Ireland’s Data Protection Commission fined Google €403 million for GDPR breaches in location data processing from 25 May 2018 to 4 February 2020. The findings covered unlawful and unfair processing, inadequate transparency, excessive retention and an accountability failure across Web & App Activity, Location History...
Published byEdited with GPT-5.6 TerraImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: Why did Ireland’s Data Protection Commission fine Google €403 million for GDPR breaches involving its Web & App Activity, Location History,. Article summary: Ireland’s Data Protection Commission (DPC) fined Google €403 million for GDPR breaches in its handling of location data through Web & App Activity, Location History and Location Accuracy from 25 May 2018 to 4 February 20. Topic tags: general, news, general web. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers,
Ireland’s Data Protection Commission (DPC) imposed €403 million in GDPR fines on Google Ireland Limited after examining how three features handled location data: Web & App Activity, Location History and Location Accuracy. The inquiry covered 25 May 2018—the day the GDPR began applying—to 4 February 2020, and followed complaints from European consumer organisations including BEUC. 4
The central issue was not simply that Google collected location information. The DPC concluded that, during the period investigated, Google did not meet GDPR requirements governing whether processing was lawful and fair, how clearly it was explained to people, how long certain data was retained, and how compliance was demonstrated. 4
The regulator’s decision identified different but connected failures across the three location-related features.
The DPC found infringements of the GDPR’s lawfulness-and-fairness principle in Google’s processing of location data through Web & App Activity and Location History. 4
That finding matters because these settings can connect location information with a person’s use of Google services. The DPC’s assessment was that Google’s processing practices in the period examined did not satisfy the GDPR standard that personal data be handled lawfully and fairly. 4
For Location Accuracy, the DPC found that Google failed to meet its accountability obligation: it could not demonstrate that its processing complied with the GDPR principle requiring processing to be lawful, fair and transparent. 4
Accountability is more than a promise to follow privacy rules. Under the DPC’s finding, Google needed to be able to show that its location-data processing complied with those requirements. 4
The DPC found transparency breaches across all three features. Its concern was the practical consequence for people: they could have been unaware that their location information was being used, for example, to influence advertising or to infer their interests. That lack of clarity could leave people without effective control over highly personal information about where they have been. 4
The regulator also found that Google kept location data in Web & App Activity and Location History longer than necessary. The DPC treated the retention issue as aggravating the loss of users’ control over data capable of revealing private details of their lives. 4
Google said the case concerned “historical policies” that had since changed. It said that from 2019 onward it had significantly evolved its practices and introduced tools intended to make location-data controls easier to manage. Google also pointed to auto-delete controls that let users set data to delete on a rolling three-, 18-, or 36-month basis. 2
Those later changes do not alter the DPC’s findings for the 2018–2020 period, but they are central to Google’s response that its current approach is different from the practices investigated. 2
Alongside the financial penalty, the DPC ordered Google to bring the processing at issue into compliance with the GDPR within six months. 4
BEUC, the European Consumer Organisation, was among the consumer groups connected to the complaints that led to the inquiry. It said the decision confirmed the illegality of how Google obtained consent to use people’s location data, while also arguing that the time taken to reach a decision was disproportionate. 24
BEUC’s position highlights two distinct consumer-protection questions: whether tracking practices meet GDPR standards, and whether enforcement arrives quickly enough to provide a meaningful remedy. 24
The case shows why location-data compliance cannot rest on a settings menu alone. Regulators may assess whether processing has a valid legal basis, whether people can understand how data will be used, whether retention is justified, and whether an organisation can prove that its design and governance meet those standards. In this case, the DPC found shortcomings across those areas and imposed a €403 million penalty. 4
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Ireland’s Data Protection Commission fined Google €403 million for GDPR breaches in location data processing from 25 May 2018 to 4 February 2020.
Ireland’s Data Protection Commission fined Google €403 million for GDPR breaches in location data processing from 25 May 2018 to 4 February 2020. The findings covered unlawful and unfair processing, inadequate transparency, excessive retention and an accountability failure across Web & App Activity, Location History and Location Accuracy.
Google has six months to bring the processing into compliance; it says the case concerns historical policies and that its controls have been substantially updated since 2019.