Ireland's DPC Fines Google €403 Million Over Location Tracking Violations

Key Takeaways
- Ireland's Data Protection Commission fined Google €403 million ($463 million) for processing location data without a valid legal basis between May 2018 and February 2020.
- The DPC found Google failed to process location data lawfully, fairly, and transparently across Web & App Activity, Location History, and Location Accuracy.
- Google has been given six months to bring its data processing practices into compliance with GDPR.
- The case originated from complaints by seven European consumer organizations, based on 2018 research by Norway's Forbrukerrådet.
- The €403 million penalty is the fourth-largest fine issued by the Irish regulator, following fines against Meta, TikTok, and Instagram.
Irish Regulator Slaps Google with €403 Million Penalty
Ireland's Data Protection Commission (DPC) has issued a €403 million ($463 million) fine against Google for processing user location data without a valid legal basis. The penalty covers the period from May 2018 to February 2020.
The regulator also ordered the tech giant to bring its data processing practices into compliance with the General Data Protection Regulation (GDPR) within six months.
What the Investigation Found
The DPC determined that Google failed to process location data lawfully, fairly, and transparently across three products: Web & App Activity, Location History, and Location Accuracy.
The first two tools track browsing and search activity along with places a user's device has visited. Location Accuracy is an Android OS setting.
Deputy Commissioner Graham Doyle emphasized that while location data can improve online services, it can also expose highly private and sensitive information about individuals.
Users may not have realized their whereabouts were being used to target advertising or infer personal interests. Retaining such data longer than necessary further eroded user control.
Origins of the Case
The inquiry began with complaints from seven European consumer organizations, accusing Google of tracking users throughout their daily lives. Their concerns were based on 2018 research by Norway's consumer agency, the Forbrukerrådet.
That research argued Google used various tricks to keep Location History and Web & App Activity enabled. It also highlighted how location tracking can reveal religious beliefs, political views, health conditions, and even sexual orientation.
Finn Myrstad, digital policy director at the Norwegian Consumer Council, called the ruling a milestone. He said people should be able to understand what they are agreeing to without being misled or pressured.
The European Consumer Organisation (BEUC) described geolocation as one of the most invasive forms of consumer surveillance.
Google's Response and Regulatory Delay
Google has pointed to changes it made after the period covered by the inquiry. A spokesperson said the case concerns historical policies that have since been updated.
The company claims it changed its practices from 2019 onward and introduced tools to make location data easier to manage. The DPC's investigation started six years ago.
BEUC director general Agustín Reyna welcomed the decision but criticized the time taken to reach it. He called the delay disproportionate with the seriousness of the infringement and warned that late enforcement can be as harmful as no enforcement at all.
Why Ireland Leads the Case
Google's European headquarters are in Dublin, making the Irish watchdog its lead regulator across the 27-member EU. The DPC holds the same role for most major US technology companies with European bases in Ireland.
The €403 million penalty is the fourth-largest fine issued by the Irish regulator. Previous fines include €1.2 billion against Meta, €530 million against TikTok, and €405 million against Instagram.
The latest decision may not be the DPC's final action against Google this year, with three other investigations already at an advanced stage.
Coinasity's Take
The €403 million fine underscores the growing regulatory pressure on big tech over data privacy, a theme that resonates deeply in the crypto sector where data sovereignty and user consent are core principles.
While the penalty is significant, the six-year investigation timeline highlights the slow pace of enforcement. For crypto projects operating in Europe, this case serves as a reminder that GDPR compliance is not optional.
Location data and on-chain activity both raise privacy concerns, and regulators are increasingly willing to act. Crypto firms should prioritize transparency and user control to avoid similar scrutiny.
DISCLAIMER
This article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments involve substantial risk and extreme volatility - never invest money you cannot afford to lose completely. The author may hold positions in the cryptocurrencies mentioned, which could bias the presented information. Always conduct your own research and consider consulting a qualified financial advisor before making any investment decisions.
About Arthur J. Beckett
Core Developer at Coinasity.com | Blockchain Researcher
Leading the tech behind Coinasity, this account shares insights from a core dev focused on secure, scalable blockchain systems. Passionate about infrastructure, privacy, and emerging altcoin ecosystems.











