Google has been fined €403 million by Ireland’s Data Protection Commission after a six-year investigation into how the company collected, used and retained location information through several Google account and Android features.
The September 21 decision concerns Google’s Web & App Activity, Location History and Location Accuracy features between May 25, 2018, when the General Data Protection Regulation became applicable, and February 4, 2020.
The Irish regulator concluded that Google violated several core GDPR requirements, including rules governing lawfulness, fairness, transparency, accountability and data retention. It also ordered Google to bring the processing covered by the decision into compliance within six months.
Google says the case concerns historical practices that it has substantially changed since the period investigated.
But the decision is significant for reasons that reach well beyond Google Maps.
At its core, the case asks what meaningful control over location data actually looks like when one company has multiple settings, products and data-processing systems capable of collecting or deriving where a person has been.
The Investigation Started With Complaints Filed in 2018
The case has been moving through Europe’s privacy enforcement system for almost eight years.
In November 2018, consumer organizations in seven European countries filed GDPR complaints concerning Google’s location practices. The coordinated action was organized through the European Consumer Organisation, BEUC, and relied on research from the Norwegian Consumer Council.
The consumer groups argued that Google’s interface and account settings pushed users toward enabling location-related processing through techniques including repeated prompts, confusing choices and settings spread across different areas of a Google account.
Ireland’s DPC formally opened its own inquiry in February 2020. Because Google Ireland serves as Google’s European headquarters for much of its EU processing, the Irish regulator acts as its lead supervisory authority for many GDPR matters.
The resulting investigation examined three different Google features rather than treating “location tracking” as a single system.
Three Google Settings Were at the Center of the Case
The distinction between those three settings is important.
Location History was designed to save information about where a user had been and create a history of places and routes associated with the user’s account.
Web & App Activity saved activity across Google services and could also save information associated with that activity, including location information.
Location Accuracy is associated with determining a device’s location using information beyond GPS alone, including signals such as Wi-Fi networks, mobile networks and sensors.
From a consumer perspective, those distinctions can become difficult.
A person might reasonably think that disabling something called “Location History” means Google is no longer retaining information capable of showing where that person has been.
But location information can potentially enter Google’s systems through other settings and services.
That separation between controls became part of the broader controversy that initially produced the complaints.
The DPC Found Different Violations for Different Features
The Irish regulator did not simply declare all three features unlawful.
Its findings were more specific.
The DPC found violations involving the lawfulness and fairness of Google’s processing of location information through Web & App Activity and Location History.
It also found that Google failed to satisfy its accountability obligations concerning Location Accuracy because it could not adequately demonstrate compliance with GDPR principles of lawfulness, fairness and transparency.
All three features were found to have transparency problems.
The regulator also found violations concerning Google’s retention of location information through Web & App Activity and Location History.
Those distinctions matter because GDPR compliance involves more than obtaining a click on a settings screen.
A company must have a lawful basis for processing personal information. It must process the information fairly. It must explain the processing with sufficient transparency. And under the accountability principle, the company must be able to demonstrate that it complies with those obligations.
Location Data Can Reveal Much More Than a Dot on a Map
Location information receives particular attention from privacy regulators because a long-term history of someone’s movements can disclose an extraordinary amount about that person.
A single location observation may reveal relatively little.
A persistent history can reveal where someone lives, where they work and how they commute.
It may also indicate visits to hospitals, fertility clinics, places of worship, political demonstrations, addiction treatment centers, lawyers’ offices, hotels or other sensitive locations.
That was part of the concern raised when European consumer organizations first complained about Google’s location practices in 2018. BEUC specifically argued that location histories could allow inferences about matters including religious beliefs, political activity, health and sexual orientation.
Irish Deputy Commissioner Graham Doyle made a similar point when announcing the new decision, describing location information as capable of revealing details about an individual’s habits and personality.
The issue therefore is not simply whether Google knew where someone was standing at a particular moment.
It is what could be learned when those observations were accumulated, connected to an account and retained over time.
Transparency Is Different From Simply Providing a Privacy Policy
The case also illustrates one of the more difficult requirements of the GDPR.
A company can disclose a data practice somewhere in its privacy documentation and still face questions about whether the processing was sufficiently transparent.
Transparency under European privacy law is concerned with whether information is presented in a way people can reasonably understand when making decisions about their data.
That becomes more difficult when a service has several overlapping settings.
A user could disable one location-related feature while another setting continues processing some form of location information.
The legal question then becomes whether the relationship between those settings was made sufficiently clear.
The DPC found transparency infringements involving all three Google features it investigated.
This has practical implications for any organization with complicated privacy controls.
Having a separate toggle for each processing operation is not automatically the same thing as giving users meaningful control if the relationship among those controls is difficult to understand.
Accountability May Be the Most Important Part of the Decision
The finding concerning Location Accuracy is particularly interesting from a privacy governance perspective.
The DPC said Google failed its accountability obligations because it was unable to demonstrate compliance with the GDPR’s lawfulness, fairness and transparency principle for the processing at issue.
That wording goes to one of the GDPR’s central concepts.
Organizations are not merely expected to comply.
They are expected to be able to prove it.
That requires documentation around what information is processed, why it is processed, which legal basis applies, how long the information is retained, which controls are available to users and how those controls actually affect processing.
For complicated technology platforms, this can become a substantial operational requirement.
