Google fined $450 million for tracking user locations quietly

Tech giant penalized for tracking users even when Location History was turned off

Google was fined $450 million after regulators investigated how location data was collected when Location History was turned off. | henry perks / Unsplash
Google was fined $450 million after regulators investigated how location data was collected when Location History was turned off. | henry perks / Unsplash

Google has been slapped with a staggering $450 million (€403 million) penalty after a major privacy investigation revealed the tech giant quietly collected, stored, and used detailed location data for targeted ads — even when users explicitly turned Location History off. By secretly gathering data through secondary background settings, Google bypassed user permissions and created a massive privacy loop. Here is how millions of users were quietly tracked, why the “off” switch didn’t protect them, and what this landmark penalty means for your personal smartphone privacy. Here is how millions were quietly mapped without realizing it.

A six-year investigation into Google’s location practices

The €403 million ($459 million) penalty imposed on Google by Ireland’s Data Protection Commission (DPC) follows a lengthy investigation into how the company handled users’ location information.

The DPC’s six-year inquiry examined Google’s practices between May 2018 and February 2020, focusing on whether users were given enough information about how their location data could be collected and used.

At the center of the investigation was a concern that Google’s location tracking could reveal far more than simply where a person was. Location information can be used to infer a user’s interests, habits, movements, and other personal details — information that can also influence the advertising they see.

The regulator ultimately concluded that Google had violated European privacy law and ordered the company to bring its processing of location data into compliance.

Why turning off Location History wasn’t enough

Google’s Location History is designed to record where users go while using their devices. The opt-in feature includes Timeline, which creates a private map showing places a user has visited.

Android devices also have a separate feature called Location Accuracy, which helps determine a device’s position using sources beyond GPS alone.

The problem examined by regulators was that turning off Location History did not necessarily stop Google from collecting all location-related information.

Google had told users that they could stop Location History tracking by disabling the setting. But an Associated Press investigation in 2018 revealed that Google could continue storing certain location data even after users had turned Location History off. Researchers at Princeton University subsequently confirmed the findings.

That discovery highlighted an important distinction between Google’s different account settings.

One of the key settings was Web & App Activity. Unlike Location History, this feature is designed to save information about activity associated with a Google account, including web browsing and actions taken in apps.

It could also collect location information.

Crucially, disabling Location History did not automatically disable Web & App Activity. As a result, users who believed they had switched off location tracking could still have some location information stored through another setting.

The issue triggered multiple U.S. settlements

Google’s location-data practices also resulted in legal action across the United States.

The company agreed to pay $85 million to Arizona in October 2022, followed by a $392 million settlement with 40 states the following month. In December 2022, Google agreed to pay another $9.5 million to the District of Columbia.

The legal consequences continued in subsequent years. Google agreed to pay $39.9 million to Washington State in 2023 and $1.38 billion to Texas in May 2025 as part of a two-suit settlement.

A separate class-action case also produced a major development, with a jury awarding $425 million last September.

These cases arose from disputes over Google’s handling of location information, although the individual proceedings involved their own claims and legal circumstances.

Ireland’s regulator took up the case

The DPC began examining the issue in 2018 following the Associated Press investigation. It subsequently launched a formal statutory inquiry in February 2020.

The European investigation ultimately resulted in the €403 million ($459 million) fine, along with an order requiring Google to bring its location-data processing practices into compliance within six months.

The DPC said it would publish the full text of its decision in due course.

The penalty therefore goes beyond the size of the fine itself. The regulator’s order requires Google to change how it handles location information, putting the company’s privacy practices under a formal compliance deadline.

Google says its practices have changed

Google told Bloomberg that it had revised its practices since 2019 and introduced tools intended to give users greater control over their location information.

The company has also made changes to how Location History works.

In December 2023, Google announced that it would change its Timeline feature so that location data would be stored on users’ devices rather than relying on the previous approach.

Google also said it would shorten the default period for automatically deleting Location History. For people enabling Location History for the first time, the default retention period would drop from 18 months to three months.

The DPC’s Google investigations go beyond location data

The location-data case is not the only major investigation the Irish regulator has opened involving Google.

The DPC also launched an investigation into Google’s processing of EU residents’ personal data for its AI model two years ago. Another investigation, opened in 2019, examined the company’s processing of personal data for its online Ad Exchange.

Taken together, the cases show how Google’s handling of personal information has become a recurring focus for European regulators.

Source:
Malwarebytes