The Irish Data Protection Commission (DPC) has levied a €403 million penalty on Google Ireland Limited for breaching GDPR rules in how it handled users’ location data. The ruling, issued September 21, 2026, requires the search giant to overhaul its practices within six months.
What triggered the fine
The investigation was launched voluntarily by the DPC in February 2020 after complaints from European consumer rights groups, including BEUC. It examined Google’s location-based features during the period from May 25, 2018—the date GDPR came into force—up through February 4, 2020.
The DPC focused on three specific services where location data is collected or processed: Web & App Activity, Location History, and Android’s Location Accuracy. The regulator found Google failed to lawfully and fairly process data in both Web & App Activity and Location History; it also found transparency failings in all three services. Plus, the company held on to personal location data for too long in the first two cases.
Laws broken & services involved
“Accountability” under GDPR requires controllers not only to obey the rules, but to keep documentation proving that processing aligns with the law. The DPC said Google did not meet this standard for the Location Accuracy feature, which enhances GPS signals using other sensor data even if a user doesn’t actively use a Google account.
Here’s what the services do:
- Web & App Activity: tracks browsing, searches, and location info from Google sites and apps tied to a Google Account.
- Location History: opt-in feature that logs movement by compatible devices and shows routes via Maps Timeline, even when users aren’t actively engaging with services.
- Location Accuracy: Android’s feature that uses signals beyond GPS to improve positioning, and works even for users without Google Accounts.
The DPC emphasized that repeated traces of location data can reveal sensitive insights—patterns of everyday life, visits to private places, routines—making robust privacy safeguards essential.
Google’s response & what’s next
Google defended its record by pointing out that many of the policies under scrutiny have since changed. It mentioned updates made after 2019 including setting automatic deletion timelines, giving users stronger controls over personalized advertising, and shifting Maps Timeline data storage options to on-device.
The DPC will make the full decision public soon; details like how the €403 million is broken down among the specific services and what precise fixes Google must implement are not yet disclosed. But the six-month compliance window sets a firm deadline.
The ruling underscores the potential risks for companies that collect and retain location data without clear, transparent user consent and purpose. It sends a broader signal across tech: vague opt-ins, long retention periods, and ambiguous product settings can lead to serious regulatory consequences.
Analytically, this case is a bellwether. It illustrates how GDPR enforcement is maturing—no longer just admonishing unclear practices but levying major fines and demanding complete overhauls. Other companies handling location or sensor-based tracking need to scrutinize their transparency, retention policies, and accountability documentation now. The coming months will show whether Google’s promised fixes satisfy regulators and whether enforcement authorities across the EU align their standards tightly.