The Republic of Ireland’s Data Protection Commission (DPC) has levied a €403 million (£345 million) penalty on Google, marking one of the largest GDPR fines issued by the Irish regulator. The sanction follows a six‑year inquiry that began after complaints from several European consumer‑rights organisations.
The DPC’s investigation focused on Google’s handling of location data in three services – Web & App Activity, Location History and Location Accuracy – between 25 May 2018 and 4 February 2020. Deputy commissioner Graham Doyle said the processing was not “lawful, fair or transparent” and that the retention of location information for longer than necessary “aggravated” the loss of control for users, potentially allowing the data to be used to influence advertising or infer personal interests.
In response, Google argued that the case centres on historic policies that have since been updated. The company highlighted recent improvements such as industry‑first auto‑delete controls that let users set automatic data deletion after three, 18 or 36 months, as well as tools to turn off personalised ads and increased transparency around location‑data settings. Google has also been ordered to bring its data‑processing activities into full compliance with the GDPR within six months.
The fine underscores the EU’s strict data‑privacy regime, which came into force on 25 May 2018. The DPC’s action sends a clear message that even large tech firms must adhere to the GDPR’s requirements for lawful, fair and transparent handling of personal data.
You may also like
Category: Business
Related Video: Murkomen Says Kenya Is Safe: “Stop Creating a Crisis” | Political Goons & Security Under Scrutiny
Related Explainer: Why the BCG Vaccine Leaves That Small Scar on Your Arm