"Google's €403 million fine is about where your phone was in 2018"
Key takeaways
- Ireland's Data Protection Commission fined Google €403 million under GDPR
- The case covers location data processed between 2018 and 2020 via Web & App Activity, Location History and Location Accuracy
- Google has six months to bring its location processing into compliance
- Three more DPC inquiries into Google are at an advanced stage
A six-year-old complaint finally lands
Ireland's Data Protection Commission (DPC) has fined Google €403 million, roughly $463 million, for breaking the EU's General Data Protection Regulation over how it handled people's location data.
The investigation started in 2020 after complaints from European consumer groups, including BEUC. It covers how Google processed location data between 2018 and 2020 through three settings: Web & App Activity, Location History and Location Accuracy. The DPC found problems with the lawfulness and fairness of that processing.
Deputy Commissioner Graham Doyle put it in human terms. People may not have known their location was being used to target them with adverts or to infer their interests, and so lost control over their own data.
"That was years ago" is not the whole defence
Google's response is that this is history. It says it has changed its location practices significantly since 2019, with auto-delete for activity data, Timeline stored on your device rather than in the cloud, and searches tied to a general area instead of a precise location.
Some of that is true and welcome. But two details in the decision matter more than the headline number.
First, the DPC has ordered Google to bring its location-data processing into compliance within six months. A regulator does not issue that order if it thinks the problem is entirely in the past.
Second, Google still faces three more statutory inquiries from the DPC, and the regulator says all three are at an advanced stage. This is not the end of the story.
Why the size matters
€403 million is the fourth-largest fine the Irish regulator has issued, out of more than €4 billion in GDPR penalties since it became the lead regulator for most big US tech firms in Europe. Across the EU, cumulative GDPR fines have now passed €7 billion.
For Alphabet, the money is a rounding error. The compliance order is the real cost, because location signals sit right at the heart of how ads get targeted and measured. Changing how that data is collected and justified touches the core business.
It also lands as EU regulators try to make fines more consistent between countries. The European Data Protection Board has new guidance on calculating GDPR fines out for consultation until 13 November 2026.
What you can do with your own location data
You do not need to wait for a regulator. Wherever you live, it takes about five minutes to check.
Go to your Google Account, open Data and privacy, then look at Web & App Activity and Timeline. Set auto-delete to three months, the shortest option, and turn off anything you do not actively use. On Android, check which apps have "all the time" location permission and downgrade them to "only while using". We cover more of this in our Android security checklist.
The fine says Google got it wrong between 2018 and 2020. Your settings decide what the next fine is about.