Regulatory Updates

Google’s €403m location data fine: lessons for every controller

Praeferre ResearchPraeferre Insights Team
Published
Read time5 min read
Regulatory Updates

On 21 September 2026 Ireland’s Data Protection Commission (DPC) fined Google €403 million and gave it six months to bring its processing of location data into line with the GDPR. The decision looks backwards, at settings and practices from 2018 to 2020, but the questions it asks of Google are ones every organisation that collects location or behavioural data should be able to answer today.

What the DPC decided

The inquiry examined three Google features: Web & App Activity, Location History and the Android Location Accuracy setting. It covered the period from 25 May 2018, when the GDPR took effect, to 4 February 2020, and was opened in February 2020 after complaints from European consumer organisations including BEUC.

According to the DPC and reporting by RTÉ, the regulator found that Google did not process location information lawfully, fairly and transparently. Users were often unaware that their location data was being used to target advertising or to infer their interests, and Google kept the data for longer than necessary. The DPC also found failings in accountability. Deputy Commissioner Graham Doyle said that keeping users’ location data for longer than necessary made their loss of control worse.

Google’s response, as reported by RTÉ, is that the case concerns historical policies that have since changed. It points to automatic deletion settings, better ad controls and more transparency introduced since 2019, and has said it intends to appeal.

Key points
Fine
€403 million, with an order to comply within six months.
Period examined
25 May 2018 to 4 February 2020.
Core failings
Lawfulness, fairness and transparency; retention for longer than necessary; accountability.
Status
Google has said it plans to appeal.

Why this matters beyond Google

It would be easy to file this under “Big Tech problems”. That would be a mistake. The DPC’s findings turn on three things that most organisations handle every day.

1. Settings that users do not understand are a transparency failure

The complaint was not that Google collected location data at all, but that people did not understand what switching a setting on actually meant for how their data was used. If your app, portal or connected product has toggles whose effect is explained only in a privacy notice few people read, you have the same exposure in miniature. Transparency is judged by what a reasonable user actually understood, not by what was technically disclosed somewhere.

2. Retention is a live enforcement issue, not housekeeping

Regulators increasingly treat over-retention as an aggravating factor rather than an administrative lapse. The logic is simple: every extra month you keep sensitive data extends the period in which it can be misused, breached or repurposed. Location data is a particularly sharp example because it can reveal where someone lives, works, worships or receives medical care.

3. “We fixed it later” does not close the file

This inquiry took more than six years from opening to decision, and the fine relates to conduct that Google says it has since changed. Remediation matters, and it may influence how a regulator views you, but it does not erase historic non-compliance. Your records need to show what you did at the time, not just what you do now.

“If a user cannot explain what a setting does, a regulator will assume they never really agreed to it.”

— Praeferre analysis

What to do now

Whether you run a consumer app, a fleet platform, a retail loyalty scheme or an HR system with geolocation, a short review now is cheaper than a long inquiry later.

  1. Map where location data enters your estate. Include SDKs, analytics tools, device telemetry and IP-derived location, not just features labelled “location”.
  2. Test your settings against real users. Ask people outside the product team what a toggle does. If their answer differs from what actually happens, rewrite the interface, not just the notice.
  3. Separate purposes. Data collected to deliver a service should not quietly flow into advertising or profiling. Document each purpose and its lawful basis in your records of processing.
  4. Set and enforce retention periods. Put hard limits on location and behavioural data, automate deletion, and evidence that deletion actually happens.
  5. Refresh your DPIAs. High-risk processing such as precise location tracking should have a current data protection impact assessment that reflects how the product works today.
  6. Keep a decision trail. Record why design choices were made and what privacy input was given. That evidence is what protects you if a complaint lands years from now.

Praeferre’s GRC automation platform helps teams keep records of processing, retention schedules and DPIAs current and linked to the controls that enforce them. For organisations without in-house capacity, our DPO as a Service provides experienced privacy leadership to run these reviews. See also our overview of the GDPR.

Get an expert review of how your products collect, explain and retain personal data.

Talk to a DPO

Common questions

Ireland’s Data Protection Commission found that Google did not process location data lawfully, fairly and transparently through its Web & App Activity, Location History and Location Accuracy features between May 2018 and February 2020, kept the data longer than necessary and fell short on accountability.

The decision was made under the EU GDPR, but the UK GDPR contains the same core principles on transparency, fairness and storage limitation. UK organisations processing location data should treat the findings as a useful benchmark.

Google has said it intends to appeal, so the outcome may still change. The DPC has ordered Google to bring its processing into compliance within six months.

Sources

  1. Data Protection Commission fines Google €403 million following Inquiry into Google’s processing of location data — Data Protection Commission, 21 September 2026
  2. Google fined €403m by data watchdog for location tracking — RTÉ, 21 September 2026