Ireland’s Data Protection Commission (DPC) has fined Google Ireland Limited €403 million after concluding that the technology giant violated the General Data Protection Regulation (GDPR) while processing users’ location data.
Announced on September 21, 2026, the decision also orders Google to bring the affected processing operations into compliance within six months.
The enforcement action follows an own-volition inquiry opened in February 2020 after the regulator received complaints from several European consumer-rights organizations, including BEUC.
Acting as Google’s lead supervisory authority in the European Union, the DPC examined location-data processing carried out from May 25, 2018, the date the GDPR became applicable, through February 4, 2020.
According to findings published by the Data Protection Commission, investigators focused on three Google features: Web & App Activity, Location History and Android’s Location Accuracy.
Google Fined €403 Million
The DPC found that Google failed to process location information lawfully and fairly through Web & App Activity and Location History. It also identified transparency failures across all three services and ruled that Google retained location information for too long in the first two.
For Location Accuracy, the regulator said Google could not demonstrate compliance with GDPR accountability requirements covering lawfulness, fairness and transparency.
This distinction matters because accountability obliges a data controller not merely to comply, but to maintain evidence showing that its data-processing practices satisfy the regulation.
Web & App Activity is available to Google Account holders and can process browsing, search and location information generated through Google sites and applications.
Location History, which requires opt-in, records movement from compatible devices and uses Google Maps Timeline to show place visits, activities and routes even when the person is not actively using a Google service.
Location Accuracy, meanwhile, is an Android feature that combines signals to determine a device’s position more precisely than GPS alone and can operate regardless of whether the owner has a Google Account.
The case highlights why geolocation records require strong privacy controls. Individually or when combined with other information, repeated location signals can expose travel patterns, routines and visits to inherently private places.
DPC Deputy Commissioner Graham Doyle warned that affected users may not have understood that location information could influence advertising or enable Google to infer their interests, while excessive retention further reduced their control.
Under GDPR principles, organizations must process personal data lawfully, fairly and transparently, collect only what is necessary, and retain identifiable information no longer than required.
Organizations using location-enabled products must document their compliance. This means they need to go beyond just showing consent. They should have clear reasons for using location data, provide understandable notices, maintain trackable data flows, and enforce schedules for deleting data.
Privacy teams should test whether product interfaces accurately reflect backend collection, advertising use, account controls and retention behavior.
Google said the case concerned historical policies that it has since updated. The company pointed to privacy changes introduced from 2019, including automatic deletion periods, controls for disabling personalized advertising and on-device storage for Maps Timeline data.
Google previously said Timeline is off by default and that encrypted cloud backup is optional. The DPC said peer European supervisory authorities assisted with the case and that it will publish the full decision later. Until that document appears, the detailed allocation of the €403 million penalty and the precise remediation measures remain unavailable.
Even so, the six-month compliance order puts Google under a firm deadline and signals that unclear location tracking, weak accountability and over-retention can produce substantial regulatory exposure.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

