For six years, European regulators dug into how Google handled the location data of millions of users. On Monday, they delivered their verdict: a $463 million fine for violating the continent’s strict privacy laws.
Ireland’s Data Protection Commission announced the penalty after finding that Google failed to lawfully or fairly process location data through multiple services, including its Web & App Activity setting and Location History feature. The investigation also determined the tech giant wasn’t transparent about how it handled personal data through its Location Accuracy feature on Android devices.
The fine marks the fourth largest EU privacy penalty ever issued by the Irish watchdog, which serves as Google’s lead regulator in the 27-nation bloc because the company’s European headquarters sits in Dublin.
Google pushed back on the ruling, pointing to changes made years ago.
“This case centers around historical policies that have since been updated,” the company said in a statement. “From 2019 onwards, we’ve significantly evolved our practices and launched robust tools that make managing location data simple.”
The investigation covered Google’s practices from May 2018, when the EU’s General Data Protection Regulation took effect, through February 2020. That means the company operated for nearly two years under the new privacy rules before regulators say it came into compliance.
The fine adds to a growing list of privacy penalties against American tech giants operating in Europe. The Irish regulator has previously handed out even larger fines to TikTok and Meta, including a staggering 1.2 billion euro penalty against Facebook’s parent company.
And Google isn’t out of the woods yet. Regulators confirmed they still have three other ongoing privacy investigations involving the search giant.
For American users, the case serves as a reminder of just how much data Big Tech companies collect on everyday people. Every search, every app opened, every trip to the grocery store or the church can be tracked, stored, and processed. European regulators have taken aggressive action to rein in these practices. American lawmakers, meanwhile, have largely left tech companies to police themselves.
The EU’s General Data Protection Regulation remains one of the strictest privacy frameworks in the world, giving citizens the right to know what data companies collect about them and to demand its deletion. No comparable federal law exists in the United States, leaving Americans with far fewer protections against corporate surveillance.
Google’s $463 million fine sounds enormous, but for a company that reported over $300 billion in revenue last year, it amounts to little more than a rounding error. Whether such penalties actually change corporate behavior remains an open question.






