EU imposes €403 million penalty on Google for location-data violations
The European Union, via Ireland’s Data Protection Commission, fined Google €403 million for unlawfully processing users’ location information between 2018 and 2020.
On September 21, the EU’s data-protection authority in Ireland levied a €403 million (approximately $590 million) fine on Google for GDPR infringements related to location data. The breach spanned from May 2018 to February 2020 and involved the collection and retention of users’ location information from web, app activity and location-history services without proper legal basis. Deputy commissioner Graham Doyle warned that individuals could have been unaware that their movements were being used to target ads or infer interests, and that excessive data retention worsened the loss of control.
Google argued the issue stems from historical policies that have since been revised and highlighted new tools introduced in 2019 to simplify location-data management. In addition to the monetary penalty, the commission gave Google six months to bring its data-processing practices into full compliance with GDPR.
How this was covered
- Coverage peaked at 10 outlets in a single hour
Why it matters
The fine signals stricter enforcement of EU privacy rules and could reshape how tech firms handle location data worldwide.
In this story
