Ireland’s Data Protection Commission (DPC) has imposed a fine of €403 million on Google for violations of the General Data Protection Regulation (GDPR) related to its handling of user location data. The decision, announced on September 21, 2026, concludes an investigation initiated in February 2020, which itself stemmed from complaints filed by several European consumer groups, including BEUC, dating back six years.
The DPC’s inquiry focused on Google’s processing of location data between May 25, 2018, when the GDPR came into effect, and February 4, 2020. Specifically, the investigation examined three Google features: "Web & App Activity," "Location History," and "Location Accuracy."
"Web & App Activity" tracks user interactions across Google services, sites, and applications, incorporating location data. "Location History" builds a timeline of a device’s movements over time, even when Google services are not actively in use. "Location Accuracy," an Android operating system feature, enhances location precision beyond standard GPS and applies to all Android users, regardless of whether they are signed into a Google account.
The DPC commissioners, Dr. Des Hogan, Mr. Dale Sunderland, and Ms. Niamh Sweeney, identified multiple issues with Google’s practices. They determined that the processing of data through "Web & App Activity" and "Location History" failed to meet GDPR requirements for lawfulness and fairness. Furthermore, Google could not demonstrate compliance with lawfulness, fairness, and transparency rules for its "Location Accuracy" feature.
Transparency was found to be a systemic problem across all three features. The DPC also concluded that Google retained location data for longer than permitted under GDPR. These findings represent four distinct violations spanning data collection, retention, and disclosure.
Deputy Commissioner Graham Doyle emphasized that location data, while enhancing online services, can also reveal highly private information about individuals. The DPC’s investigation found that Google’s failures meant users might have been unaware that their location data was being used for targeted advertising or to build interest profiles, thereby reducing their control over their personal information. The extended retention of this data exacerbated the issue.
The DPC has given Google six months to align its data processing practices with GDPR requirements. This is not the first time Google has faced scrutiny from the Irish regulator. The €403 million penalty is the fourth-largest EU privacy fine issued by the DPC, which has previously levied larger fines against companies such as TikTok and Meta, including a record €1.3 billion fine against Meta for transferring European user data to the United States. The six-year duration from initial complaint to final decision highlights the lengthy process involved in GDPR enforcement cases.