A product team may understand why a particular location signal exists. An engineering team may understand how it is technically processed. A privacy team may know which legal basis the company believes applies.
The company still needs a coherent record connecting those pieces.
When regulators ask how a system operates, “our engineers understand it” is not the same thing as demonstrating GDPR compliance.
The DPC Also Focused on How Long Google Kept Location Data
Retention was another significant part of the decision.
The DPC found violations involving how long location information associated with Web & App Activity and Location History was retained.
The GDPR’s storage-limitation principle generally requires organizations to avoid keeping identifiable personal data longer than necessary for the purposes for which it is processed.
Location histories make that issue particularly important because the privacy impact can increase as the dataset grows.
A few location records may reveal several destinations.
Years of location information can create a detailed record of a person’s life.
Doyle said the retention of the information for longer than necessary further reduced individuals’ control over their data.
Retention policies therefore cannot be treated as an administrative afterthought.
An organization needs to determine why a category of information is being retained for a particular period and whether the purpose still requires that information.
Google Says These Were Historical Practices
Google has emphasized that the DPC investigation concerns practices dating from 2018 through early 2020.
A company spokesperson told Reuters the decision involves historical policies and pointed to changes Google has made to its location controls since that period.
Those changes have been substantial.
In May 2019, while the period examined by the DPC was still underway, Google announced controls allowing users to automatically delete Location History and Web & App Activity information after either three or 18 months.
Google later made auto-delete the default for new users of certain activity settings and added additional privacy controls.
In 2023, the company announced another major change to Google Maps Timeline, the successor branding associated with Location History. Google said Timeline information would increasingly be stored directly on users’ devices, with optional encrypted cloud backup, rather than primarily associated with centralized Google account storage. It also reduced the default auto-delete period for newly enabled Timeline histories to three months.
Google’s current documentation says Timeline is off by default and requires the user to opt in. It also provides auto-delete choices and separate controls for other forms of activity and location information.
Those current controls do not erase the historical conduct being examined by the DPC, but they are important context when assessing how Google’s location practices operate today.
Turning Off One Location Feature Does Not Necessarily Turn Off Every Use of Location
Google’s current documentation also illustrates why location privacy remains complicated even after significant changes.
Turning off Timeline does not necessarily stop all processing involving location.
Google explains that location information can still be associated with other services and settings, including Web & App Activity, Search-related history and information inferred from IP addresses or device activity.
There are legitimate reasons for some of those uses.
A search engine needs some idea of location to answer a request such as “restaurants near me.” Maps needs location information to provide navigation. Weather results and local search features similarly depend on geography.
The privacy challenge is making the distinction understandable.
Users need to know what type of location information is being collected, why it is being collected, whether it is stored, for how long and which control affects it.
That is considerably harder than providing one master “location on/off” switch.
The Case Took More Than Six Years to Resolve
The enforcement timeline is also noteworthy.
The original consumer complaints were filed in November 2018.
The Irish DPC formally opened its inquiry in February 2020.
The final decision arrived in September 2026.
That delay means the enforcement action is addressing products and policies that Google has already modified repeatedly.
It is one of the structural challenges of privacy enforcement against large technology platforms.
Complex investigations can take years while the underlying product continues evolving.
By the time a regulator issues a decision, the interface users see today may bear little resemblance to the system that generated the original complaint.
That does not make enforcement meaningless. A regulator can still establish how privacy law applies to a category of processing, impose financial consequences for past conduct and require remaining practices to change.
But it makes dates especially important when reporting these cases.
The €403 million fine relates to Google’s location processing between May 25, 2018 and February 4, 2020. It should not be read as a finding that every aspect of Google’s current location settings operates identically today.
The Full DPC Decision Still Matters
There is also an important limitation to what is currently known.
As of the announcement, Ireland’s DPC had not yet published its complete final decision.
The regulator’s summary identifies the provisions and processing activities at issue, but the full ruling will provide the detailed reasoning behind the findings.
That document should explain more precisely why the DPC considered the processing unfair or unlawful, what it found deficient in Google’s notices and interfaces, how it assessed retention, and how the €403 million penalty was calculated.
Until the full decision is available, some of the most interesting legal questions remain unresolved publicly.
For privacy professionals, those details may ultimately be more useful than the size of the fine.
The Lesson Is Bigger Than Location Tracking
The €403 million penalty reinforces a broader problem facing companies that operate complicated privacy settings.
Privacy controls can become fragmented as products grow.
One engineering team creates an activity setting. Another product introduces location functionality. Advertising systems use information for personalization. Account settings develop over time. New privacy controls are added after the original systems are already running.
Eventually, a user may face a collection of individually understandable switches whose combined effect is difficult to understand.
The GDPR does not focus exclusively on whether each toggle technically exists.
Regulators can examine whether the overall processing is lawful and fair, whether the explanations actually make sense to users, whether information is kept longer than necessary, and whether the organization can document the reasoning behind the entire system.
That may be the more durable lesson from Ireland’s Google decision.
Privacy compliance is not simply a matter of giving people settings.
The settings have to correspond with the underlying data flows, the disclosures have to explain those flows accurately, retention has to be justified, and the company needs evidence showing why it believes the entire system complies with the law.
For location information, where a long history of seemingly ordinary data points can reveal some of the most private details of a person’s life, regulators appear willing to apply those requirements aggressively.