Ireland's Data Protection Commission (DPC) has announced the fine, which it said was one of the largest of its kind imposed by the Irish watchdog. The penalty follows an inquiry launched six years ago after complaints from several European consumer rights organisations.
The investigation focused on the processing of location data within three specific Google features — Web & App Activity, Location History and Location Accuracy — covering the period from 25 May 2018 to 4 February 2020.
Location data, which can be used to infer a person's whereabouts, can 'reveal a significant amount of information about an individual, including information that is inherently private', said DPC deputy commissioner Graham Doyle in a statement released on Monday.
Doyle added: 'The GDPR provides a high level of protection of personal data throughout the EEA, and requires that the processing of personal data must be carried out in a lawful, fair and transparent manner.'
He continued: 'As a result of Google's failures, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data.'
The report said the company's practices 'infringed' GDPR, a European regulation that came into effect on 25 May 2018.
Google said in response that it had improved its data protection practices in recent years. The company's specific response to the fine was not detailed in the available sources.
The inquiry's findings mark a significant regulatory action against one of the world's largest technology companies over privacy practices tied to user location data.