
Ireland’s Data Protection Commission has fined Google €403 million, approximately $463 million, for violating European Union privacy rules in its handling of users’ location information.
The decision, announced on Monday, September 21, 2026, followed a six-year investigation into whether Google processed location data transparently, fairly and lawfully under the General Data Protection Regulation.
Ireland’s privacy regulator led the case because Google’s European headquarters is located in Dublin. Under the GDPR’s cross-border enforcement system, the decision covers the company’s operations throughout the European Union.
The investigation began in 2020 after European consumer organizations submitted complaints about Google’s location-tracking practices. It examined data processed between May 2018 and February 2020 through Web & App Activity, Location History and Android’s Location Accuracy feature.
Regulators found that Google failed to provide users with sufficiently clear information about the collection and use of location data under its Web & App Activity settings. The feature can record information connected to searches, browsing activity and the use of Google services.
The commission also raised concerns about Location History, an optional feature that creates a record of places visited through connected mobile devices. Investigators concluded that some location information was retained for longer than necessary.
Android’s Location Accuracy system was also found to have fallen short of transparency and accountability requirements governing the processing of users’ geographical information.
The regulator said the practices made it difficult for users to understand how detailed information about their movements could be processed for purposes including personalized advertising and behavioural profiling.
In addition to the financial penalty, Google has been ordered to bring the affected data-processing systems into compliance with EU privacy law within six months.
Google said the investigation concerned historical systems and maintained that it had significantly changed its location-data practices since 2019. The company pointed to newer controls intended to make it easier for users to manage, delete and limit the retention of their location information.
The €403 million sanction ranks among the largest privacy penalties issued by the Irish regulator against a major technology company.
Source: Omanghana



