Summary
Ireland’s Data Protection Commission fined Google Ireland €403 million after finding GDPR infringements in the processing of location data through three Google and Android features. Google was ordered to bring the processing into compliance within six months.
Ireland’s Data Protection Commission (DPC) has fined Google Ireland €403 million after finding that the company infringed the EU General Data Protection Regulation (GDPR) in its processing of location data. The regulator also ordered Google to bring the relevant processing into compliance within six months.
The DPC announced the final decision on 21 September 2026 after an inquiry into Google’s handling of location information between 25 May 2018, when the GDPR took effect, and 4 February 2020. The inquiry examined three features: Web & App Activity, Location History and Location Accuracy.
What the DPC investigated
Web & App Activity is a Google Account setting that processes information about activity on Google services, including browsing history, search history and location data, when enabled.
Location History is an opt-in service that tracks a user’s location through compatible mobile devices. Google uses the data to infer information such as places visited, activities and routes between locations. Its Timeline feature displays this information as a private map in Google Maps and can save the map of a user’s movements even when the user is not using a Google service.
Location Accuracy is an Android operating-system feature that helps a device determine its position more precisely than relying only on the device’s GPS inputs. Unlike the other two features described by the DPC, it is available to Android users whether or not they hold a Google Account.
The findings and compliance order
The DPC found that Google’s processing of location data through Web & App Activity and Location History breached GDPR requirements concerning lawfulness and fairness. It also found that Google failed to meet its accountability obligations for Location Accuracy because it could not demonstrate compliance with the principles of lawfulness, fairness and transparency.
Transparency obligations were found to have been breached in relation to all three features. The regulator also found infringements concerning the retention of location data in Web & App Activity and Location History.
Under the GDPR, accountability requires an organisation not only to follow data-protection principles but also to be able to demonstrate that it has done so. Transparency requires people to receive understandable information about how their personal data is processed.
The DPC said location data can reveal an individual’s whereabouts either by itself or when combined with other information. It can make online services more useful, but it can also expose private details such as movements, activities and inferred interests. According to the regulator, Google’s failures could leave people unaware that their location data was being used to influence advertising or infer interests, while retaining the data longer than necessary could further reduce their control over it.
The €403 million penalty is an administrative fine. The DPC said the full decision will be issued in due course, while the compliance order gives Google six months to change the relevant processing so that it meets the regulator’s requirements.