Legal and Compliance

Why Google just lost €403 million over your location history

Google fined €403m by Irish DPC for location tracking breaches. Learn what this means for your data privacy and how to protect your location history.
Why Google just lost €403 million over your location history

Most of us treat our smartphones like a trusted companion that stays in our pocket from morning until night. We rarely think about the invisible trail of digital breadcrumbs we leave behind as we commute to work, visit a doctor, or meet a friend at a cafe. However, these breadcrumbs are more than just technical leftovers. They are a precise map of our private lives. In the eyes of the law, this map is protected property.

Ireland’s Data Protection Commission (DPC) recently concluded a six-year investigation into how Google managed this map. The result is a €403 million fine. This penalty targets the way Google tracked and stored user location data between 2018 and 2020. For the average person, this case is not just about a large sum of money moving from one corporate balance sheet to a regulator’s account. It is a fundamental confirmation that your digital shadow belongs to you, not to the company that provides your operating system.

The long road to a six-year verdict

Legal battles involving Big Tech move at a pace that often feels glacial. This specific inquiry began in February 2020. The DPC acted on formal complaints from consumer rights groups, including the European Consumer Organisation (BEUC). These groups argued that Google made it difficult for users to understand how their location was being used.

Investigators looked at three specific features: Web & App Activity, Location History, and Location Accuracy. The probe covered the period starting in May 2018, which is when the General Data Protection Regulation (GDPR) became active. This timing is significant because the GDPR sets a high bar for how companies must ask for permission to use personal data.

The law is a shield that protects you from being tracked without your clear, informed consent. When a company fails to be transparent about its tracking, that shield breaks. The DPC found that Google’s practices during those years left users in the dark about where their data went and how long it stayed there.

Breaking down the three tracking features

To understand why Google is liable for such a heavy fine, we must look at the specific tools the DPC examined.

First, Web & App Activity is a setting that saves your activity on Google sites and apps. This includes things like your searches and your location. Second, Location History creates a personal map of where you go with your signed-in devices. Third, Location Accuracy uses signals like Wi-Fi and mobile networks to get a more precise fix on a device’s position.

Regulators found that Google failed to process this data lawfully and fairly. In simple terms, the company did not have a valid legal reason to collect the data in the way it did. The DPC also noted a failure in transparency for the Location Accuracy feature. When a system is not transparent, the law views it as a trapdoor. Users think they are agreeing to one thing, but the system is actually doing something much more invasive.

The danger of the digital shadow

Deputy Commissioner Graham Doyle noted that location data is uniquely sensitive. Even if Google does not use your name directly, your location history can reveal your religion, your political leanings, or your health status. If you visit a specific clinic every Tuesday, a computer can infer your medical condition without you ever typing a search query about it.

Because of these failures, many individuals were unaware that their location influenced the ads they saw. They did not realize Google used their physical movements to infer their personal interests. This resulted in a total loss of control over personal data. The law requires that you remain the master of your information. When a company hides the toggle switches or uses confusing language, you lose that mastery.

Why keeping data too long is a legal risk

One of the most significant findings in this case involves data retention. The DPC found that Google kept location data for longer than was necessary to provide its services. Under the GDPR, there is a principle of data minimization. This means a company should only collect what it needs and delete it as soon as the purpose is served.

Think of your data like a leaky bucket. If a company keeps the bucket full for years, the risk of a leak or misuse grows every day. The DPC determined that Google’s habit of holding onto this history for extended periods aggravated the loss of user control. A company cannot simply hoard your movements indefinitely just because it might be useful for their advertising algorithms later. The statutory requirement is clear: if the data is no longer needed for the original task, it must go.

The six-month countdown for compliance

This fine is a heavy blow, but the DPC did not stop at a financial penalty. The regulator issued a binding order for Google to bring its data processing practices into compliance within six months. This means Google must rewrite its internal rules and change how it presents privacy choices to users across Europe.

This decision came after cooperation with other privacy watchdogs across the European Union. Because Google has its European headquarters in Dublin, the Irish DPC acts as the lead regulator. However, this was a collective effort to ensure that the rules are the same whether you are in Paris, Berlin, or Dublin. The systemic nature of these violations required a comprehensive response that forces the company to change its behavior, not just pay a fee and continue as usual.

What this means for your privacy rights

This case sets a strong precedent for consumer rights. It proves that "standard" settings are not always legal settings. Just because a company has operated a certain way for years does not mean its practices are equitable or lawful.

From a regulatory context, this fine is part of a larger trend. Brussels and national watchdogs are no longer hesitant to issue penalties that reach into the hundreds of millions. They are looking past the boilerplate language in privacy policies to see how the software actually functions in practice.

For the average person, this is a reminder to check your settings. You have the right to know exactly what is being tracked. If a service feels like it knows too much about your daily routine, it might be because the company is pushing the boundaries of what the law allows.

How to protect your location data today

You do not need a law degree to take control of your digital privacy. While the regulators handle the big corporate shifts, you can take immediate steps to secure your own devices.

  1. Review your Google Account settings and look specifically for the "Data & Privacy" tab.
  2. Check your "Activity Controls" and see if Web & App Activity is turned on.
  3. Look at the "Auto-delete" options. You can set Google to automatically delete your location and activity data after three months or 18 months.
  4. Audit the location permissions for every app on your phone. Many apps request location access even when they do not need it to function.
  5. Use the "Ask App Not to Track" feature if you use an iPhone, or the "Approximate Location" setting on Android to limit how much detail a company gets.

Ultimately, the law is only as strong as its enforcement. This €403 million fine serves as a clear warning to the tech industry. It reminds every service provider that transparency is a requirement, not a suggestion. As a consumer, your most powerful tool is your awareness. When you notice a company is being vague about your data, you have the right to walk away or file a complaint with your local data authority.

Sources: General Data Protection Regulation (GDPR) Articles 5, 6, 12, and 13; Irish Data Protection Act 2018; European Consumer Organisation (BEUC) official filings.

Disclaimer: This article is for informational and educational purposes only and does not constitute formal legal advice. Please consult a qualified attorney in your jurisdiction for specific legal issues or privacy concerns.

bg
bg
bg

See you on the other side.

Our end-to-end encrypted email and cloud storage solution provides the most powerful means of secure data exchange, ensuring the safety and privacy of your data.

/ Create a free account