← All stories
● Covered by 7 sources · 7 reportsMedium impact6 negative1 neutral

Google fined over €400m by Irish DPC for manipulating location data consent

🔄 Updated 2d ago — new reporting from Hacker News Front Page
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Google fined over €400m by Irish DPC.
  • Fine relates to manipulation of user consent for location data.
  • Inquiry found Google lacked valid legal basis for data processing.
  • Location data can reveal sensitive personal details.
  • Google fined $463 million.
  • Google must make location data processing GDPR compliant within six months.
  • Investigation started in 2020.
  • DPC investigated Web & App Activity, Location History, and Location Accuracy features.
  • DPC found Google failed to lawfully process data between May 2018 and February 2020.
  • DPC found Google breached rules on lawful and fair processing, transparency, and data retention.
  • Web & App Activity is a Google account setting that processes user activity data, including location.
  • Location History tracks user movement with signed-in mobile devices.
  • Location Accuracy is an Android feature that determines device location more precisely than GPS.
  • Google's European headquarters is in Dublin.
  • Google stated the case centers around historical policies updated since 2019.
  • DPC found Google retained location data longer than necessary.
  • DPC found Google failed to meet transparency obligations.
  • Investigation started after complaints from consumer rights organizations.
  • Google must rectify data processing practices within six months.
  • DPC announced its final decision on September 21, 2026.
  • DPC launched the inquiry in February 2020.
  • DPC acted as Lead Supervisory Authority for Google.
  • DPC found Google infringed accountability obligations.
  • The decision was made by Dr Des Hogan, Mr Dale Sunderland, and Ms Niamh Sweeney.

Regulatory Fine Imposed

Google has been fined more than €400 million (£345 million) by Ireland's Data Protection Commission (DPC). The fine addresses Google's methods for processing users' location data, specifically concerning claims that the company manipulated users into constant tracking on their mobile devices.

Origin of the Inquiry

The DPC's inquiry stemmed from complaints by multiple European consumer organizations. These complaints, prompted by 2018 research from the Norwegian consumer agency, alleged that Google's extensive use of location data could lead to privacy breaches by revealing sensitive personal details such as religious beliefs, political leanings, health conditions, and sexual orientation.

DPC Findings on Consent

After a six-year investigation, the DPC concluded that Google users might have been unaware their location was being used for advertising or to gather information about their health and interests. The DPC determined that Google lacked a valid legal basis for its use of this location data, which can greatly enhance online services but also reveal inherently private information.

Google's Response

A Google spokesperson stated that the case centers on historical policies that have since been updated. The company claims to have significantly evolved its practices and launched tools for managing location data since 2019.

Updates

🕒 2026-09-22 · new reporting from Hacker News Front Page
  • DPC announced its final decision on September 21, 2026.
  • DPC launched the inquiry in February 2020.
  • DPC acted as Lead Supervisory Authority for Google.
  • DPC found Google infringed accountability obligations.
  • The decision was made by Dr Des Hogan, Mr Dale Sunderland, and Ms Niamh Sweeney.
🕒 2026-09-21 · new reporting from The Record
  • DPC found Google retained location data longer than necessary.
  • DPC found Google failed to meet transparency obligations.
  • Investigation started after complaints from consumer rights organizations.
  • Google must rectify data processing practices within six months.
🕒 2026-09-21 · new reporting from BleepingComputer, The Hacker News, SecurityWeek
  • DPC found Google breached rules on lawful and fair processing, transparency, and data retention.
  • Web & App Activity is a Google account setting that processes user activity data, including location.
  • Location History tracks user movement with signed-in mobile devices.
  • Location Accuracy is an Android feature that determines device location more precisely than GPS.
  • Google's European headquarters is in Dublin.
  • Google stated the case centers around historical policies updated since 2019.
🕒 2026-09-21 · new reporting from Engadget
  • Google fined $463 million.
  • Google must make location data processing GDPR compliant within six months.
  • Investigation started in 2020.
  • DPC investigated Web & App Activity, Location History, and Location Accuracy features.
  • DPC found Google failed to lawfully process data between May 2018 and February 2020.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~26 min · 21 stories · Sep 23

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

The Data Protection Commission (DPC) fined Google Ireland Limited €403 million for GDPR infringements related to its processing of location data. The DPC found Google violated principles of lawfulness, fairness, transparency, and accountability concerning its "Web & App Activity," "Location History," and "Location Accuracy" features. Google must bring its processing into compliance within six months.

Ireland's Data Protection Commission (DPC) has fined Google over €403 million ($462 million) for violations related to its processing of user location data, concluding an inquiry that began in February 2020. Google has also been ordered to rectify its data processing practices within six months, as the DPC found its methods for tracking and storing location data violated GDPR.

Google received a 403 million euro ($463 million) fine from the EU's data privacy watchdog for mishandling users' location data, specifically in Web & App Activity, Location History, and Android's Location Accuracy feature. This fine highlights ongoing regulatory scrutiny over how major tech companies manage user data under GDPR, impacting their operational practices in the EU.

Ireland's Data Protection Commission (DPC) fined Google €403 million for GDPR violations related to how three features handled user location data between May 2018 and February 2020. The DPC found Google breached rules on lawful and fair processing, transparency, and data retention, impacting user control over personal location information.

Ireland's Data Protection Commission (DPC) has fined Google €403 million for multiple GDPR violations concerning the processing of user location data. The DPC found Google failed to meet transparency obligations and retained location data longer than necessary for its Web & App Activity, Location History, and Location Accuracy features. This fine highlights ongoing regulatory scrutiny over how major tech companies handle user privacy and data retention.

Ireland's Data Protection Commission (DPC) fined Google $463 million (€403 million) for violating GDPR rules regarding location data processing. The DPC found Google failed to lawfully and transparently process location data across its Web & App Activity, Location History, and Location Accuracy features between May 2018 and February 2020.

Google received a fine exceeding €400 million from Ireland's Data Protection Commission (DPC) for manipulating users into agreeing to location data tracking. The DPC's six-year inquiry found Google lacked a valid legal basis for processing location data, which could reveal sensitive personal information.