Ireland's Data Protection Commission fined Google €403 million (approximately $462 million) for collecting users' location data in breach of GDPR, giving the company six months to bring its practices into compliance1,2,3.
The enforcement action followed complaints from European consumer rights groups. The Data Protection Commission determined that three Google features drove the unlawful tracking: Web App Activity, Timeline, and GLA.
Web App Activity is a Google account setting that collects user data when enabled. Timeline and GLA also gathered location information, though the accessible source material describes their mechanics in less detail. The Data Protection Commission concluded that the way Google processed location data through these features violated European data-protection rules.
The €403 million penalty ranks among the larger GDPR fines levied by the Data Protection Commission, which serves as the lead EU privacy regulator for many U.S. technology companies because their European headquarters sit in Ireland.
Beyond the financial penalty, the Data Protection Commission ordered Google to achieve compliance within six months. ANALYSIS The compliance deadline creates a concrete operational obligation: Google must alter or disable the data-collection pathways the regulator found unlawful, not merely pay the fine.
The case centers on location data, a category that intersects with AI-driven services such as personalized recommendations, mapping, and ad targeting. Enforcement that restricts how location signals are collected and processed could constrain the training and inference pipelines that depend on that data across Alphabet Inc.'s product stack.