Ireland fines Google €403M for mishandling location data under GDPR
Ireland's data watchdog fined Google €403 million over location data privacy breaches.
Why it matters: This penalty signals intensifying enforcement of EU privacy laws, stressing compliance risks for global tech firms and their legal teams. It highlights ongoing scrutiny on handling sensitive user information like location data.
- Ireland's Data Protection Commission fined Google €403 million on September 21, 2026.
- The investigation covered Google's location data use from May 25, 2018 to February 4, 2020.
- Google must comply with GDPR rules within six months or face enforcement action.
- This is the fourth-largest privacy fine by Ireland’s DPC, following larger fines on Meta and TikTok.
On September 21, 2026, Ireland's Data Protection Commission (DPC) imposed a €403 million fine on Google Ireland Limited for breaching the European Union's General Data Protection Regulation (GDPR). The investigation, which began in February 2020, scrutinized Google’s processing of location data across features such as 'Web & App Activity,' 'Location History,' and 'Location Accuracy' between May 2018 and February 2020.
The DPC found Google unlawfully and unfairly processed location data specifically in 'Web & App Activity' and 'Location History,' failed to prove compliance for 'Location Accuracy,' and lacked transparency in all these features. Graham Doyle, Deputy Commissioner at the DPC, emphasized that location data can reveal "a significant amount of information about an individual, including information that is inherently private."
Google said the case pertains to historic policies that have since been revised. Since 2019, Google has implemented stronger controls and tools for users to manage location data, reflecting significant changes in their practices. However, Google now faces a six-month deadline to bring its location data processing fully into compliance with GDPR or risk enforcement action.
This fine ranks as the fourth-highest privacy penalty by the Irish regulator, following larger fines issued to Meta and TikTok. The ruling reinforces the growing trend of strict GDPR enforcement in the EU, underscoring heightened regulatory risks for multinational technology companies and their legal advisors.
By the numbers:
- €403 million — fine imposed on Google by Ireland's Data Protection Commission
- May 25, 2018 to February 4, 2020 — period examined in the investigation
- 6 months — timeframe given to Google to comply with GDPR