
DUBLIN — Tech giant Google has faced a massive regulatory blow after Ireland's Data Protection Commission (DPC) slapped the company with a €403 million (approximately 628 billion KRW) administrative fine. The penalty stems from severe violations of the European Union's General Data Protection Regulation (GDPR) concerning how the tech conglomerate handles, tracks, and retains user location data.
The high-stakes ruling concludes a comprehensive multi-year inquiry initiated in February 2020 following formal complaints lodged by multiple European consumer rights organizations, including the European Consumer Organisation (BEUC). Investigators closely examined Google's data processing practices spanning from May 25, 2018—the exact date GDPR took effect—through February 4, 2020.
Unlike many isolated privacy probes, this investigation cast a wide net across Google's systemic data ecosystem. Regulators scrutinized three core features: Web & App Activity, Location History, and Location Accuracy. According to the DPC, Google failed to secure lawful and fair processing bases for Web & App Activity and Location History, while neglecting its accountability obligations regarding Location Accuracy. Furthermore, transparency standards were breached across all three categories, compounded by excessive data retention periods that kept logs longer than necessary.
The scope of the investigation extended beyond standard Google account holders. While Web & App Activity tracks browsing, search history, and associated movements within signed-in user apps, and Location History maps continuous personal travel timelines, Location Accuracy operates differently. Built directly into the Android operating system to optimize GPS performance, Location Accuracy tracks device positioning data regardless of whether a user is logged into a Google account.
Regulators emphasized that these systemic failures undermined user agency. Consumers were frequently left unaware that sensitive location metrics were being utilized to profile behavior, deduce personal interests, and hyper-target advertisements.
In response to the judgment, Google maintained that the penalty targets historical operational models rather than current practices. The company stressed that it significantly reformed its location data management framework starting in 2019. Modern updates include streamlined privacy controls, automated data deletion timelines, device-local storage for Maps Timeline data, and search operations that record generalized regional estimates instead of exact coordinates.
Alongside the €403 million financial penalty—marking the fourth-largest enforcement action issued by the Irish DPC against a major tech corporation—regulators have issued a strict compliance order. Google is mandated to bring all relevant data processing procedures into full GDPR alignment within six months. Meanwhile, privacy analysts note that regulatory pressure on the company remains high, with the Irish DPC continuing to advance three separate ongoing investigations into the tech giant's operations.
[Copyright (c) Global Economic Times. All Rights Reserved.]

![[등록] 2026-09-01 15:48:31](/support/_updata/banner2/tl181982910_6749.png)



























