Cookie Consent by Free Privacy Policy Generator

Google Fined €403 Million by Irish Regulator for Location Data Handling Under GDPR

Ireland's Data Protection Commission has fined Google €403 million (approximately £345 million) for breaching GDPR rules in how it processed users' location data. The Guardian reports that the fine follows complaints from multiple European consumer organisations, which alleged that Google manipulated users into agreeing to constant location tracking on mobile devices. The DPC found that users may not have been adequately informed that their location data was being used to target advertisements or infer their interests, raising questions about the transparency and fairness of consent mechanisms. The decision is one of the largest GDPR fines issued to date and reflects continued regulatory scrutiny of how technology companies handle personal data, particularly where tracking and profiling are involved.

Why this matters for UK organisations

For UK organisations, this case is a reminder that GDPR enforcement remains active and that regulators are willing to impose substantial penalties where data processing practices fall short of transparency and consent requirements. While this fine relates to Google's consumer services, the principles apply broadly: organisations must ensure that users understand what data is being collected, how it will be used, and that consent mechanisms are clear, informed and not manipulative. Location data is particularly sensitive, and its use in advertising, analytics or service delivery must be handled with care. The decision also highlights the importance of privacy by design, ensuring that data collection is proportionate, well-documented and aligned with the purposes users have been told about. For organisations operating mobile applications, customer tracking systems or location-based services, this is a prompt to review how consent is obtained, whether privacy notices are clear and accessible, and whether users have meaningful control over how their data is used. The case also underscores the importance of cross-functional collaboration between legal, product, marketing and technical teams to ensure that privacy requirements are embedded in how services are designed and delivered, not treated as an afterthought or compliance checkbox.

What to review

Review how location data, tracking technologies and consent mechanisms are implemented in mobile applications, marketing platforms and customer-facing services. Ensure that privacy notices are clear, accessible and written in plain language that explains what data is being collected, why it is needed, and how it will be used. Check that consent mechanisms are designed to be fair and transparent, avoiding dark patterns, pre-ticked boxes or manipulative design that nudges users towards agreeing to more data collection than they would otherwise choose. Consider whether users have meaningful control over their data, including the ability to withdraw consent, access their data, or limit how it is used. Review how location data is stored, processed and shared, ensuring that it is handled securely and only retained for as long as necessary. This is also a prompt to ensure that privacy impact assessments are conducted for services that involve tracking, profiling or sensitive data, and that data protection considerations are embedded in product development, procurement and vendor management processes. Ensure that accountability is clear, with defined ownership for privacy compliance, regular reviews of data processing activities, and mechanisms for responding to regulatory inquiries or subject access requests.

Source: The Guardian

News and blog posts
The US Cybersecurity and Infrastructure Security Agency has added...
Today's brief reflects the practical reality of defending modern organisations:...
The National Cyber Security Centre has published a blog post titled "One does...
WordPress released version 7.1.1 on 17 September 2026 to address a critical...