Policy · 5h ago

Irish Regulator Hits Google Over Location Profiling

Ireland’s Data Protection Commission fined Google €403 million and gave it six months to bring location-data processing into GDPR compliance after examining Web & App Activity, Location History, and Location Accuracy from May 2018 through February 2020. The ruling turns a long-running inquiry into a formal sanction, and it lands on Google’s account-level controls rather than a single broken product.

The regulator said Google’s settings made location easier to collect, retain, and use than users would reasonably understand, including for ad influence and interest inference. In plain terms, the issue was not access to a map app but the way account toggles and telemetry could feed a broader profiling picture while people thought they had more control than they did.

For EU-facing ad-tech and location-based services, the case raises the bar on how consent, transparency, and retention have to line up with actual data use. If a product relies on account settings to justify location profiling, the exposure can persist even after the wording changes unless the underlying retention model changes too.

Timeline

Sources

5 sources covering this story

Part of the PlainSec briefing for 2026-09-21

Editions