Google Dublin
Google's European headquarters are located in Dublin, Ireland. Credit: Stephen Bergin / Unsplash

EU data regulator fines Google more than $460 million for location data violations

Ireland’s Data Protection Commission (DPC) will fine Google more than €403 million ($462 million) for the tech giant’s processing of location data, the regulator said Monday, concluding an inquiry into the company that began in February 2020.

Google has also been ordered to fix its data processing practices within six months, according to the regulator’s press release. The DPC is the European Union’s lead supervisory authority charged with overseeing Google’s data protection practices because the platform’s European headquarters are based in Dublin. 

The inquiry began more than six years ago after several European consumer rights groups asked the DPC to look into Google’s practices, which allegedly violated Europe’s General Data Protection Regulation (GDPR). 

The inquiry focused on how Google processes location data in connection with three of its services and features: web and app activity, location history and location accuracy, the DPC said. Google’s practices allegedly violated GDPR due to how it tracked and stored the location data.

The inquiry examined Google’s data processing norms beginning in May 2018 — when GDPR became law — through February 2020.

It is unclear if Google still processes at least some of the allegedly illegal data or if it has updated its approach. Monday’s fine is the first time the DPC has punished Google, though other tech giants like TikTok and Meta have been fined hundreds of millions on multiple occasions.

A spokesperson for Google did not reply to a request for comment.

The DPC inquiry focused on whether Google’s data processing norms were legal and fair and whether the tech company complied with transparency and accountability requirements under the GDPR. Investigators also probed the company for retaining location data in its web and app activity and location history features.

The DPC highlighted the sensitivity of location data, “which by itself or in conjunction with other information an individual’s location can be inferred,” DPC Deputy Commissioner Graham Doyle said in a statement.

“It can also reveal a significant amount of information about an individual, including information that is inherently private.”

The GDPR is a notably tough data protection law enforced throughout the European Economic Area (EEA), which gives citizens significant data protection rights.

“As a result of Google’s failures in this regard, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data,” the press release said. “The retention of users’ location data for longer than necessary aggravated this loss of control.” 

Recorded Future
No previous article
No new articles
Suzanne Smalley

Suzanne Smalley

is a reporter covering digital privacy, surveillance technologies and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.