On September 21, 2026, Ireland’s Data Protection Commission (DPC) imposed a €403 million penalty on Google Ireland Limited for infringing the General Data Protection Regulation (GDPR) in the handling of users’ location data. This decision mandates that Google rectify the related processing activities within a six-month timeframe.
Investigation and Findings
The enforcement action originated from a self-initiated inquiry by the DPC in February 2020, following grievances from various European consumer advocacy groups, including BEUC. As Google’s principal supervisory body within the European Union, the DPC scrutinized the company’s location data processing from the GDPR’s inception on May 25, 2018, until February 4, 2020.
The DPC’s investigation concentrated on Google’s Web & App Activity, Location History, and Android’s Location Accuracy features. The findings revealed that Google’s processing of location data via Web & App Activity and Location History was neither lawful nor fair, with transparency shortcomings identified across all examined services.
Key Compliance Issues
The DPC noted that Google retained location data excessively and failed to demonstrate GDPR compliance, particularly regarding lawfulness, fairness, and transparency, in its Location Accuracy feature. This is significant as GDPR accountability requires data controllers not only to comply but also to validate that data-handling practices adhere to regulatory standards.
Web & App Activity can collect search, browsing, and location data for Google account users. Location History, which necessitates user opt-in, logs device movements and uses Google Maps Timeline for tracking locations and activities. Location Accuracy, an Android function, enhances device positioning beyond GPS capabilities.
Implications for Privacy and Compliance
This case underscores the necessity of robust privacy measures for geolocation data, as such information can reveal personal travel patterns and visits to private locations. DPC Deputy Commissioner Graham Doyle emphasized that users might not fully comprehend how location data could shape advertising strategies or allow Google to infer personal interests.
GDPR mandates that personal data must be processed lawfully, fairly, and transparently, with only necessary information collected and retained for no longer than needed. Companies using location-based services must demonstrate compliance by providing clear data use explanations, maintaining data flow records, and enforcing data deletion schedules.
Future Outlook and Google’s Response
Google indicated that the case pertains to outdated policies and highlighted privacy enhancements initiated since 2019, such as automatic data deletion and improved user controls over personalized advertising and data storage. Despite these changes, the six-month compliance deadline emphasizes the regulatory risks of unclear location tracking and data retention practices.
The DPC, with assistance from other European supervisory authorities, plans to release the complete decision details later. Meanwhile, the case serves as a crucial reminder for organizations about the importance of transparent data practices and stringent adherence to GDPR standards.
