The 60-second summary
On 21 September 2026, the Data Protection Commission announced a final decision fining Google Ireland Limited €403 million over location-data processing in Web & App Activity, Location History and Location Accuracy. The inquiry covered processing from 25 May 2018 to 4 February 2020. Findings concerned lawfulness and fairness for Web & App Activity and Location History; inability to demonstrate compliance for Location Accuracy; transparency across all three features; and retention of location data in Web & App Activity and Location History. Google was ordered to bring the processing into compliance within six months. The full decision is pending publication, so the detailed legal reasoning and corrective terms are not yet available.
Timeline that matters
25 May 2018–4 February 2020
Processing period examined
The inquiry examined specified location-data processing during this period.
February 2020
Inquiry launched
The DPC opened an own-volition inquiry after complaints from consumer organisations.
21 September 2026
Final decision announced
The DPC announced the infringements, €403 million fine and compliance order.
Within six months
Compliance deadline
Google was ordered to bring the relevant processing into compliance; the precise operative date should be confirmed from the full decision.
On publication
Next legal review
Review the full decision when released for detailed reasoning, corrective terms and fine allocation.
What changed
The final decision moves the matter from a long-running inquiry to binding enforcement, combining a substantial fine with a six-month compliance order. It reinforces that location settings, account controls and product labels do not by themselves demonstrate lawful, fair and transparent processing or justify retention. Organisations should be able to explain which signals create location inferences, how each purpose is authorised, what users understand at collection time and why every retention period is necessary.
Who should pay attention?
Product and engineering teams
Map every location signal, inference, setting and downstream use.
Privacy and legal teams
Validate legal basis, fairness, transparency, accountability and retention for each purpose.
Advertising and analytics teams
Check whether location influences profiles, interests, targeting or measurement.
UX and consent teams
Test whether controls and notices accurately explain processing at the point of collection.
Audit and risk teams
Retain evidence that configurations, deletion rules and user choices work in production.
What the guidance clarifies
- The decision is final
- The DPC announced a final decision and administrative fines totalling €403 million.
- Three product features were examined
- The inquiry covered Web & App Activity, Location History and Location Accuracy.
- The findings differ by feature
- Lawfulness and fairness findings concerned Web & App Activity and Location History; accountability findings concerned Location Accuracy; transparency findings covered all three.
- Retention was a separate failure
- The DPC identified retention infringements for location data in Web & App Activity and Location History.
- A setting label is not enough
- Organisations must demonstrate the actual legal basis, fairness, transparency and necessity of the processing behind each feature.
- Detailed reasoning is still pending
- The regulator has not yet published the full decision, so precise findings, fine allocation and corrective terms should not be inferred.
Location data requires purpose-by-purpose proof, not broad settings and assumptions
Why this matters for global organisations
Location signals can reveal movements, routines, interests and sensitive patterns. Organisations need a traceable connection between each signal, purpose, legal basis, notice, user control and retention rule, supported by production evidence rather than policy language alone.
- Map raw signals, derived locations and downstream profiles.
- Separate legal analysis and notices by feature and purpose.
- Prove that user controls change processing in practice.
- Delete location data when the justified retention period ends.
15 actions to start now
- Inventory every source of precise, approximate and inferred location data.
- Map location processing separately for account holders, signed-out users, devices and embedded services.
- Document each purpose, legal basis, necessity test and accountable owner.
- Identify advertising, personalisation, analytics, fraud and product-improvement uses.
- Test whether notices explain the relevant processing at the time data is obtained.
- Review whether feature names, toggles and defaults accurately represent underlying processing.
- Verify that disabling a setting stops all processing that users would reasonably associate with it.
- Separate consent-dependent processing from activities relying on another legal basis.
- Assess fairness risks from combining location with browsing, search, device or account data.
- Review sensitive inferences that could arise from places visited, routes and routines.
- Set purpose-specific retention periods and automated deletion controls.
- Test deletion across primary stores, logs, analytics systems, models, caches and backups.
- Record exceptions, legal holds and retention extensions with approval and expiry.
- Update DPIAs, records of processing and data-flow maps.
- Monitor publication of the full decision and reassess the control framework.
Suggested next steps
- Select one live location-enabled product journey and trace every signal from collection to inference, advertising, retention and deletion. Reconcile the result with notices, controls, DPIAs and production logs.
Evidence worth retaining
- Location-data inventory and end-to-end data-flow diagrams.
- Purpose and legal-basis assessments for each feature.
- Fairness and reasonable-expectations analysis.
- Consent records and versioned interface evidence where consent is used.
- Screenshots and test results for notices, toggles and defaults.
- Processing logs showing the effect of user choices.
- Advertising and profiling data dictionaries.
- Sensitive-inference risk assessments.
- DPIAs and approval records.
- Retention schedules with purpose-level rationale.
- Deletion job logs, exception registers and backup lifecycle evidence.
- Access, sharing and vendor records.
- Audit findings, remediation plans and management oversight.
- Evidence retained for each relevant historical product version.
Questions to take to counsel or your conformity team
These are discussion prompts, not legal advice or conclusions.
- Which technical signals can directly or indirectly infer a person’s location?
- Does each feature have its own documented purpose and legal basis?
- What would a reasonable user understand from the setting name and notice?
- Does disabling a control stop collection, inference and downstream use?
- Can location reveal sensitive behaviour, associations or interests?
- Is location used to influence advertising or personalisation?
- Why is each category retained for its current duration?
- Can deletion be demonstrated across analytics, logs, models and backups?
- Are account, device and signed-out processing flows assessed separately?
- What changes may be required once the full decision is published?
Official sources
- Data Protection Commission — final decision announcement, 21 September 2026
- EUR-Lex — General Data Protection Regulation
- Data Protection Commission — decisions register
PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.
PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.