Google Fined €403 Million Over Location Data Practices

Ireland’s DPC fined Google €403 million over GDPR violations involving location data, transparency, retention and user control.
Ireland’s Data Protection Commission (DPC) just fined Google €403 million, and the case behind it goes back six years, to a set of complaints that never really went away.
The DPC launched the investigation in February 2020 after receiving complaints from several European consumer groups, including BEUC, about how Google handled location data. The investigation covered the period from 25 May 2018, when the GDPR came into force, to 4 February 2020.
“The scope of the Inquiry concerned Google’s processing of location data in three specific features – “Web & App Activity”, “Location History” and “Location Accuracy” between the date of application of the GDPR, 25 May 2018 to 4 February 2020.” reads the DPC’s press release.
Three specific features sat at the center of it: Web & App Activity, Location History, and Location Accuracy. Web & App Activity tracks what a signed-in user does across Google’s own services, sites and apps included, and location data is part of that mix. Location History goes further, following a device’s movements over time and building a private Timeline map of everywhere that phone has been, even when the person isn’t actively using any Google service.
Location Accuracy works differently from the other two. It’s a feature baked into Android itself, sharpening location beyond what raw GPS alone provides, and it applies to anyone running the OS regardless of whether they’ve ever signed into a Google account. That last point matters, because it means the reach of this feature extends past Google’s own user base entirely.
The Commissioners, Dr Des Hogan, Mr Dale Sunderland and Ms Niamh Sweeney, found several problems with how Google handled location data. They said the processing behind Web & App Activity and Location History did not meet the GDPR requirements for lawfulness and fairness. They also found that Google could not show that its Location Accuracy feature complied with the rules on lawfulness, fairness and transparency. Transparency was a problem across all three features, and the company also kept location data for longer than allowed.
That’s four separate violations stacked on the same underlying data. Not one narrow technical slip, but a pattern spanning collection, retention and disclosure all at once.
“Location data is a type of personal data which is processed by way of location tracking, and includes data collected or processed by Google, which by itself or in conjunction with other information an individual’s location can be inferred.”said Deputy Commissioner Graham Doyle. “Location data can bring both benefits and harms to individuals. It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private.”
Knowing where someone is makes plenty of ordinary services genuinely more useful, better maps, better local search, faster delivery estimates. But the same data point, tracked continuously, tells you where someone works, who they see, what they believe, and what they might be hiding. There’s no version of location tracking that’s neutral by default.
The GDPR provides strong protection for personal data across the EEA and requires companies to process this data in a lawful, fair and transparent way.
According to the DPC, Google’s failures meant that users may not have known their location data was being used to target them with ads or build profiles about their interests. This could have reduced their control over their own data. The fact that Google kept location data for longer than necessary made the problem worse.
That’s the practical harm regulators actually care about. Not abstract privacy philosophy, but a real information gap: people not knowing their movements were being converted into ad targeting or interest profiles they never agreed to. If you don’t know it’s happening, you can’t opt out, correct it, or challenge it. The consent mechanism only works if the person on the other end actually understands what they’re consenting to.
Ireland’s Data Protection Commission (DPC) gave Google six months to bring its data processing practices in line with the GDPR. This is not Google’s first dispute with the Irish regulator, and the company is likely to face further scrutiny as location and behavioral data remain important to its advertising business. The investigation also took six years from the initial complaint to the final decision, showing how long GDPR enforcement cases can take.
The €403 million penalty ranks as the fourth-largest EU privacy fine issued by Ireland’s data protection regulator. The DPC has previously imposed even larger penalties on companies including TikTok and Meta, with Meta receiving a record €1.3 billion fine over the transfer of European users’ data to the US.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
Pierluigi Paganini
(SecurityAffairs – hacking, GDPR)

