
The Google logo outside the company’s offices in London on June 24, 2025. Carlos Jasso/Reuters
The European Union’s leading data privacy regulator has fined Google 403 million euros ($463 million) after finding that the tech giant had breached the bloc’s strict privacy rules in its processing of users’ data.
The Republic of Ireland’s Data Protection Commission (DPC) said in a Sept. 21 statement that Google had infringed on the EU’s General Data Protection Regulation (GDPR) in the processing of users’ location data in its “Web & App Activity,” “Location History,” and “Location Accuracy” features between March 2018 and February 2020.
Google said that the investigation focused on historical policies that have since been updated. But the company has nevertheless been fined and ordered to bring processing into compliance within six months.
Regulators found that Google did not fairly or lawfully process user data in the Web & App Activity feature, which tracks searching and browser history, and Location History, which maps where users have been with their phones.
Google also infringed on GDPR, the regulator said, in its accountability obligations by failing to show compliance with the transparency, lawfulness, and fairness of its processing of data in Location Accuracy.
The DPC is the lead regulator in the bloc for most major U.S. tech firms’ operations in Europe, due to their EU operations being based in the Republic of Ireland.
Google’s European headquarters is based in Dublin.
DPC Deputy Commissioner Graham Doyle said that GDPR “provides a high level of protection of personal data throughout the [European Economic Area], and requires that the processing of personal data must be carried out in a lawful, fair and transparent manner.”
“As a result of Google’s failures in this regard, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data,” Doyle said.
“The retention of users’ location data for longer than necessary aggravated this loss of control.”
Policies Since Been Updated
Google said in a statement that this case centers on “historical policies that have since been updated.”
“From 2019 onwards, we’ve significantly evolved our practices and launched robust tools that make managing location data simple.”
The DPC said it launched the investigation in February 2020, following complaints from several European consumer rights organizations over Google’s processing of location data.
Google said that since the investigation, it has introduced updates that allow users to automatically delete personal data on a rolling basis, manage how data—including location—is used for ads, and now store timeline data directly onto a user’s device.
It added that it now stores estimated general data, rather than a precise location when a user searches on Google.
This is the fourth-largest DPC fine issued against Google since GDPR came into force in 2018.
Reuters and The Associated Press contributed to this report.