacy controls to maintain data collection. The ruling establishes that providing an opt-out toggle is insufficient if the underlying system continues to harvest the same telemetry through secondary channels.[3][6]
Key points
- The Irish Data Protection Commission fined Google €403 million for GDPR violations regarding location data.
- The inquiry found that Google's settings obscured how location data was collected and used for targeted advertising.
- Users who disabled 'Location History' were still tracked if the separate 'Web & App Activity' setting remained active.
- Google has been ordered to bring its data processing practices into full compliance within six months.
- Google stated that the fine relates to historical policies that were updated in 2019.
Viewpoints in depth
Data Protection Regulators
Argues that tech companies must process personal data transparently and cannot retain it indefinitely.
Regulators maintain that location data is inherently sensitive and can reveal highly private details about a person's life, including their religious beliefs, political leanings, and health conditions. The DPC asserts that overlapping or confusing settings menus violate the GDPR's core requirement that data processing be lawful, fair, and transparent, ultimately stripping users of control over their own information.
Consumer Privacy Advocates
Argues that users are often manipulated into sharing location data without understanding how it will be used.
Consumer rights organizations argue that technology platforms frequently employ "dark patterns"—deceptive user interface designs—to encourage continuous data sharing. They contend that the average user cannot be expected to navigate multiple, disconnected settings menus to achieve a basic level of privacy, and that regulatory fines are necessary to force companies to adopt privacy-by-default architectures.
Cybersecurity Analysts
Focuses on the technical reality that disabling one tracking feature often leaves others active.
Security researchers highlight the gap between user expectations and system architecture. When a user disables a feature labeled "Location History," they reasonably assume tracking has stopped. However, analysts point out that telemetry data is often routed through secondary channels like "Web & App Activity," allowing companies to maintain their advertising profiles while technically complying with the user's input on a specific toggle.
Why this matters
The €403 million penalty establishes a strict regulatory precedent that technology companies cannot use confusing settings menus to maintain continuous location tracking. For consumers, the ruling forces Google to simplify its privacy controls and explicitly clarify how location data influences targeted advertising.
Sources
[1]The GuardianConsumer Privacy AdvocatesGoogle fined more than €400m by Irish regulator over its use of location data
Read on The Guardian →
[2]The Irish TimesData Protection RegulatorsIrish data protection watchdog fines Google €403m over GDPR breaches
Read on The Irish Times →
[3]Android AuthorityCybersecurity AnalystsGoogle gets another $462 million fine, this time for misusing location history
Read on Android Authority →
[4]Data Protection CommissionData Protection RegulatorsData Protection Commission fines Google €403 million following Inquiry into Google's processing of location data
Read on Data Protection Commission →
[5]BitdefenderCybersecurity AnalystsGoogle hit with €403 million fine over location tracking
Read on Bitdefender →
[6]MalwarebytesCybersecurity AnalystsGoogle's location data privacy failures draw a €403 million fine
Read on Malwarebytes →
[7]The JournalConsumer Privacy AdvocatesGoogle fined €400m by Irish watchdog for not being clear it was using customers' location data
Read on The Journal →
Comments
More in Technology
See all →AI Regulation
Bipartisan Coalition of 26 Attorneys General Demands Federal AI Safety Regulation
5 sources
Digital Services Act
US Justice Department Intervenes in X's Appeal Against EU Digital Services Act Fine
7 sources
Battery Tech
The Mechanism of Cold-Weather Charging: Why Lithium-Ion Batteries Reject Fast Currents Below Freezing
8 sources
AI Hardware
UK AI Chip Startup Fractile Nears $6.5B Valuation After Securing $250M Anthropic Supply Deal
6 sources
Every angle. Every day.
Get Technology stories with full source coverage and perspective breakdowns delivered to your inbox.




