Irish data protection watchdog fines Google €403m over GDPR breaches

Users may have been ‘unaware’ that location data was being used to ‘influence them with ads’

The DPC said its investigation, which began in 2020, found that Google infringed the GDPR by processing users' location data unlawfully and unfairly through three of its features. Photograph: Sam Boal/RollingNews.ie
The DPC said its investigation, which began in 2020, found that Google infringed the GDPR by processing users' location data unlawfully and unfairly through three of its features. Photograph: Sam Boal/RollingNews.ie

Ireland’s Data Protection Commission (DPC) has fined Google €403 million for breaches of European information privacy laws related to the tech giant’s processing of its users’ location history and data.

As a result of these infringements, Google users may have been “unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data”, said DPC deputy commissioner Graham Doyle in a statement.

It is understood that Google may appeal elements of the decision.

Under the EU’s General Data Protection Regulation (GDPR), the processing of such data must be lawful, fair and transparent.

The DPC said its investigation, which began in 2020, found that Google infringed the GDPR by processing users’ location data unlawfully and unfairly through three of its features.

“Location data is a type of personal data which is processed by way of location tracking, and includes data collected or processed by Google, which, by itself or in conjunction with other information, an individual’s location can be inferred,” he said.

Google has been given six months to address the issues. However, the tech giant said the case centres around “historical policies” that have since been updated.

“From 2019 onwards, we’ve significantly evolved our practices and launched robust tools that make managing location data simple,” a Google spokesperson said.

The company now allows users to delete their data automatically once a certain period has expired, between three and 36 months. Google also stores location data that populates the Timelines feature on Google Maps on users’ devices, and simplified the management of how personal data is used for ad personalisation.

The €403 million fine is the fourth largest that the DPC has handed down since the GDPR came into force. The largest remains Meta’s €1.2 billion fine imposed in 2023.

The decision was welcomed by the European Consumer Organisation, BEUC, which submitted one of the complaints to the DPC.

“The decision is good news for consumers, as it holds Google accountable and confirms the illegality of the way the tech giant obtained consent to use peoples’ location data,” said Agustín Reyna, director general of BEUC. “However, the time needed to come to this conclusion is disproportionate with the seriousness of the infringement. Late enforcement can be as harmful as no enforcement at all. Consumers’ fundamental rights need to be upheld faster and better.”

Location data is considered particularly sensitive because it can be used to reveal details about users’ personal lives, from religious beliefs and health conditions to political opinions.

  • From maternity leave to remote working: Submit your work-related questions here

  • Listen to Inside Business podcast for a look at business and economics from an Irish perspective

  • Sign up to the Business Today newsletter for the latest new and commentary in your inbox

Ian Curran

Ian Curran

Ian Curran is a Business reporter with The Irish Times
Ciara O'Brien

Ciara O'Brien

Ciara O'Brien is an Irish Times business and technology journalist