Google has been fined €403 million ($463 million) by Ireland’s Data Protection Commission (DPC) for violating European Union privacy rules over the way it handled users’ location data. The decision was announced on September 21, 2026, after an investigation into Google’s location-tracking practices. The case focused on how personal location information was processed through some of Google’s services and Android features.

The investigation covered three Google features: Web & App Activity, Location History and Location Accuracy. Regulators examined Google’s practices from May 25, 2018, to February 4, 2020, when the EU’s General Data Protection Regulation (GDPR) rules applied. The DPC found issues with the lawfulness and fairness of processing location data through Web & App Activity and Location History.

The regulator also found problems with transparency across all three features and said Google could not demonstrate compliance with GDPR requirements for Location Accuracy. It also found that location information was retained through Web & App Activity and Location History. According to the DPC, these practices could have left people unaware of how their location information was being used and could reduce their control over their personal data.

The inquiry was opened in February 2020 after complaints from several European consumer organisations, including the European Consumer Organisation (BEUC). The DPC said location data can reveal significant information about a person and can sometimes expose details that are inherently private. The regulator also said that keeping users’ location data for longer than necessary increased the loss of control over that information.

Google said the case relates to historical policies and that its practices have changed since the period covered by the investigation. The company said that since 2019 it has introduced stronger tools for managing location data, including automatic deletion options and controls over how location information is used for advertising. Google also said Timeline data can be stored directly on a device and that searches may use an estimated general area instead of a precise location.

Along with the €403 million fine, the DPC has ordered Google to bring its location-data processing into full GDPR compliance within six months. The penalty is the fourth-largest fine issued by Ireland’s Data Protection Commission, which has previously imposed larger penalties on companies including Meta and TikTok. The regulator also said that three other privacy investigations involving Google are still ongoing.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news