Google must pay a 403 million euro fine, roughly 463 million dollars, for violating European Union privacy rules on location data. Ireland's Data Protection Commission, which oversees Google in the EU because the company's European headquarters is in Dublin, issued the penalty. Google also has six months to bring its location data processing into compliance with the General Data Protection Regulation.

The DPC opened its investigation in 2020 after consumer rights groups filed complaints. Regulators examined how Google handled location data from May 2018 through February 2020 across three features. Those are Web & App Activity, which stores user activity across many Google services; Location History, an opt-in tool that displays a timeline of where a phone has been; and Location Accuracy, which determines an Android device's position more precisely than GPS alone.

The commission found that Google processed location data unfairly and unlawfully in Web & App Activity and Location History. It also concluded the company did not demonstrate compliance with the GDPR's lawfulness, fairness and transparency principle for Location Accuracy. According to the DPC, Google fell short of transparency requirements for all three features and violated GDPR retention rules for Web & App Activity and Location History.

Google told the Associated Press that the case concerns historical policies that have since been updated. The company said it has significantly changed its practices since 2019 and introduced tools that make managing location data simple. The DPC said it has three other ongoing large-scale statutory inquiries into Google, all at an advanced stage.

The penalty adds to a series of EU actions against Google. This summer, the company lost its final appeal over a 4.7 billion dollar Android antitrust fine imposed by the bloc in 2018. The European Commission also fined Google 1 billion dollars in July after finding it unfairly prioritized its own services in Search results, and the company agreed this month to make changes to Search to reduce that fine.

The DPC said the 403 million euro penalty is the fourth largest it has issued since the GDPR took effect. The biggest was a 1.3 billion dollar fine against Meta for transferring EU citizens' Facebook data to servers in the United States. For US readers, the decision signals that EU regulators continue to press American technology companies over how they collect and retain location information, and that American companies operating in Europe must meet the bloc's privacy standards.

More company and startup news from TechManNews.