Technology reviews & practical guides
Ireland's Data Protection Commission has fined Google €403 million under the GDPR over location data in Web & App Activity, Location History and Location Accuracy, and given it six months to comply.

Ireland's Data Protection Commission (DPC) has fined Google €403 million under the GDPR over how it handled people's location data. The regulator announced its final decision on 21 September 2026, more than six years after it opened the inquiry in February 2020.
The fine covers three Google settings - Web & App Activity, Location History and Location Accuracy - and conduct between 25 May 2018 and 4 February 2020. Alongside the money, Google Ireland Limited has been ordered to bring its processing into compliance within six months.
The DPC acts as Google's Lead Supervisory Authority in the EU, because Google's European operations are run from Ireland. It opened this own-volition inquiry in February 2020 after complaints from several European consumer rights organisations, including BEUC, the European Consumer Organisation.
The final decision imposes administrative fines totalling €403 million, roughly $460 million at current exchange rates, and an order requiring Google to bring its processing into compliance within six months. It was made by the three Commissioners for Data Protection: Dr Des Hogan, Dale Sunderland and Niamh Sweeney. The European Data Protection Board has also published the announcement, confirming the €403,000,000 figure and the compliance order.
The inquiry covers location data processing from 25 May 2018, the day the GDPR started to apply, to 4 February 2020. It is a finding about that period, not a ruling on how Google handles location data today.
A Google Account setting, so it only applies to people who have an account. When it is on, Google uses it to process information about your activity on Google services, including sites and apps. According to the DPC, that can include browsing history, search history and location data.
An opt-in service that tracks your location while you carry a compatible mobile device and works out the places you visited, what you were doing and the routes between them. It powers Timeline, the private map in Google Maps, and saves where you go with signed-in devices even when you are not using a Google service.
An Android operating system feature that helps a phone work out its location more precisely than GPS alone. Unlike the other two, it is available to Android users whether or not they have a Google Account.
The DPC found four groups of infringements, and they do not apply equally to all three settings:
Location Accuracy therefore comes out of the decision with narrower findings: accountability and transparency, but no finding of unlawful processing or excessive retention. The DPC has not yet published the full decision, so there is no breakdown of how much of the €403 million relates to each feature.
Deputy Commissioner Graham Doyle explained why the regulator treats location data so seriously:
"Location data is a type of personal data which is processed by way of location tracking, and includes data collected or processed by Google, which by itself or in conjunction with other information an individual's location can be inferred. Location data can bring both benefits and harms to individuals. It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private. The GDPR provides a high level of protection of personal data throughout the EEA, and requires that the processing of personal data must be carried out in a lawful, fair and transparent manner. As a result of Google's failures in this regard, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data. The retention of users' location data for longer than necessary aggravated this loss of control"
At €403 million this is the DPC's fourth-largest GDPR fine. Only three penalties are bigger:
The gap to Instagram's penalty is just €2 million.
Google's position is that the case is about the past. The company says it centres on "historical policies that have since been updated", and in a statement said: "From 2019 onwards, we've significantly evolved our practices and launched robust tools that make managing location data simple."
The main change Google points to is how Timeline works today. In a blog post on 12 December 2023, Marlo McGriff, Director of Product for Google Maps, announced that Timeline would be saved on the user's device rather than in the account, that optional cloud backups would be automatically encrypted so that "no one can read it, including Google", and that the default auto-delete period for Location History would drop from 18 months to 3 months. Google said the rollout would happen gradually over the following year on Android and iOS.


None of that changes the outcome of this case. The decision looks at what Google did between May 2018 and February 2020, when Location History data lived in the Google Account and the defaults were different.
The case covers old practices, but the settings still exist. Malwarebytes suggests these steps if you want to limit what Google keeps:
Turning a setting off stops new data from being saved. It does not remove what is already there, so delete past activity as a separate step.
More in Tech News
Browse Tech News