Particle.news

Dublin Regulator Fines Google €403 Million Over Location Data Breaches

The DPC found consent and retention failures breached GDPR and set a six‑month deadline for Google to fix its location‑data practices.

Overview

  • The Data Protection Commission issued its final decision on Monday, September 21, 2026, fining Google €403 million and ordering the company to bring its processing of location data into compliance within six months.
  • The inquiry examined three features — Web & App Activity, Location History and Location Accuracy — and found breaches of lawfulness, fairness, transparency, accountability and excessive data retention.
  • The DPC said users could have been unaware that their location was used to target ads or infer interests and that holding location records longer than necessary worsened the loss of user control.
  • Consumer groups led by BEUC alleged Google used dark patterns to obtain consent, and Google replied that the decision relates to historical policies updated from 2019 and pointed to new user tools for managing location data.
  • The penalty is the DPC’s fourth‑largest GDPR fine and underscores growing EU scrutiny of U.S. tech firms that have their European headquarters in Ireland while critics say the six‑year probe highlights slow enforcement.