Google has been hit with a €403 million GDPR fine by Ireland’s Data Protection Commission (DPC) over the way it handled users’ location data.
The decision was announced on September 21, 2026, following an investigation that examined Google’s location-data practices between May 2018 and February 2020.
Along with the financial penalty, the DPC has ordered Google to bring the affected data-processing practices into compliance with GDPR requirements within six months.
What Did the DPC Find?
The investigation focused on three Google features:
- Web & App Activity
- Location History
- Location Accuracy
According to the DPC, Google did not meet GDPR requirements for lawfulness and fairness when processing location data through Web & App Activity and Location History.
The regulator also found transparency problems across all three features. It said Google had not adequately demonstrated compliance with GDPR accountability requirements for Location Accuracy and had retained some location data through Web & App Activity and Location History longer than necessary.
The investigation began in February 2020 after the DPC received complaints from several European consumer-rights organizations, including BEUC.
Why Location Data Is Sensitive
Location information can reveal much more than where someone is at a particular moment.
When collected over time, it can show travel patterns, frequently visited places, daily routines and other information about a person’s activities. The DPC said users could have been unaware that their location data might be used to influence advertising or help infer their interests.
The case also highlights the importance of data retention. GDPR requires organizations to handle personal information lawfully and transparently and avoid keeping personal data for longer than necessary.
For companies collecting location information, simply having a privacy notice is not enough. Organizations should understand exactly what data is collected, why it is collected, where it goes, who can access it and when it should be deleted.
Google Says Its Practices Have Changed
Google said the case relates to historical policies and pointed to privacy changes introduced since 2019.
The company has since added features such as automatic deletion controls and additional tools for managing location information. Google Maps Timeline has also moved toward storing location information directly on users’ devices rather than relying on cloud storage by default.
The DPC has not yet released the complete decision and said it will publish the full document later. The regulator has nevertheless ordered Google to make the required changes within six months.
The case is another reminder that location data needs strong privacy controls, clear user choices and well-documented compliance processes—especially when the information can reveal detailed patterns about people’s lives.