Google Slammed with €403 Million Fine for EU Location Data Violations
The Irish Data Protection Commission has fined Google €403 million ($463 million) for violating European Union privacy rules on handling users' location data. The penalty is one of the largest issued under the General Data Protection Regulation (GDPR), which took effect in 2018.
The investigation, which began in 2020, examined three Google features: Web & App Activity logs, Location History, and Location Accuracy. Regulators concluded that Google did not process data lawfully or fairly in these features, failed to meet transparency requirements, and broke data retention rules.
According to Deputy Commissioner Graham Doyle, users may have been unaware their location was being used to target them with ads or infer their interests, potentially losing control over their personal data as a result. The commission ordered Google to bring its location data processing into full compliance with GDPR within six months.