Google Fined €403 Million Over Location Data Tracking in Ireland
Ireland's privacy regulator fined Google €403 million for tracking and storing users' location data — here's what it means for Indian users.
Google just got a €403 million reminder that "anonymised" location data isn't as anonymous as it sounds. Ireland's Data Protection Commission (DPC) — the regulator that oversees Google's European operations because the company's regional headquarters sits in Dublin — closed a six-year investigation this week by ruling that three of Google's location-tracking features broke the EU's data protection law, GDPR (General Data Protection Regulation, the EU's main privacy law that also shapes how global companies handle user data everywhere, including in India).
What the regulator actually found
The probe started back in 2020, triggered by user complaints, and dug into three specific settings baked into every Android phone and Google account: Web & App Activity (which logs your browsing and search history), Location History (which maps everywhere you've physically carried your phone), and Location Accuracy (a background feature on Android devices that sharpens GPS positioning using nearby Wi-Fi and cell towers). The DPC's finding wasn't that Google collected this data — it's that people had no real way of knowing this data was quietly shaping the ads they saw and the "interests" Google inferred about them.
On top of that, the regulator found Google kept the data around for longer than it needed to, which only deepened the problem. Four separate violations were logged across lawfulness, fairness, and transparency requirements under GDPR.
"The retention of users' location data for longer than necessary aggravated this loss of control," said Graham Doyle, the DPC's Deputy Commissioner, in the regulator's statement. He added that location data "can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private."
At €403 million, this is the fourth-largest fine the DPC has ever handed out under GDPR — behind Meta's €1.2 billion penalty in 2023, TikTok's €530 million fine, and a separate €405 million fine against Instagram. Google now has six months to bring its location-data practices into line or face further action.
Why this isn't just a European story
Here's the part that matters if you're reading this from Bengaluru or Bhubaneswar rather than Berlin: the three features under fire — Web & App Activity, Location History, and Location Accuracy — run on the exact same Android build that ships in India, Google's single largest Android market by user count. GDPR itself has no jurisdiction here, but India now has its own version of this fight brewing under the Digital Personal Data Protection (DPDP) Act, which we covered in detail here. The DPDP Act leans on many of the same ideas GDPR does — consent has to be specific and informed, and companies can't just hold onto personal data indefinitely "just in case."
The DPDP Act's rules aren't fully in force yet, but the enforcement body behind it, the Data Protection Board of India, is expected to start actively taking up cases once the rules are notified. When that happens, the exact kind of question the DPC just spent six years chasing — did users genuinely understand what location tracking was doing with their data — becomes fair game for Indian regulators too. A €403 million fine in Dublin is effectively a preview of the arguments Indian privacy complaints will eventually run into.
What you can actually do about it
Whatever the regulatory back-and-forth, the settings this case is about are ones any Android user can check right now:
- Go to your Google Account's Data & Privacy settings and check whether Web & App Activity and Location History are switched on
- Review and delete old location history — Google lets you set auto-delete windows of 3, 18, or 36 months instead of keeping it forever
- Turn off Location Accuracy on Android if you don't need pinpoint GPS precision for navigation apps
None of this is a workaround exclusive to Europe — the toggles are identical on an Android phone bought in Chennai or Copenhagen.
What happens next
Google has said it plans to appeal, which is standard practice for large GDPR fines — Meta and Amazon have both fought theirs through the courts, sometimes for years, before the numbers were settled. So the €403 million is unlikely to actually change hands anytime soon. What's more immediately useful is the DPC's underlying finding: that "your location data is being used to shape your ad experience" needs to be said plainly, not buried in a settings menu nobody opens. That's a bar every company operating in India will eventually be measured against too, whether the fine comes from Dublin or from Delhi.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0