Ireland’s Data Protection Commission (DPC), the lead EU regulator for Google under GDPR’s one-stop-shop mechanism, has imposed a €403 million penalty on Google Ireland Limited following a multi-year investigation into how the company collected and handled users’ location data. The decision, issued September 21, 2026, is one of the larger GDPR fines levied against a single company and adds to a growing list of enforcement actions against major location-tracking practices across the tech industry.
Three Features, One Common Thread
The DPC’s inquiry examined three distinct Google features that all touch location data in different ways:
- Web & App Activity — the setting controlling whether Google logs a user’s activity, including location signals, across its own apps and partner sites
- Location History — the feature that builds a timeline of where a signed-in user’s devices have been
- Location Accuracy — an Android-level feature that improves the precision of location data using additional sensors and network information
Rather than a single failure, the regulator found a pattern spanning all three: the DPC concluded Google processed location data through Web & App Activity and Location History without a lawful basis and without being sufficiently fair to users about what was happening with their data. All three services were found to fall short on transparency, and the first two were flagged for retaining location information longer than the DPC considered justified. On Location Accuracy specifically, the regulator said Google could not adequately demonstrate accountability — the GDPR obligation to be able to show, not just claim, that processing meets the law’s lawfulness, fairness, and transparency requirements.
A Long Road From Complaint to Fine
The roots of the case go back further than the fine itself. The DPC opened its inquiry in February 2020 after complaints filed by European consumer-rights organizations, including the influential umbrella group BEUC, which represents consumer bodies across the EU. The examination ultimately covered a specific window of Google’s practices, from May 25, 2018 — the date GDPR took effect — through February 4, 2020. That multi-year gap between the conduct being examined and the final decision is typical of how long complex, cross-border GDPR investigations under the one-stop-shop system tend to run, especially when other EU data protection authorities weigh in during the review process, as is standard procedure for decisions of this size.
Google’s Response
Google has pushed back on the framing of the decision rather than the underlying facts, stating that the case concerns “historical policies that it has since updated.” The company pointed to a series of privacy changes rolled out starting in 2019, including automatic deletion windows for stored activity data, more granular controls over personalized advertising, and a shift toward storing Maps Timeline data locally on-device rather than in Google’s cloud infrastructure — a change that, if a device is lost or the account is deleted, means the location history may no longer be recoverable from Google’s servers at all.
What Happens Next
Beyond the financial penalty, the DPC has given Google a firm compliance window: the company must bring the affected processing operations in line with GDPR requirements within six months of the decision. That puts a concrete deadline on practices the regulator says have already been substantially changed, effectively requiring Google to formally close the gap between its updated policies and what the DPC’s order demands.
For other companies handling location data at scale, the decision reinforces a theme regulators have repeated across several major GDPR cases: retrofitting privacy improvements after the fact doesn’t erase liability for the years a system operated without them. Transparency and data-minimization obligations apply from the moment a feature launches, not from whenever a company gets around to updating its settings menu.
Leave a Reply
You must be logged in to post a comment.