The Irish Data Protection Commission fined Google EUR 403 million on September 21 over its processing of location data in three features: Web & App Activity, Location History, and Location Accuracy, per the DPC. The inquiry began in February 2020 on the DPC's own initiative and covered conduct from 25 May 2018 to 4 February 2020, per the EDPB.
The decision covers those three features and names four breaches: lawfulness and fairness, accountability, transparency, and retention. The order runs six months. Google has that long to bring the processing into compliance. The conduct window closes in February 2020, so the findings describe those settings as they worked then. The fine is the fourth largest the DPC has issued under GDPR, behind Meta at EUR 1.2 billion in 2023, TikTok at EUR 530 million, and Instagram at EUR 405 million, per the Irish Times.
For anyone running ad tech, the compliance order carries more weight than the euro figure. Alphabet can absorb the fine. An order attached to Web & App Activity reaches the signals behind ad personalization and interest inference, and the DPC said users might not have realized location was shaping the ads they saw. Whatever Google files to close that order becomes the template other European regulators point at.
Bottom Line
The fine is small against Alphabet's revenue, and the six-month order is the operative part. If you process location data or infer interests from it, treat the four breach findings as a checklist, because lawfulness, transparency, accountability, and retention are the same four a regulator will test on you.