$ techbeacon▋
Phishing

Irish Regulator Slaps Google with Record €403 Million GDPR Fine Over Location Tracking

Ireland’s Data Protection Commission (DPC) has imposed a €403 million penalty on Google for breaching the European Union’s General Data Protection Regulation (GDPR) through its handling of users’ location data. The sanction, the largest ever levied by the DPC, stems from a series of investigations that began six years ago when a group of privacy complaints highlighted gaps in the tech giant’s transparency, data retention and user‑control mechanisms.

According to the DPC, Google failed to provide clear information about how location information was collected, processed and stored, and did not give users sufficient means to delete or limit that data. The regulator also found that Google retained location histories for longer periods than necessary, contravening the GDPR principle of data minimisation.

The case underscores the growing scrutiny of big‑tech firms operating in the EU. While Google’s European headquarters are based in Ireland, the DPC’s jurisdiction extends across the bloc, allowing it to enforce GDPR provisions on any company that offers services to EU residents. The fine follows earlier penalties against other tech companies for similar privacy lapses, signalling a tougher enforcement climate.

Google has announced plans to appeal the decision, arguing that the fine is disproportionate and that its location services have evolved to give users more granular control. The company points to recent updates that let users delete location history automatically after a set period, though the DPC maintains that these measures were implemented after the violations occurred.

Legal experts note that the €403 million figure represents roughly 0.02 % of Google’s annual revenue, a proportion consistent with GDPR’s emphasis on fines that are “effective, proportionate and dissuasive.” The DPC’s statement highlighted that the penalty reflects both the seriousness of the infringements and the length of time the issues persisted without adequate remediation.

The ruling may prompt broader changes across the tech sector, as firms reassess data‑handling practices to avoid similar penalties. Regulators across Europe are watching the outcome closely, and the case could set a precedent for how location‑based services are governed under the GDPR in the years ahead.

Rakesh Meena — Rakesh tracks CVEs, zero-days, and exploit disclosures as they break, translating advisories into plain-language impact analysis. Background in vulnerability research, follows NVD and vendor bulletins closely.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related