On 21 October 2026, Ireland's Data Protection Commission (DPC) announced a fine of €403 million on Google Ireland Limited. The inquiry covered how Google handled location data through three features that most Android and Google account users have touched without thinking about it: Web & App Activity, Location History and Location Accuracy.
It is easy to read this as a Big Tech story that has nothing to do with a business of ten or fifty people. It does. The DPC did not invent a new rule. It applied the basics of the GDPR, namely a valid legal basis, honest explanations, a limit on how long you keep data and the ability to prove you comply. Those basics apply to every website, app and back office that touches location data.
What the DPC actually found
The DPC opened the inquiry in February 2020 on its own initiative, acting as lead supervisory authority for Google in the EU. It examined the period from 25 May 2018 to 4 February 2020, and it took more than six years to reach a decision. According to the EDPB's summary of the decision, four kinds of infringement were established:
- Unlawful and unfair processing (Articles 5 and 6) for Web & App Activity and Location History.
- Failure to demonstrate compliance (accountability, Article 5) for Location Accuracy.
- Insufficient transparency (Articles 12 and 13) for all three features.
- Keeping location data longer than necessary (storage limitation, Article 5) for Web & App Activity and Location History.
Alongside the fine, Google has six months to bring its processing into compliance. The decision was signed by Commissioners Des Hogan, Dale Sunderland and Niamh Sweeney.
“The retention of users' location data for longer than necessary aggravated this loss of control.”
That is how DPC Deputy Commissioner Graham Doyle described the harm. His point: people could have been unaware that their location was being used to influence them with ads or to infer their interests, and could lose control over their personal data.
The three features, in plain words
Web & App Activity saves activity from Google services and apps to a Google account, including search and browsing activity and location signals. Location History is the opt-in tracking that fed Google Maps Timeline, a record of the places and routes a person visited. Location Accuracy is an Android feature that uses non-GPS signals, such as nearby networks, to place a device more precisely, and it worked regardless of what a user had done with their account settings.
The pattern across all three is the same one regulators keep finding. Data was collected for one purpose, then used for another (ad personalisation and interest inference). The explanations were not clear enough for people to understand that. And the data stayed around for longer than any specific need could justify.
“Historical policies” is not a defence
Google's answer is that the case concerns historical policies that have since been updated. It points to automatic deletion options (three to 36 months), Timeline data stored on the device, and simpler ad personalisation controls. Reports also say Google may appeal parts of the decision on legal grounds.
Both things can be true, and the business lesson is the same either way. The conduct at issue ended in early 2020 and the decision arrived in late 2026. A practice you fixed three years ago can still be examined, and a fine is calculated on what happened, not only on what you do today. Fixing something quietly does not close the file.
The complaints behind the case are also worth noticing. Eight consumer organisations from Norway, the Netherlands, Greece, the Czech Republic, Slovenia, Poland, Sweden and Denmark filed complaints coordinated through the European consumer organisation BEUC. Coordinated complaints from advocacy groups are now a standard way for a data protection case to start, in the same way as the 171 drivers behind the Uber decision.
“We're not Google” is the wrong reading
The size of the fine reflects Google's scale. The obligations behind it do not depend on scale. Anywhere your business collects, infers or stores where people are, you are answering the same questions the DPC asked. Typical places where small and mid-sized businesses do exactly that:
- Delivery, field-service and fleet apps that record GPS traces of customers or employees, often for longer than the job requires.
- Store locators, booking and ride tools that ask for precise location when a postcode would do.
- Analytics and advertising SDKs inside your mobile app that pick up location signals you never intended to collect.
- Websites and ad platforms that use IP-based or inferred location to build audiences and profile interests.
- Employee tracking in vehicles and phones, where the power imbalance makes consent a poor legal basis.
Using a platform vendor does not move the responsibility. If you decide to switch on a tracking feature for your customers or staff, you are the controller for that processing, and you are the one who has to explain it and justify how long it stays.
Answer a few questions in our GDPR decision tree to see which obligations apply to a specific use of personal data, including location.
Where this sits in the enforcement picture
The €403 million fine is the fourth largest the DPC has imposed on a large technology company, just below the €405 million fine on Instagram, and behind TikTok (€530 million) and Meta (€1.2 billion). The DPC has also said that three further large Google inquiries are at an advanced stage, so this is unlikely to be the last decision of its kind.
It also lands in a busy month for enforcement. The EDPB adopted its first harmonised method for calculating fines, which we explain in the EDPB's new fining methodology, and the Dutch authority's €825 million decision against Uber is only about a month old. The direction is consistent: regulators are writing bigger decisions, coordinating across borders, and looking closely at transparency and retention rather than only at breaches.
A practical checklist for this week
- Find your location data. List every app, SDK, form, device and vendor that collects precise or inferred location, including IP-based location. Most businesses find two or three sources they had forgotten.
- Pick a lawful basis and write it down. Consent must be specific and freely given. For staff tracking, consent rarely works, so document the necessity instead.
- Collect the minimum. Use city or postcode instead of GPS where that is enough, and switch off background tracking that no feature needs.
- Set a retention period and enforce it. Location traces should be deleted or anonymised on a schedule, not kept indefinitely “in case”. Automate the deletion.
- Explain it in plain language. Say what you collect, why, and what else it is used for, at the moment the user sees the permission prompt, not only in a privacy policy.
- Keep evidence. Record your decisions, consent logs and deletion runs. Accountability was one of the four findings against Google, and it means being able to prove compliance.
Check also the cookie banner and tracker mistakes that regulators keep finding, since many location signals reach advertisers through the same scripts.
The bottom line
Google's fine is about ordinary duties applied to extraordinary volume: a lawful basis, clear explanations, limited retention and proof. The decision took six years, the conduct is from 2018 to 2020, and the compliance clock now runs for another six months. Businesses that treat location as “just another field” tend to discover it is one of the most sensitive things they hold.
Book a free consultation with GDPRGard → and we will help you map where your business collects location data and what needs to change.
Sources
- Data Protection Commission: fines Google €403 million following inquiry into its processing of location data (21 Sep 2026)
- EDPB: The Irish DPC fines Google €403,000,000 following an inquiry
- The Irish Times: Irish data protection watchdog fines Google €403m over GDPR breaches
- RTÉ: Google fined €403m by DPC
- BleepingComputer: Google fined €403 million over location data privacy violations
Also read:
- Uber's €825M Fine: When “The Algorithm Decided” Becomes a Liability
- The EDPB just standardised how every DPA in Europe calculates your fine
- The 5 most common cookie banner mistakes — and how to fix them