Faultline Faultline Kommando 161

Germany · de.indymedia · · 2h

Bottleneck Ireland: Only 400 million fine for Google's years of violation of the law

Deutsch (original) · Auto-translated to English

It took almost a decade for the Irish data protection authority to come to a decision. Accordingly, Google unlawfully processed large amounts of sensitive location data of its users. The delayed procedure once again highlights the Irish enforcement problem.


https://cdn.netzpolitik.org/wp-upload/2026/09/imago0121079373h-scaled-e1...class="attachment-landscape-860 size-landscape-860 wp-post-image" alt="Google headquarters in Dublin, Ireland." decoding="async" loading="lazy" srcset="https://cdn.netzpolitik.org/wp-upload/2026/09/imago0121079373h-scaled-e1...2560w,https://cdn.netzpolitik.org/wp-upload/2026/09/imago0121079373h-scaled-e1...860w,https://cdn.netzpolitik.org/wp-upload/2026/09/imago0121079373h-scaled-e1...1200w,https://cdn.netzpolitik.org/wp-upload/2026/09/imago0121079373h-scaled-e1...380w,https://cdn.netzpolitik.org/wp-upload/2026/09/imago0121079373h-scaled-e1...1536w,https://cdn.netzpolitik.org/wp-upload/2026/09/imago0121079373h-scaled-e1...2048w" sizes="auto, (max-width: 2560px) 100vw, 2560px" />
For years, Google has secretly manipulated its users to hoard their location data. – All rights reserved:https://www.imago-images.de/st/0121079373?searchID=c66c8e83-272f-4853-86...>IMAGO / NurPhoto

Google will have to pay a fine of 403 million euros, announced todayhttps://www.dataprotection.ie/en/news-media/latest-news/data-protection-...Data Protection Authority DPC(Data Protection Commission). Accordingly, Google illegally collected and processed users' location data and thus violated the General Data Protection Regulation. The data company now has six months to convert its data processing to comply with the law.


The data protection officers took a closer look at the period between 2018 and 2020. Google unlawfully processed the location data in web and app activities as well as in the location history, according to the DPC. In addition, Google was unable to prove that the personal data collected was processed lawfully and comprehensibly and did not comply with transparency requirements. In addition, Google unlawfully retained collected data in the three services mentioned. The full text of the decision is not yet available.


The DPC explains that this is not a formal triviality. It may not have been apparent to individuals that their location was being used, for example, to influence them through advertising or to draw conclusions about their interests. This led to a loss of control over one's own personal data, said the DPC. “Storing user location data beyond what is necessary exacerbated this loss of control.”


Problem known for almost a decade


The penalty is based on media reports and investigations by European consumer protection organizations from 2018. At that time the Norwegian couldhttps://www.forbrukerradet.no/side/google-manipulates-users-into-constan...ådet authoritythat Google uses manipulative design to force its users to be constantly monitored. Previously it hadhttps://netzpolitik.org/2018/google-speichert-standort-auch-bei-ausgesch...AP reportsthat Google stores the location of users even if they have turned off the location history. Together with seven other consumer protection organizations, the European Consumer Association finally submittedhttps://www.beuc.eu/enforcement/every-step-you-take">BEUCa complaint in Irelanda.


Although BEUC boss Agustín Reyna welcomes today's decision from Ireland, he sharply criticizes the length of the process. This is disproportionate to the seriousness of the violation: "Delayed intervention can be just as damaging as no intervention at all. Consumers' fundamental rights must be protected more quickly and effectively," sayshttps://www.beuc.eu/press-releases/google-fined-invasive-location-tracki...in a press release.

–––

The hut is on fire! We're going in.
We oppose fascisation. We fight for a free, open and solidarity-based society. We defend basic rights for everyone.https://netzpolitik.org/spenden/?via=rss">Thisonly possible with your support.

–––


https://netzpolitik.org/2025/databroker-files-outing-durch-standortdaten...through location data



It is clear: “Google has tracked hundreds of millions of European consumers over the years in order to find out as much as possible about them,” says the BEUC boss.https://netzpolitik.org/2024/berliner-unternehmen-datenhaendler-verticke...can be extremely sensitivebecause they "reveal a lot about our private lives: for example, which school our children attend, how often someone has visited a hospital or a religious place. This massively intrudes on privacy, violates the fundamental right to data protection and violates the GDPR," continues Reyna.


