Google Fined $403M 🤯 Privacy Rights Violated! ⚖️

September 21, 2026 |

Tech

🎧 Audio Summaries
English flag
French flag
German flag
Japanese flag
Korean flag
Mandarin flag
Spanish flag

🧠Quick Intel


  • Ireland’s DPC fined Google €403 million ($463M) for GDPR violations beginning February 2020, stemming from complaints regarding Google features.
  • The investigation targeted Web and App Activity, Location History, and Location Accuracy, active from May 25, 2018, through February 4, 2020.
  • Google processed location data via Web & App Activity and Location History without meeting GDPR requirements, leading to the administrative fine.
  • The DPC found Google failed to meet transparency obligations for all three features and retained location data longer than necessary.
  • Deputy Commissioner Graham Doyle noted individuals may have been unaware of location usage for advertising and lost control over their personal data.
  • Google has updated its practices and implemented tools allowing users to define a timeline for automatically deleting data in their account, with Google Maps Timeline information stored on the device and automatically removing data older than three months.
  • Google states it does not save precise device location in Web & App Activity, but an estimated general area.
  • 📝Summary


    Ireland’s Data Protection Commission has levied a €403 million fine against Google, stemming from multiple violations of the General Data Protection Regulation. The investigation, initiated in February 2020 following complaints from consumer rights organizations, centered on Google’s Web & App Activity, Location History, and Location Accuracy features, active between May 25, 2018, and February 4, 2020. The DPC determined that Google processed location data through these features without sufficient GDPR compliance, particularly regarding transparency and data retention. Deputy Commissioner Graham Doyle highlighted concerns about user awareness and control over their data. Google has since updated its practices, introducing tools allowing users to manage their location data and delete older timelines. The DPC’s actions underscore the ongoing importance of GDPR compliance in the handling of personal location data.

    💡Insights



    GOOGLE FINED €403 MILLION FOR GDPR VIOLATIONS
    Google has been fined €403 million by Ireland’s Data Protection Commission (DPC) for multiple violations of the General Data Protection Regulation (GDPR) related to the processing of user location data. This significant penalty stems from an investigation launched in February 2020, triggered by numerous complaints from consumer rights organizations. The investigation specifically focused on three key Google features active between May 25, 2018, and February 4, 2020: Web & App Activity, Location History, and Location Accuracy. These features allowed Google to collect and process a vast amount of user data, including browsing history, search activity, location data, and device location information, raising serious concerns regarding user privacy and control over their personal data.

    ANALYSIS OF KEY GOOGLE FEATURES AND GDPR NON-COMPLIANCE
    The DPC’s investigation centered around the operation of three distinct Google features and their adherence to GDPR requirements. Firstly, Web & App Activity allowed Google Account holders to enable processing of activity across Google services, potentially capturing browsing history, search queries, and location data. Secondly, Location History was an opt-in service that tracked users’ mobile device locations, inferring visited places, activities, and routes, and storing this information within a private Google Maps Timeline. Finally, Location Accuracy was an Android feature designed to enhance device positioning beyond GPS, regardless of whether the user possessed a Google Account. Critically, the DPC determined that Google processed location data through Web & App Activity and Location History without fulfilling the GDPR’s stipulations regarding transparency and user consent. Furthermore, the company failed to demonstrate sufficient compliance with GDPR principles when processing location data via Location Accuracy. The core issue revolved around a lack of transparency regarding how location data was being utilized, coupled with the retention of this data for an extended period beyond what was deemed necessary, significantly diminishing user control over their personal information. Deputy Commissioner Graham Doyle highlighted the potential for users to be unaware of Google’s data collection practices, specifically concerning targeted advertising and interest inference, emphasizing the detrimental impact on individual data control.

    GOOGLE’S RESPONSE AND COMPLIANCE MEASURES
    In response to the DPC’s findings, Google has acknowledged the issues and implemented several changes to its data processing practices. A Google spokesperson stated that the case centered around historical policies that have since been updated, noting significant advancements in their practices since 2019. Key improvements include the introduction of robust tools enabling users to easily manage their location data. Specifically, Google now allows users to define a specific timeline for automatically deleting data within their accounts. Furthermore, the company has clarified that it does not save precise device location data within Web & App Activity, instead storing an estimated general area. The company has also updated its Maps Timeline information to be stored on the device, with automatic data deletion occurring after three months. These changes represent a concerted effort by Google to address the DPC’s concerns and ensure greater user control over their location data, demonstrating a commitment to aligning its practices with GDPR regulations.