
Four hundred and sixty-three million dollars. That’s what Google owes after Ireland’s Data Protection Commission found the company broke EU privacy law, not once, not twice, but across three separate location-tracking features. And yet Google’s response is essentially: that was then, we’re better now.
According to Engadget, the DPC ordered Google to pay €403 million and bring its location data practices into full GDPR compliance within six months. The investigation started back in 2020, triggered by complaints from consumer rights groups, and focused on how Google handled location data between May 2018 and February 2020. Three features were under the microscope:
- Web and App Activity, which logs user behavior across Google’s services
- Location History, an opt-in feature that builds a timeline of where your phone has been
- Location Accuracy, which sharpens device positioning beyond standard GPS
The DPC found that Google failed to process location data fairly or lawfully in Web and App Activity and Location History. It also found that Google didn’t meet the GDPR’s transparency requirements across all three features, and violated data retention rules in two of them. That’s a lot of violations for a company that positions itself as a responsible steward of user data.
Google’s statement to the Associated Press was predictably defensive. “This case centers around historical policies that have since been updated,” the company said, pointing to changes made from 2019 onward. But that framing should raise eyebrows. If the violations happened between 2018 and 2020, and the investigation launched in 2020, Google had already begun quietly revising its practices while regulators were still building the case. Users during that window had no way of knowing their location data was being handled in ways that a major regulator would later call unlawful.
This fine doesn’t exist in isolation. This summer, Google lost its final appeal against a $4.7 billion Android antitrust fine from 2018. The European Commission also hit the company with a $1 billion fine in July for favoring its own services in Search results. The DPC has three more large-scale Google inquiries already at an advanced stage. So the pattern here is clear: this is a company that repeatedly requires legal force to change behavior that affects millions of people.
The DPC noted this is the fourth largest GDPR fine it has issued. The biggest was a $1.3 billion penalty against Meta for shipping EU users’ Facebook data to American servers. That comparison matters. Location data and behavioral data are among the most sensitive categories of personal information. When the largest fines in GDPR history involve exactly these categories, it tells you where the real privacy battles are being fought.
A $463 million fine sounds significant. But for a company with Google’s revenue, it’s closer to a rounding error than a deterrent. The compliance order may ultimately matter more.