September 22, 2026, 11:15 am | Read time: 2 minutes
Google must pay a hefty fine in Europe. According to the Irish Data Protection Authority, the company repeatedly violated the General Data Protection Regulation in handling location data. The fine amounts to 403 million euros.
Depending on usage, Android devices and various Google services can store data about visited locations and routes taken. This can reveal personal information, such as home address, workplace, or leisure activities. The Irish Data Protection Commission (DPC) investigated the company’s handling of such data from May 25, 2018, to February 4, 2020.
These Google Features Came Under Scrutiny
The investigation focused on three settings. The “Web & App Activity” feature can capture location information in addition to search queries and visited websites. The “Location History” stores visited places and routes on a timeline. The “Location Accuracy” option helps Android smartphones determine their position more precisely using Wi-Fi and mobile networks. The fine is directed at Google Ireland, the European headquarters of Google. According to the data protection authority, several of these features did not comply with important data protection requirements.
The proceedings were initiated by a study by the Norwegian Consumer Council Forbrukerrådet. Subsequently, several European associations filed complaints with data protection authorities at the end of 2018. They argued that Google was violating GDPR requirements.
Criticisms included difficult-to-understand menus and certain default settings. The associations also criticized prompts within the services that may have led users to activate location functions. Following these allegations, the DPC launched its own investigations.
Do you actually know what Google knows about you?
EU Commission Warns Meta Over Payment Model
Authority Sees Multiple Violations
The investigation’s outcome was clear from the authority’s perspective. Location data related to “Web & App Activity” and Location History was processed unlawfully. Additionally, Google reportedly stored the data longer than necessary.
Also of interest: Gemini infiltrated real company networks
With the “Location Accuracy” feature, the company could not demonstrate that key data protection requirements were met. Furthermore, the authority found deficiencies in user information across all three features. Google must now adjust its processes within six months.
Google Points to Changes
Google told Reuters that the criticized policies have since been revised. Since 2019, several additional control options have been introduced.
According to the company, changes include that the timeline in Google Maps is now stored directly on the smartphone. Users can also decide when entries are automatically deleted. Alternatively, automatic deletion can be disabled.