Irish Regulator Slaps Google with €403 Million GDPR Fine Over Location Tracking
Ireland's Data Protection Commission has imposed a record €403 million penalty on Google, citing multiple breaches of the European Union's General Data Protection Regulation tied to the way the tech giant handled users' location information.
The commission's investigation concluded that Google continued to collect and process precise geolocation data from Android devices and its web services without obtaining clear, informed consent from millions of individuals. In several instances, the company allegedly retained the data beyond the periods required by law and failed to provide transparent mechanisms for users to delete their location histories.
Under the GDPR, companies must secure explicit permission before gathering sensitive data, and they are obliged to limit retention to what is necessary for the declared purpose. The DPC's decision underscores that Google’s default settings and opaque privacy notices fell short of these obligations, prompting the steep fine, which is among the largest ever levied by the Irish regulator.
Google has previously faced scrutiny over its data‑handling practices, including a €50 million fine in France for similar concerns and ongoing investigations in other EU member states. The latest sanction arrives as European authorities intensify enforcement of privacy rules, aiming to curb the expansive data‑collection models employed by large tech platforms.
While Google has indicated it will assess the ruling and explore legal avenues, the fine signals a broader shift toward stricter oversight of location‑based services. Analysts expect the case to influence how companies design consent flows and data‑retention policies across the continent, and it may prompt further coordinated actions by EU data‑protection bodies.
Comments (0)
Be the first to comment.
Join the discussion