Ireland imposes €403M GDPR penalty on Google for location tracking breaches

Ireland's Data Protection Commission has fined Google €403 million for violating GDPR rules on location data processing. The investigation, launched in 2020, found that Google's Web and App Activity, Location History, and Location Accuracy features lacked proper transparency and retained data longer than allowed. Google must bring its practices into compliance within six months.
The investigation stemmed from complaints filed by consumer rights organizations in early 2020, covering a period from May 2018 through February 2020. Three Google features were scrutinized: Web and App Activity, Location History, and Location Accuracy, each handling location data differently across Google services and Android devices.
Google maintains that its practices have evolved since 2019, pointing to tools that let users schedule automatic data deletion and store Maps Timeline information locally on devices. The company also notes it no longer saves precise device location in Web and App Activity, relying instead on estimated general areas. The DPC's full decision has not yet been released.
This penalty could signal a firmer regulatory stance on location data practices across the tech industry. Users may gain greater awareness of how their movements are tracked and retained, potentially prompting more cautious engagement with location-based features. Other companies processing similar data may need to reassess their transparency and retention policies to avoid comparable enforcement actions, though the practical effect on Google's operations remains to be seen.