Prefer to listen? Click play for AI narration

On 21 October 2026, Ireland's Data Protection Commission (DPC) announced a fine of €403 million on Google Ireland Limited. The inquiry covered how Google handled location data through three features that most Android and Google account users have touched without thinking about it: Web & App Activity, Location History and Location Accuracy.

It is easy to read this as a Big Tech story that has nothing to do with a business of ten or fifty people. It does. The DPC did not invent a new rule. It applied the basics of the GDPR, namely a valid legal basis, honest explanations, a limit on how long you keep data and the ability to prove you comply. Those basics apply to every website, app and back office that touches location data.

What the DPC actually found

The DPC opened the inquiry in February 2020 on its own initiative, acting as lead supervisory authority for Google in the EU. It examined the period from 25 May 2018 to 4 February 2020, and it took more than six years to reach a decision. According to the EDPB's summary of the decision, four kinds of infringement were established:

Alongside the fine, Google has six months to bring its processing into compliance. The decision was signed by Commissioners Des Hogan, Dale Sunderland and Niamh Sweeney.

“The retention of users' location data for longer than necessary aggravated this loss of control.”

That is how DPC Deputy Commissioner Graham Doyle described the harm. His point: people could have been unaware that their location was being used to influence them with ads or to infer their interests, and could lose control over their personal data.

€403M
Fine on Google Ireland, Irish DPC, 21 Sep 2026
3
Location features examined
4
Kinds of GDPR infringement found
6 mo
Deadline to bring processing into compliance

The three features, in plain words

Web & App Activity saves activity from Google services and apps to a Google account, including search and browsing activity and location signals. Location History is the opt-in tracking that fed Google Maps Timeline, a record of the places and routes a person visited. Location Accuracy is an Android feature that uses non-GPS signals, such as nearby networks, to place a device more precisely, and it worked regardless of what a user had done with their account settings.

The pattern across all three is the same one regulators keep finding. Data was collected for one purpose, then used for another (ad personalisation and interest inference). The explanations were not clear enough for people to understand that. And the data stayed around for longer than any specific need could justify.

“Historical policies” is not a defence

Google's answer is that the case concerns historical policies that have since been updated. It points to automatic deletion options (three to 36 months), Timeline data stored on the device, and simpler ad personalisation controls. Reports also say Google may appeal parts of the decision on legal grounds.

Both things can be true, and the business lesson is the same either way. The conduct at issue ended in early 2020 and the decision arrived in late 2026. A practice you fixed three years ago can still be examined, and a fine is calculated on what happened, not only on what you do today. Fixing something quietly does not close the file.

The complaints behind the case are also worth noticing. Eight consumer organisations from Norway, the Netherlands, Greece, the Czech Republic, Slovenia, Poland, Sweden and Denmark filed complaints coordinated through the European consumer organisation BEUC. Coordinated complaints from advocacy groups are now a standard way for a data protection case to start, in the same way as the 171 drivers behind the Uber decision.

“We're not Google” is the wrong reading

The size of the fine reflects Google's scale. The obligations behind it do not depend on scale. Anywhere your business collects, infers or stores where people are, you are answering the same questions the DPC asked. Typical places where small and mid-sized businesses do exactly that:

Using a platform vendor does not move the responsibility. If you decide to switch on a tracking feature for your customers or staff, you are the controller for that processing, and you are the one who has to explain it and justify how long it stays.

🧭
GDPRGard Tool
Not sure what your tracking needs legally?

Answer a few questions in our GDPR decision tree to see which obligations apply to a specific use of personal data, including location.

Open the decision tree →

Where this sits in the enforcement picture

The €403 million fine is the fourth largest the DPC has imposed on a large technology company, just below the €405 million fine on Instagram, and behind TikTok (€530 million) and Meta (€1.2 billion). The DPC has also said that three further large Google inquiries are at an advanced stage, so this is unlikely to be the last decision of its kind.

It also lands in a busy month for enforcement. The EDPB adopted its first harmonised method for calculating fines, which we explain in the EDPB's new fining methodology, and the Dutch authority's €825 million decision against Uber is only about a month old. The direction is consistent: regulators are writing bigger decisions, coordinating across borders, and looking closely at transparency and retention rather than only at breaches.

A practical checklist for this week

  1. Find your location data. List every app, SDK, form, device and vendor that collects precise or inferred location, including IP-based location. Most businesses find two or three sources they had forgotten.
  2. Pick a lawful basis and write it down. Consent must be specific and freely given. For staff tracking, consent rarely works, so document the necessity instead.
  3. Collect the minimum. Use city or postcode instead of GPS where that is enough, and switch off background tracking that no feature needs.
  4. Set a retention period and enforce it. Location traces should be deleted or anonymised on a schedule, not kept indefinitely “in case”. Automate the deletion.
  5. Explain it in plain language. Say what you collect, why, and what else it is used for, at the moment the user sees the permission prompt, not only in a privacy policy.
  6. Keep evidence. Record your decisions, consent logs and deletion runs. Accountability was one of the four findings against Google, and it means being able to prove compliance.

Check also the cookie banner and tracker mistakes that regulators keep finding, since many location signals reach advertisers through the same scripts.

The bottom line

Google's fine is about ordinary duties applied to extraordinary volume: a lawful basis, clear explanations, limited retention and proof. The decision took six years, the conduct is from 2018 to 2020, and the compliance clock now runs for another six months. Businesses that treat location as “just another field” tend to discover it is one of the most sensitive things they hold.

Book a free consultation with GDPRGard → and we will help you map where your business collects location data and what needs to change.

Sources

Share this article

Also read:

⚠️ This article is for informational purposes only and does not constitute legal advice. For complex compliance situations, consult a qualified data protection professional. GDPR and EU AI Act requirements are subject to ongoing regulatory guidance — verify current obligations with your legal adviser.