Irish DPC fines Google €403m over historical location-data GDPR breaches
Ireland’s Data Protection Commission fined Google Ireland Limited EUR 403 million for GDPR breaches over processing of location data between May 2018 and February 2020 across Web & App Activity, Location History and Location Accuracy, ordering compliance within six months; the fine awaits Irish court confirmation.
Ireland’s Data Protection Commission (DPC) adopted a final decision on 21 September 2026 imposing administrative fines of EUR 403 million on Google Ireland Limited for breaches of the GDPR in how it processed users’ location data between 25 May 2018 and 4 February 2020. The DPC examined Web & App Activity, Location History and Location Accuracy and found infringements including unlawful or unfair processing, accountability and transparency failures, and retention longer than appropriate.
Why it matters
- The decision orders Google to bring its processing into compliance within six months and can only be collected after Irish court confirmation; Google may appeal.
- The case highlights regulator scrutiny of historical tech-sector data practices and the GDPR risks from location processing, retention and transparency failures.
Sources
Check the original material below. How we use sources
- Primary sourceDPC announcement of Google location-data fine