Ireland’s Data Protection Commission has fined Google Ireland Limited €403 million following an inquiry into its processing of personal location data.
In their official statement, they have shared that the decision concludes an investigation opened in February 2020 after consumer rights organizations raised concerns over three features: Web & App Activity, Location History, and Location Accuracy. The commission determined that Google breached GDPR rules between May 2018 and February 2020 by failing to meet lawful, fair, and transparent standards, lacking accountability, and storing users’ location data longer than necessary.
Alongside the financial penalty, the regulator ordered Google to bring its data processing practices into compliance with EU rules within six months. Because Google’s European headquarters are located in Dublin, the Irish DPC acts as the lead supervisory authority under the GDPR’s cross-border enforcement framework, allowing a national regulator to enforce European Union law to protect users across the European Economic Area.