Ireland Orders Google to Overhaul Location-Data Processing After €403 Million GDPR Penalty
Ireland's DPC fined Google €403M for GDPR violations in location data processing via Web & App Activity, Location History and Location Accuracy.
Illustrative image generated with AI
Google faces a €403 million penalty in Ireland after regulators found that its handling of location data failed to meet several requirements of the European Union’s General Data Protection Regulation.
The enforcement action, reported on September 21, 2026, covers location information processed through Web & App Activity, Location History, and Android’s Location Accuracy capability. Ireland’s Data Protection Commission also ordered Google to bring the relevant processing into compliance within six months.
The inquiry assessed practices used from May 25, 2018, through February 4, 2020. It found problems involving lawfulness, fairness, transparency, accountability, and the length of time some location data was retained.
This is a privacy and data-governance case, not a security breach. There is no reported malicious actor, unauthorized access, exposed infrastructure, or software vulnerability.
Complaints Triggered a Multi-Year GDPR Investigation
The DPC opened its investigation in February 2020 after complaints from European consumer-rights organizations. BEUC, the European Consumer Organization, was involved, and member groups had submitted complaints to national data-protection authorities in November 2018.
Ireland handled the cross-border case because Google’s European headquarters are in Dublin, making the Irish authority the company’s lead EU privacy regulator. GDPR protections apply across the European Economic Area.
The DPC concluded that Google had not adequately explained or justified how location information was collected, used, and retained. According to the regulator, this weakened users’ practical ability to control personal data that could reveal movements, routines, interests, and other sensitive details.
The penalty is reportedly the fourth-largest privacy fine issued by the Irish regulator. It is also the first DPC penalty against Google, although the authority still has three other privacy investigations involving the company. Previous major DPC enforcement has included a €1.2 billion fine against Meta, while TikTok has also received substantial penalties.
The complete Google decision has not yet been published. Consequently, the precise processing activities covered by the six-month compliance order remain unknown, as does the regulator’s assessment of every privacy change Google introduced after the investigated period.
Three Google Features Are at the Center of the Case
The findings concern three services that handle location information in different ways. Their settings, account requirements, and data uses are not identical.
Web & App Activity
Web & App Activity is a Google Account setting covering activity across Google services. Depending on the service and configuration, processed information can include browsing activity, searches, and location-related data.
The DPC found that Google’s location-data processing through this feature did not meet GDPR standards for lawful and fair processing. It also identified inadequate transparency and concluded that the relevant location information was kept longer than necessary.
Google’s current position is that Web & App Activity does not save a device’s precise position. The company says it uses an estimated general area instead.
Location History
Location History is an opt-in service for compatible mobile devices signed into a Google Account. It can record places a person visits, infer routes and activities, and present that information through a private Google Maps Timeline.
Collection can continue even when the person is not actively using another Google service. That persistence increases the sensitivity of the resulting record because movements can be reconstructed over time.
For Location History, the DPC again found deficiencies in lawfulness, fairness, and transparency. It also determined that collected information had been retained beyond what was necessary.
Location Accuracy
Location Accuracy is an Android feature designed to calculate a device’s position more accurately than GPS alone. It differs from the other two services because Android users can access it without having a Google Account.
The findings here were narrower. Google failed to demonstrate that its processing through Location Accuracy complied with GDPR requirements for transparency and accountability, including proof that the activity was lawful, fair, and transparent.
That distinction matters. The regulator was not only assessing what Google said it did; it also examined whether the company could produce sufficient evidence of compliance.
Persistent Location Records Reduce User Control
Location information can reveal much more than a coordinate. When combined with searches, browsing history, application activity, and account data, it can support inferences about a person’s habits, interests, journeys, and potentially sensitive circumstances.
The DPC said users might not have understood that their location could help shape advertising or be used to infer interests. Unclear explanations of processing can therefore affect both awareness and the validity of choices presented through settings or opt-in flows.
Retention added a separate layer of risk. The longer location-linked information remains available, the longer it can be used for profiling, secondary purposes, or other processing that users may not expect. Extended storage also increases the consequences of any future misuse or unauthorized access, although no such compromise has been reported in this case.
The regulator linked opaque processing and excessive retention to a broader loss of control. Users cannot make an informed decision about data collection when they do not clearly understand which feature is operating, what information it derives, or how long the resulting records remain available.
The concern also extends to inferred location. A service may determine where somebody is from location signals alone or by combining them with other information. Privacy obligations are therefore not limited to a stored GPS coordinate.
Google Points to Privacy Changes Introduced After the Investigated Period
Google says the case concerns historical policies that it has since changed. The company began adding automatic-deletion controls in May 2019, allowing users to remove Web & App Activity and Location History data after three or 18 months.
In June 2020, Google made 18-month deletion the default for Web & App Activity on new accounts and for people activating Location History for the first time.
Further changes followed in December 2023. Google announced that Maps Timeline information would move to on-device storage and that users enabling Location History for the first time would receive a three-month deletion default. Timeline data is now reported to be stored locally and automatically removed when it is older than three months.
Google has also introduced controls through which users can choose automatic-deletion periods for account information. These changes may reduce centralized retention and give users more direct control, but the DPC has not publicly confirmed whether they fully satisfy the new order.
It is also unclear whether Google still conducts every type of processing addressed by the findings. Publication of the complete decision should clarify what must change and whether existing controls count toward compliance.
The Fine Still Faces Irish Court Procedures
The penalty is not immediately collectible. A DPC fine becomes payable after confirmation by an Irish court, and Google may appeal to the Irish High Court within 28 days of receiving formal notice of the decision.
The company has six months to correct the processing covered by the order. Because the DPC has not disclosed its exact scope, organizations and users cannot yet determine which settings, disclosures, retention rules, or technical flows Google must modify.
The unresolved details are substantial. They include the precise compliance measures required for each feature and the extent to which Google’s later product changes address the violations.
Users and Organizations Can Review Location Retention Now
Google users do not need to wait for the complete decision to reduce the amount of location-linked information retained through their accounts and devices. Practical steps include:
- Review Web & App Activity and determine whether it should remain enabled.
- Check Location History and disable it if a persistent travel record is unnecessary.
- Select the shortest suitable automatic-deletion period, including the available three-month or 18-month options.
- Inspect Google Maps Timeline settings and confirm where Timeline information is stored.
- Review Android Location Accuracy separately, since it can operate without a Google Account.
- Check both account-level and device-level location controls rather than assuming one setting governs every feature.
Organizations managing Google accounts or Android devices should verify whether enterprise controls and defaults differ from those used for consumer accounts. They should also document notices, opt-in processes, processing purposes, deletion mechanisms, and retention schedules.
That evidence is central to accountability. The DPC’s findings show that making privacy controls available is not enough if an organization cannot demonstrate lawful processing, provide intelligible explanations, and justify how long sensitive information is kept.
Sources
This article is an original reworking based on the sources below.
