Google is facing one of the largest fines ever imposed by the Irish Data Protection Authority, as the Data Protection Commission (DPC) has imposed a fine of €403 million for the way the company handled data user location. The decision concerns practices from May 2018 to February 2020 and is linked to complaints from European consumer groups.

Location settings in focus
The investigation focused on how features such as Web & App Activity and Location History worked, as well as the Location Accuracy setting . The DPC found issues related to the lawfulness and fairness of the processing, as well as the transparency with which users were presented with the relevant choices.
See also: Google Maps Timeline now stores your location data on the device
According to the Irish authority, Google's practices could have resulted in users not fully understanding that their location data was being used in certain ways. Among other things, the data could be used to draw conclusions about interests and behaviors or for targeted advertising purposes .
Why transparency matters so much
The case is not simply about whether a user has a particular setting enabled or disabled. The issue examined was whether the way the options were presented allowed the user to truly understand what was happening with their data.
This position is particularly important in the case of location data, as a location history can reveal important information about a person's daily habits. The DPC has pointed out more generally that location data can reveal information about a person's habits, characteristics and activities.
The investigation began after the complaints
The case was initiated after complaints from consumer groups from several European countries, including BEUC, which alleged that Google's interface design could push users towards keeping location tracking.

The DPC launched its own investigation in February 2020, as part of its role as the lead supervisory authority for Google in the European Union. The process was examined under the cooperation mechanism provided for in the GDPR for cross-border cases.
See also: Google: New measures in the advertising market after the antitrust decision in the US
What does Google say?
Google has argued that the decision concerns older practicesthat have since been modified. The company has pointed to, among other things, the automatic data deletion that began to be introduced in 2019.
This position is significant as technology and data management arrangements have changed significantly in recent years. However, the DPC assessed the practices in place during the period covered by the investigation and found that there were breaches of GDPR requirements.
Six months for compliance
In addition to the fine, Google has been ordered to bring its data processing practices into line with the law within six months. The decision is therefore not limited to a financial penalty, but also requires changes to the way certain processing operations.
The €403 million fine is among the largest fines imposed by the DPC since the GDPR came into force. The Irish authority itself says that in total, its investigations have resulted in fines of more than €4 billion, although the fines are not enforceable until judicial confirmation is required and can be appealed.
See also: Google made search worse in Europe and publicly admitted it
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Another message about the data economy
The Google case shows that GDPR compliance is not just about the security of personal data, but also how companies explain to users what they collect, why they collect it, and how long they keep it.
For users, the issue translates into something very practical: privacy settings are not just technical options that are activated once. They can determine what data is recorded, how it is used, and how long it remains available.
The DPC decision thus highlights a broader trend in Europe: regulators are now examining not only what big tech companies do with personal data, but also how they present these practices to users themselves.
