Google Location Data Fine Set at US$462 Million by Irish Regulator
Pan-African · TECHNOLOGY
Key Facts
- —What happened Google was fined 403 million euros (about US$462 million) by Ireland’s Data Protection Commission on 21 September 2026.
- —What the regulator found The watchdog said Google’s location data processing was not lawful, fair or transparent, and that data was kept too long.
- —The period The inquiry covered 25 May 2018 to 4 February 2020 across Web & App Activity, Location History and Location Accuracy.
- —The catch The fine is not payable until an Irish court confirms it, and the Irish Times says an appeal is inevitable.
- —Google’s answer Google said the case covers historical policies that have since been updated, and that it changed its practices from 2019.
- —Why it matters for Africa African regulators drafting their own privacy rules now have a template, as Nigeria and the African Union build data regimes.
Ireland’s Data Protection Commission imposed a fine of 403 million euros (about US$462 million) on Google on Monday 21 September 2026. The penalty is one of the largest under the European Union’s privacy law, but Google can still contest it in court.

The Google location data fine announced in Dublin on 21 September 2026 came to 403 million euros (about US$462 million). Ireland’s Data Protection Commission, the country’s privacy watchdog, said the company’s handling of location data broke European Union law.
What the Irish regulator decided
The commission examined three Google services: Web & App Activity, Location History and Location Accuracy. Its inquiry covered 25 May 2018 to 4 February 2020, the period after the General Data Protection Regulation took effect.
That regulation, known as the GDPR, is the European Union’s main privacy law. The regulator found Google’s processing was not lawful, fair or transparent, and that location data was kept longer than the law allows.
Deputy Commissioner Graham Doyle said location data “can also reveal a significant amount of information about an individual”. The commission ordered Google to bring the processing into line within six months.
Why Dublin polices Big Tech for Europe
Ireland is the lead European Union regulator for most large United States technology firms, because their European headquarters sit in Dublin. That makes the commission the first stop for complaints from across the bloc.
Reuters reported it was the fourth largest fine the commission has issued. The regulator has levied more than 4 billion euros (about US$4.6 billion) since 2018.
Three larger penalties sit above it, all against social media companies. Meta was fined 1.2 billion euros (about US$1.4 billion) in 2023, the biggest the commission has issued.
TikTok was fined 530 million euros (about US$608 million) and Instagram 405 million euros (about US$464 million). Google’s penalty now sits just below them.
Conversions here use the European Central Bank reference rate of 1.1463 dollars to the euro on 22 September 2026.
The inquiry itself began in February 2020, on the commission’s own initiative. It followed complaints from consumer groups across Europe about how Google recorded where people went.
Eight organisations had filed complaints from 2018 onwards, the Irish Times reported. BEUC, the European Consumer Organisation, said “late enforcement can be as harmful as no enforcement at all”.
The penalty is not payable yet
Under Irish law a data protection fine must be confirmed by a court before it can be collected. Penalties above 75,000 euros (about US$86,000) go to the High Court in Dublin.
The Irish Times reported on 22 September 2026 that an appeal by Google is inevitable. It noted that a 225 million euro penalty (about US$258 million) against WhatsApp from 2021 is still under appeal.
Google said the case involves “historical policies that have since been updated”. The company added: “From 2019 onwards, we’ve significantly evolved our practices and launched robust tools that make managing location data simple.”
Google has already changed some settings. The Irish Times reported that certain information is now deleted automatically once a set period has expired.
The decision is an administrative penalty by a regulator. No court has found wrongdoing and nobody has been charged with any offence.
What it means for African startups

African companies that serve users in Europe fall under the same regulation, wherever their engineers sit. A delivery or ride-hailing app built in Lagos or Nairobi must meet European consent standards if it has European users.
Nigeria has built its own regime. The Nigeria Data Protection Act of 2023 created the Nigeria Data Protection Commission.
That commission can fine a large company up to 2 percent of its annual gross revenue in the previous financial year. The threshold applies to firms the law calls data controllers of major importance.
At continental level, the African Union’s Malabo Convention sets rules on cyber security and personal data. Agreed in 2014, it entered into force on 8 June 2023 once fifteen member states had ratified it.
For African regulators, the Dublin decision is a worked example of how to hold a global platform to account. It also feeds the wider contest over data described in Africa: The New Scramble.
What to watch next
Google has six months from 21 September 2026 to bring its location data processing into compliance. Any appeal would run separately, through the Irish courts, and could take years.
The commission has said three further large inquiries into Google remain at an advanced stage. Their outcomes will show whether this penalty marks a change of pace or a one-off.
Frequently Asked Questions
How much was Google fined over location data?
Ireland’s Data Protection Commission fined Google 403 million euros (about US$462 million) on 21 September 2026 for breaches of the General Data Protection Regulation.
Is the Google location data fine final?
No. Irish law requires a court to confirm the penalty before it can be collected, and the Irish Times reported that an appeal by Google is inevitable.
What does the decision mean for African startups?
African apps with users in Europe must meet the same consent and transparency standards. Nigeria and the African Union now have comparable data protection rules of their own.
Connected Coverage
Sources
This article was produced by The Rio Times’ automated newsroom system. How we use AI · Report an error
Read More from The Rio Times