Skip to content

Regulatory Pulse

DPC fines Google €403 million over location data: lawfulness, transparency and retention

The DPC has announced a €403 million final decision concerning Google location-data processing, with findings on lawfulness, fairness, accountability, transparency and retention.

Ireland and European Union
GDPR, location data, transparency, accountability and retention
Guidance
Official source reviewed

PrivacyBuilt Editorial · Source published Final enforcement decision; full decision pending publication · Reviewed 24 September 2026 · 7 min read

The 60-second summary

On 21 September 2026, the Data Protection Commission announced a final decision fining Google Ireland Limited €403 million over location-data processing in Web & App Activity, Location History and Location Accuracy. The inquiry covered processing from 25 May 2018 to 4 February 2020. Findings concerned lawfulness and fairness for Web & App Activity and Location History; inability to demonstrate compliance for Location Accuracy; transparency across all three features; and retention of location data in Web & App Activity and Location History. Google was ordered to bring the processing into compliance within six months. The full decision is pending publication, so the detailed legal reasoning and corrective terms are not yet available.

Timeline that matters

  1. 25 May 2018–4 February 2020

    Processing period examined

    The inquiry examined specified location-data processing during this period.

  2. February 2020

    Inquiry launched

    The DPC opened an own-volition inquiry after complaints from consumer organisations.

  3. 21 September 2026

    Final decision announced

    The DPC announced the infringements, €403 million fine and compliance order.

  4. Within six months

    Compliance deadline

    Google was ordered to bring the relevant processing into compliance; the precise operative date should be confirmed from the full decision.

  5. On publication

    Next legal review

    Review the full decision when released for detailed reasoning, corrective terms and fine allocation.

What changed

The final decision moves the matter from a long-running inquiry to binding enforcement, combining a substantial fine with a six-month compliance order. It reinforces that location settings, account controls and product labels do not by themselves demonstrate lawful, fair and transparent processing or justify retention. Organisations should be able to explain which signals create location inferences, how each purpose is authorised, what users understand at collection time and why every retention period is necessary.

Who should pay attention?

Product and engineering teams

Map every location signal, inference, setting and downstream use.

Privacy and legal teams

Validate legal basis, fairness, transparency, accountability and retention for each purpose.

Advertising and analytics teams

Check whether location influences profiles, interests, targeting or measurement.

UX and consent teams

Test whether controls and notices accurately explain processing at the point of collection.

Audit and risk teams

Retain evidence that configurations, deletion rules and user choices work in production.

What the guidance clarifies

The decision is final
The DPC announced a final decision and administrative fines totalling €403 million.
Three product features were examined
The inquiry covered Web & App Activity, Location History and Location Accuracy.
The findings differ by feature
Lawfulness and fairness findings concerned Web & App Activity and Location History; accountability findings concerned Location Accuracy; transparency findings covered all three.
Retention was a separate failure
The DPC identified retention infringements for location data in Web & App Activity and Location History.
A setting label is not enough
Organisations must demonstrate the actual legal basis, fairness, transparency and necessity of the processing behind each feature.
Detailed reasoning is still pending
The regulator has not yet published the full decision, so precise findings, fine allocation and corrective terms should not be inferred.

Location data requires purpose-by-purpose proof, not broad settings and assumptions

Why this matters for global organisations

Location signals can reveal movements, routines, interests and sensitive patterns. Organisations need a traceable connection between each signal, purpose, legal basis, notice, user control and retention rule, supported by production evidence rather than policy language alone.

  • Map raw signals, derived locations and downstream profiles.
  • Separate legal analysis and notices by feature and purpose.
  • Prove that user controls change processing in practice.
  • Delete location data when the justified retention period ends.

15 actions to start now

  1. Inventory every source of precise, approximate and inferred location data.
  2. Map location processing separately for account holders, signed-out users, devices and embedded services.
  3. Document each purpose, legal basis, necessity test and accountable owner.
  4. Identify advertising, personalisation, analytics, fraud and product-improvement uses.
  5. Test whether notices explain the relevant processing at the time data is obtained.
  6. Review whether feature names, toggles and defaults accurately represent underlying processing.
  7. Verify that disabling a setting stops all processing that users would reasonably associate with it.
  8. Separate consent-dependent processing from activities relying on another legal basis.
  9. Assess fairness risks from combining location with browsing, search, device or account data.
  10. Review sensitive inferences that could arise from places visited, routes and routines.
  11. Set purpose-specific retention periods and automated deletion controls.
  12. Test deletion across primary stores, logs, analytics systems, models, caches and backups.
  13. Record exceptions, legal holds and retention extensions with approval and expiry.
  14. Update DPIAs, records of processing and data-flow maps.
  15. Monitor publication of the full decision and reassess the control framework.

Suggested next steps

  • Select one live location-enabled product journey and trace every signal from collection to inference, advertising, retention and deletion. Reconcile the result with notices, controls, DPIAs and production logs.

Evidence worth retaining

  • Location-data inventory and end-to-end data-flow diagrams.
  • Purpose and legal-basis assessments for each feature.
  • Fairness and reasonable-expectations analysis.
  • Consent records and versioned interface evidence where consent is used.
  • Screenshots and test results for notices, toggles and defaults.
  • Processing logs showing the effect of user choices.
  • Advertising and profiling data dictionaries.
  • Sensitive-inference risk assessments.
  • DPIAs and approval records.
  • Retention schedules with purpose-level rationale.
  • Deletion job logs, exception registers and backup lifecycle evidence.
  • Access, sharing and vendor records.
  • Audit findings, remediation plans and management oversight.
  • Evidence retained for each relevant historical product version.

Questions to take to counsel or your conformity team

These are discussion prompts, not legal advice or conclusions.

  • Which technical signals can directly or indirectly infer a person’s location?
  • Does each feature have its own documented purpose and legal basis?
  • What would a reasonable user understand from the setting name and notice?
  • Does disabling a control stop collection, inference and downstream use?
  • Can location reveal sensitive behaviour, associations or interests?
  • Is location used to influence advertising or personalisation?
  • Why is each category retained for its current duration?
  • Can deletion be demonstrated across analytics, logs, models and backups?
  • Are account, device and signed-out processing flows assessed separately?
  • What changes may be required once the full decision is published?

Official sources

PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.

PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.