Google just got hit with another nine-figure bill from European regulators. Ireland’s Data Protection Commission slapped the tech giant with a €403 million fine, roughly $463 million, for violating the EU’s General Data Protection Regulation through its handling of users’ location data.
The penalty marks the DPC’s fourth-largest fine under GDPR and covers a period stretching from May 25, 2018, to February 4, 2020.
What Google actually did wrong
The DPC’s investigation zeroed in on three specific features: “web and app activity,” “location history,” and “location accuracy.” All three were found to process location information in ways that violated GDPR’s core principles of lawfulness, fairness, and transparency.
The core problem was straightforward. Users didn’t adequately understand how their location data was being harvested, retained, and then fed into Google’s advertising and interest-inference engines. The commission also flagged unreasonable data retention periods, meaning Google was holding onto location information longer than users might reasonably expect.
The investigation itself traces back to complaints filed by several European consumer rights organizations, including the Norwegian Consumer Council. Their focus was on Android’s location tracking practices. The inquiry was formally initiated in 2020.
Google has responded by pointing to changes already made. The company says its location data management practices have “significantly evolved” since 2019, citing management tools it implemented during that period. The commission has given Google a six-month window to bring its data processing activities into full GDPR compliance.
A growing tab for Alphabet in Europe
This fine exists in a regulatory context that has become increasingly expensive for Google. Just months earlier, in July 2026, the European Commission levied a separate €890 million penalty against the company under the Digital Markets Act for anti-competitive practices.
When you add up prior competition violations, Google’s total penalties from European regulators now exceed €10 billion. That figure spans years of antitrust cases, including landmark rulings on search engine favoritism and Android bundling practices.
For the DPC specifically, this case is significant. Ireland’s data protection authority has faced years of criticism for being too slow and too lenient with the Big Tech companies headquartered in its jurisdiction. Google, Apple, Meta, and others maintain their European headquarters in Ireland, making the DPC the lead supervisory authority for most cross-border GDPR complaints involving these firms.
Why this matters beyond Google
Location data reveals where you live, where you work, which doctors you visit, which protests you attend, and which bars you frequent. The DPC found Google was processing this data without adequate transparency or lawful basis between 2018 and 2020.
The six-month compliance deadline is also worth watching. GDPR allows for fines of up to 4% of a company’s global annual turnover, which for Alphabet would translate to a theoretical maximum in the tens of billions. The €403 million fine sits well below that ceiling.
Consumer rights organizations across Europe are likely to view this outcome as validation of their advocacy strategy. The Norwegian Consumer Council’s original complaint took years to wind through the regulatory process, but the resulting fine and compliance order demonstrate that the complaint mechanism works.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 hour ago
24







English (US) ·