The Irish Data Protection Commission (DPC) has fined Google €403 million following an inquiry into how the company processes location data.
The DPC acts as Google's lead supervisory authority in the European Union under the one-stop-shop mechanism established by the General Data Protection Regulation, meaning decisions of this kind are coordinated with other national data protection authorities across the bloc.
The European Data Protection Board published notice of the fine, indicating the decision has been through the cooperation and consistency procedures that apply to cross-border enforcement cases.
This action concerns data protection law rather than the EU AI Act directly, but it is relevant to organisations building or deploying AI systems that rely on location data, since such data is frequently used for personalisation, profiling, and geolocation-based features.
As a compliance matter, organisations should note that large-scale enforcement actions of this kind demonstrate that regulators continue to scrutinise how location and behavioural data are collected, processed, and disclosed to users, independent of any AI-specific obligations.
For organisations preparing for the EU AI Act, this case is a reminder that AI governance programmes cannot be built in isolation from existing data protection compliance. Systems that ingest location data as training or inference input should be reviewed against both frameworks in parallel.
Further details of the DPC's findings, including the specific legal basis and any corrective measures ordered alongside the fine, may be published in the coming weeks.