Ireland's Data Protection Commission (DPC) has levied a €403 million fine on Google for GDPR violations This article explores google gdpr violations. . The investigation, initiated in February 2020, scrutinized Google's handling of users' location data, including its Web & App Activity, Location History, and Android's Location Accuracy setting.

The DPC found that Google failed to demonstrate compliance with accountability obligations concerning location accuracy, specifically proving that its processing met the GDPR's lawfulness, fairness, and transparency requirements. Google must rectify affected processing operations within six months to avoid hefty fines imposed by Ireland's data protection authority. Persistent records can expose details such as home and workplace, travel routes, medical visits, religious institutions, political events, or social interactions.

Deputy Commissioner Graham Doyle of the Data Protection Commission (DPC) emphasized that location tracking enhances digital services but also exposes sensitive information that users should be aware of. Doyle cautioned that Google’s methods could make users unaware that their location data is being used to infer interests and shape ads, thereby diminishing their control over personal data. This case underscores the ongoing compliance risk for technology providers: privacy controls must not only exist but also be understandable, legally justified, demonstrably accountable, and paired with retention limits appropriate to the sensitivity of the data collected.