Ireland’s Data Protection Commission has fined Google €403 million ($463 million) for multiple breaches of the GDPR connected to how the company processes users’ location data. The google location data fine covers how Google collects and handles that data across its consumer services, and it adds to a long list of EU run-ins for the company.
What the DPC found
The ruling cites several separate breaches rather than one infringement, all tied to location data processing. BleepingComputer, which first detailed the scope of the case, reported that the violations span multiple aspects of how Google collects and processes that data, and that the Irish regulator settled on the €403 million figure, which converts to roughly $463 million.
Under the GDPR, location data counts as personal data the moment it can be tied to an identifiable person, which is almost always. That means Google needs a valid legal basis, usually explicit consent, before collecting it, and it has to limit what it does with that data to the purpose it was collected for. A finding of multiple violations suggests the DPC identified more than one point in that chain where Google’s practices fell short, rather than a single isolated failure.
A pattern of privacy enforcement
This is not Google’s first clash with EU regulators, and it fits a broader run of enforcement action this year against companies over how they collect and share sensitive personal data. We covered a similar case in September, when Grindr agreed to pay £26 million over claims it shared users’ HIV status data without proper consent. That case ran through the UK’s regulator rather than Ireland’s DPC, and it involved health data rather than location data, but the throughline is the same: regulators are now treating the categories of personal data that reveal where someone is, or what condition they have, as needing a much higher bar for consent than companies have been applying.
The fine also lands during a stretch of scrutiny over Google’s wider data practices. In May, as we reported, Google confirmed its Gemini AI had been used to hack three companies. That’s a separate matter with a different cause, but it keeps Google’s handling of user and customer data under a wider spotlight heading into this ruling.
What the google location data fine means for users
For anyone with a Google account, the practical takeaway is that the location data Google holds, whether from Android, Maps or Search, was collected in ways a regulator has now ruled did not meet GDPR’s consent standard. Google has not said whether it plans to appeal, and neither the company nor the DPC has published the full decision yet. Until one of those happens, €403 million is the number on record, and it’s worth checking your own Google account’s location history settings regardless of how the appeal plays out.
Image: Mkkagain via Wikimedia Commons, licensed under CC BY-SA 4.0.








