← Back
AI News

Irish regulator fines Google €403 million over location data violations

Ireland's Data Protection Commission (DPC) has imposed a €403 million fine on Google Ireland Limited on Monday 21 September 2026, closing a six-year inquiry.

AIMag.no
AIMag.no
September 24, 2026 · 5 min
Illustration of a digital brain behind a gavel and scales, with EU stars in the background.

Irish regulator fines Google €403 million over location data violations

Ireland's Data Protection Commission (DPC) has imposed a €403 million fine on Google Ireland Limited on Monday 21 September 2026, closing a six-year inquiry. The case concerns the company's handling of location data in its Web & App Activity, Location History and Location Accuracy services — and the fine is the fourth largest the DPC has ever issued.

What the regulator found

According to BetaNews, the DPC's commissioners — Dr. Des Hogan, Dale Sunderland and Niamh Sweeney — found four types of breach of the General Data Protection Regulation (GDPR):

  1. Lawfulness and fairness violations in processing through Web & App Activity (a setting that tracks browsing and search history) and Location History (a service that maps the places a user has been with their mobile phone). The Associated Press, which reported the decision via the Baltimore Sun, describes Google as having processed this data unlawfully and unfairly.
  2. Accountability breaches related to Location Accuracy, because Google could not demonstrate that the processing met the principle of lawfulness, fairness and transparency, BetaNews writes.
  3. Transparency obligations, which applied to all three services.
  4. Excessive retention of location data in Web & App Activity and Location History.

The inquiry covered the period from 25 May 2018 to 4 February 2020 — that is, from when the GDPR took effect until just before the investigation was announced, according to BBC News NI via Yahoo News.

The regulator's reasoning

Deputy Commissioner Graham Doyle pointed to the dual nature of location data: "Location data can provide benefits and harms to individuals. It can greatly enhance the usefulness of online services, but it can also reveal a significant amount of information about a person, including information that is inherently private," he said, according to the Associated Press.

Doyle added that Google's breaches meant users could be unaware that their location was being used, for example, to target them with advertising or to infer their interests, and that they could lose control of their own personal data, according to the BBC's coverage.

The procedural history: from 2018 complaints to a 2026 fine

The case has long roots. BEUC's member organisations — the national sister organisations of the European Consumer Organisation — complained to national data protection authorities about Google as far back as November 2018. The DPC opened its inquiry in February 2020, and six years later, in September 2026, it ended in a fine and a compliance order.

The consumer organisation itself is unimpressed by the pace. BEUC Director General Agustín Reyna welcomed the decision but criticised how long it took: "Late enforcement can be as harmful as no enforcement at all," he said, according to The Hacker News, which cites NewsIreland.EU.

What happens next — and why the fine cannot be collected yet

Despite the headlines, the case is not finished:

  • The DPC has ordered Google to bring its processing into compliance with the law within six months, but the regulator has not disclosed which processing activities the order covers, The Hacker News writes.
  • The fine cannot yet be collected: a DPC fine becomes payable only after confirmation by an Irish court.
  • Google can appeal to the High Court within 28 days of receiving formal notice of the decision.
  • The full decision has not yet been published; the DPC says it will come later.

That means all coverage so far, including this article, rests on secondary reporting of the announcement — not on the decision itself.

Google's response

Google emphasises that the case concerns outdated policies. "This case is about historical policies that have since been updated. Since 2019, we have significantly evolved our practices and launched robust tools that make it easy to manage location data," the company said in a statement carried by the Associated Press.

The company points to what it calls "industry-first auto-delete controls," which allow users to "set your account to automatically delete your data on a rolling three-, 18- or 36-month basis," according to the BBC's coverage.

The timeline partially supports this: Google announced auto-delete controls for Location History and Web & App Activity in May 2019 — that is, while the DPC inquiry was under way — and made 18-month auto-deletion the default for new accounts in June 2020, The Hacker News writes, citing Google's own product announcements. Whether these changes satisfy the DPC's compliance order, however, the regulator has not publicly said.

Where the fine ranks, and what remains for Google

The €403 million is the fourth-largest EU data protection fine the DPC has issued. The regulator has previously issued larger fines to TikTok and Meta — the latter including a €1.2 billion fine, according to the Associated Press. The amount corresponds to roughly $462–463 million; media outlets convert differently, while the euro figure is consistently reported.

For the DPC, this case is far from its last involving Google. The regulator has three further statutory inquiries into the company under way, each at an advanced stage and independent of this decision, according to BetaNews.

The unresolved questions

Three matters remain to be clarified once the full decision is published:

  • The legal reasoning: which specific GDPR provisions the DPC believes Google breached, and how the regulator justifies each of the four findings.
  • The scope of the order: which future processing the six-month compliance order actually covers.
  • The appeal: whether Google exercises its right to appeal to the High Court, and any resulting changes to the amount or findings.

The €403 million fine is substantial, but the amount, the order and the findings themselves all remain subject to court confirmation and possible appeal before taking final effect.

AIMag.no
AIMag.no
The AIMag.no editorial team covers artificial intelligence, tools, research, and regulation.

Sources

  1. Google fined €403M over location data by Irish regulator — betanews.com
  2. Google gets another $460 million fine for misusing user data - Android Authority — www.androidauthority.com
  3. Google hit with $463 million fine for EU location data rule breach — www.baltimoresun.com
  4. Google hit with €403m fine by Irish data watchdog over GDPR violations — www.yahoo.com
  5. Google Fined €403 Million Over GDPR Violations Tied to Location Data — thehackernews.com