Ireland's Data Protection Commission (DPC) has imposed administrative fines totaling €403 million on Google following an inquiry into the tech giant's processing of user location data under European General Data Protection Regulation (GDPR) rules. The supervisory authority has also ordered Google to bring its data processing practices into compliance within six months.

The investigation, launched following complaints from multiple European consumer rights organizations, examined Google's handling of location data between May 2018 and February 2020. The scope of the inquiry focused on three specific features: "Web & App Activity", "Location History", and "Location Accuracy". The regulator concluded that Google infringed GDPR principles requiring personal data processing to be lawful, fair, and transparent, while also failing to meet its accountability obligations.

In a statement, DPC Deputy Commissioner Graham Doyle emphasized that location data can reveal inherently private information about an individual's daily life. Doyle stated that due to Google's failures, users could have been unaware that their location was being used to influence them with advertisements or infer their personal interests, leading to a loss of control over their personal data. He added that the retention of location data for longer than necessary aggravated this loss of control.

The €403 million fine marks one of the largest financial penalties issued by the Irish watchdog since the GDPR framework came into force in 2018. Because Google operates its main European headquarters in Dublin, the DPC serves as the lead supervisory authority responsible for regulating the multinational's cross-border data processing within the European Union.