Bottleneck Ireland


The case ended up with the Irish DPC because Google, like many other companies from other EU countries, is based there in the EU. The country had lured them alonghttps://www.srf.ch/news/international/starkes-wir Growth-tech-f...Corporate taxesand sometimeshttps://www.lto.de/recht/nachrichten/n/c46520p-eugh-apple-irland-beihilf...Aidin billions. Ireland has become increasingly dependent on these companies: despite the low tax rates, almost half of the income collected by Ireland comes from corporate taxeshttps://thenextweb.com/news/ireland-eu-presidency-big-tech-conflict">led...come from three corporations, presumably from Apple, Microsoft and the pharmaceutical company Eli Lilly, also from the USA.


Ireland gave a helping hand, ashttps://netzpolitik.org/2022/scheidender-datenschutzanwalt-ich-wol...öhr applies to GDPR enforcement, the corporations also at the regulatory level. For almost a decade, complaints have been accumulating that Irish authorities such as the DPChttps://netzpolitik.org/2021/irland-bremst-das-durchstellungsproblem-der-...carry off, decisionshttps://netzpolitik.org/2021/irland-wenn-die-datenschutzbehoerde-zur-fac...of Big Techor evenhttps://netzpolitik.org/2020/kritik-an-geheimen-absprachen-facebooks-mit...Agreementsmeet with the corporations. A few years ago, this led to an unusual step by the European Data Protection Board (EDPB), which was difficult to understandhttps://netzpolitik.org/2022/missende-rechtsbasis-schwerer-schlag-fu...the DPC threw overboardand stopped blatantly illegal behavior from Meta.


Ireland proposes “digital expropriation” of Europeans


Whether the latest decision from Ireland heralds a lasting change of course for the country in its dealings with tech companies remains to be seen. At the moment it doesn't look like it: there are stillhttps://noyb.eu/en/project/dpa/dpc-ireland">DozensThe process has been open for years, as the data protection organization noyb documents. In addition, Ireland holds the presidency of the Council of the EU until the end of the year and can accordinglyhttps://www.bundestag.de/resource/blob/1193144/prioritaeten-der-eu-ratsp...set devices. This includes, among other things, the one proposed by the EU Commissionhttps://netzpolitik.org/2025/faq-zum-digitalen-omnibus-was-plant-die-eu-...to move forward.

–––

The work of netzpolitik.org is financed by donations from our readers.
Become part of this unique community and support our public interest-oriented, advertising- and tracking-free journalismhttps://netzpolitik.org/spenden/?via=rss">nowwith a donation.

–––


How currenthttps://pro.politico.eu/news/223891">Politicoreported (€), Ireland proposes as part of the so-called “Digital Omnibus” that tech companies should be allowed to use personal data practically without restriction for training AI systems. However, Ireland is not alone in its view; Germany is also said to be one of the EU countries that support the proposal.


“This is nothing other than a ‘digital expropriation’ of Europeans,”https://noyb.eu/de/ai-eu-member-states-plan-digital-expropriation-europe...the prominent noyb data protection officer Max Schrems, the one with thehttps://noyb.eu/de/irische-behoerde-schliesst-noyb-aus-laufenden-verfahr...been in a clinch for a long timelies. “Everything that we have ever typed into digital systems or that the companies have otherwise received would be fair game for the AI ​​companies.”


Most recently, EU Commission President Ursula von der Leyen advocated so-called artificial intelligence in her speech on the State of the European Unionhttps://netzpolitik.org/2026/rede-zur-lage-der-union-wir-wollen-kuenstli...to be rolled out as widely as possible across the EU. The EU already agreed on this in May, which was only passed a few years agohttps://netzpolitik.org/2026/ki-verregulation-eu-parlament-und-rat-einigen-...(AI Act).and reduce requirements for the industry.


–––

The work of netzpolitik.org is financed by donations from our readers.
Become part of this unique community and support our public interest-oriented, advertising- and tracking-free journalismhttps://netzpolitik.org/spenden/?via=rss">nowwith a donation.

https://vg03.met.vgwort.de/na/4afc6c470d9c4c30a755f06ac328aa7a"width="1" height="1" alt>

web address: https://netzpolitik.org/2026/schnellenhals-irland-nur-400-millionen-traffic-fuer-googles-jahrelangen-rechtsbruch/Author/Group: Tomas RudlTopics: Netactivismfeed date: Monday, September 21, 2026 - 4:13 p.m

Read the full story at the source

Source: de.indymedia