€403 Million GDPR Lesson: When Location Data Becomes a Governance Failure

€403 Million GDPR Lesson: When Location Data Becomes a Governance Failure


Ireland’s Data Protection Commission has fined Google €403 million over its processing of users’ location data — turning an old data-processing practice into a very current lesson in privacy governance, transparency and accountability.

On September 21, 2026, Ireland’s Data Protection Commission (DPC) announced its final decision following an investigation into Google Ireland Limited’s processing of location data.

The investigation focused on Google’s Web & App Activity, Location History and Location Accuracy features during the period from May 25, 2018, to February 4, 2020.

The DPC concluded that Google had infringed several requirements of the EU General Data Protection Regulation (GDPR) and imposed administrative fines totalling €403 million. Google was also ordered to bring the affected processing activities into compliance within six months.

The Investigation

The DPC launched the inquiry in February 2020 after receiving complaints from several European consumer-rights organisations, including BEUC.

The investigation examined how Google processed location information through three specific mechanisms:

1. Web & App Activity

Web & App Activity allows Google Account users to save information about activity across Google services, websites and applications.

The information can include search and browsing activity as well as location information.

2. Location History

Location History records location information associated with compatible devices.

According to the DPC, the feature can be used to infer information such as places visited, activities and routes between locations.

3. Location Accuracy

Location Accuracy is an Android capability that helps determine a device’s location more precisely than GPS alone by using additional sources of information.

Unlike some account-based services, Location Accuracy is available to Android users regardless of whether they have a Google Account.

The DPC examined the way these three mechanisms processed location data during the investigation period.

What Did the DPC Find?

The decision identified several areas of GDPR non-compliance.

The findings included issues concerning:

  • Lawfulness and fairness of processing location data through Web & App Activity and Location History.
  • Transparency relating to all three features.
  • Accountability, specifically Google’s ability to demonstrate compliance regarding Location Accuracy.
  • Retention, with the DPC finding that certain location data was retained longer than necessary through Web & App Activity and Location History.

The issue therefore went beyond the simple question of whether location data was collected.

The regulator examined why it was processed, how users were informed, how much control users had and how long the information was retained.

Transparency Was Central

One of the most important aspects of the decision is the emphasis on transparency.

Location data can reveal significantly more than a simple geographical coordinate.

Repeated location information can potentially expose patterns involving:

  • Places an individual regularly visits
  • Movement patterns
  • Activities
  • Interests
  • Relationships and routines
  • Other sensitive aspects of personal life

The DPC stated that failures around lawfulness, fairness and transparency could leave individuals unaware that their location information could be used, for example, to influence advertising or infer interests.

That can reduce an individual’s ability to exercise meaningful control over personal information.

This creates an important privacy principle:

A user clicking “Enable” does not automatically mean the underlying processing is sufficiently transparent.

Consent and control mechanisms need to be understandable in the context in which the data is actually being processed.

Retention Became Another Issue

The investigation also examined how long location data was retained.

The DPC found infringements concerning retention of location data associated with Web & App Activity and Location History.

This is important because GDPR compliance is not simply about answering:

“Are we allowed to collect this data?”

Organisations also need to answer:

“Why do we still need it?”

That distinction moves privacy governance from collection controls toward the entire data lifecycle.

A mature privacy programme therefore needs visibility across:

Collection → Purpose → Processing → Access → Sharing → Retention → Deletion

A weakness anywhere along that lifecycle can become a regulatory issue.

€403 Million Is Only One Part of the Story

The financial penalty is obviously significant.

But the more important lesson for organisations may be what sits behind the number.

The DPC did not simply identify a technical failure.

The decision touched multiple governance dimensions:

Lawfulness.

Was the processing legally justified?

Fairness.

Was the processing conducted in a manner that appropriately respected individuals?

Transparency.

Did users understand what was happening with their data?

Accountability.

Could the organisation demonstrate that its processing complied with GDPR requirements?

Retention.

Was data being kept longer than necessary?

These are governance questions as much as technology questions.

The CISO and Privacy Connection

Location data sits at an interesting intersection between cybersecurity, privacy, data governance and business analytics.

Security teams traditionally focus on protecting data from unauthorised access.

Privacy governance asks a different set of questions:

  • Should the organisation collect the data?
  • What is the legitimate purpose?
  • Is the processing proportionate?
  • Does the user understand the processing?
  • Who can access the information?
  • How long should it remain available?
  • Can it be deleted reliably?
  • Can the organisation demonstrate compliance?

This means an organisation can have strong encryption, IAM, endpoint protection and SOC capabilities and still face substantial privacy exposure.

Protecting data is not the same as governing data.

Privacy by Design Needs to Be Operational

The case also reinforces the importance of embedding privacy considerations into product design.

For organisations developing applications that process sensitive or behavioural data, privacy cannot remain a document sitting inside the compliance function.

It needs to influence engineering decisions.

That includes:

Data minimisation

Collect only what is necessary for the defined purpose.

Purpose limitation

Clearly establish why information is being processed and prevent uncontrolled secondary use.

Transparency

Explain processing in a way that users can realistically understand.

Retention controls

Define retention periods and enforce deletion rather than relying on indefinite storage.

User control

Provide meaningful mechanisms to review, change or withdraw choices where applicable.

Accountability

Maintain evidence demonstrating why processing decisions comply with regulatory requirements.

Google’s Response

Google has said that the case concerns practices from an earlier period and that it has since made changes to its approach.

According to Reuters, Google pointed to measures including enhanced user controls, automatic deletion and the use of less precise location data.

The DPC nevertheless ordered Google to bring the affected processing into compliance within six months.

The full DPC decision is expected to provide further detail on the regulator’s reasoning.

The Bigger Governance Lesson

The Google case demonstrates how privacy risk can accumulate quietly.

A location feature may appear to be a normal product capability.

A setting may appear to be a simple user preference.

A retention period may appear to be an engineering decision.

An advertising use case may appear to be a business optimisation.

But when these decisions are connected, they form a data-processing ecosystem.

And that ecosystem is subject to regulatory scrutiny.

The real question for organisations is therefore not:

“Do we have a privacy policy?”

It is:

“Can we demonstrate that our actual data practices match our stated privacy commitments?”

That is the difference between privacy documentation and privacy governance.

What Security and Privacy Leaders Should Take Away

The €403 million decision provides several practical checkpoints for organisations:

1. Map sensitive data flows.
Know where location, behavioural and other high-value personal data originates, travels and is stored.

2. Validate the purpose.
Every significant processing activity should have a clearly defined and defensible purpose.

3. Test transparency from the user’s perspective.
A legally written disclosure is not necessarily meaningful transparency.

4. Review retention continuously.
Data should not remain simply because storage is cheap.

5. Connect privacy and security governance.
Security protects information; privacy determines whether and how that information should be processed.

6. Maintain evidence.
GDPR accountability requires organisations to demonstrate compliance, not merely claim it.

7. Treat product changes as privacy changes.
New features, analytics capabilities, AI models and advertising mechanisms can fundamentally alter existing data-processing risks.

Final Takeaway

The €403 million Google fine is not merely a story about location tracking.

It is a reminder that modern organisations don’t just manage data.

They manage permissions, purposes, expectations, retention and accountability around that data.

The technology may collect the location.

The business may derive the insight.

But governance determines whether the entire chain is defensible.

In the era of data-driven products, privacy risk rarely begins with a breach. Sometimes, it begins with data being collected, processed or retained without sufficient clarity about why.

And when that governance gap reaches regulatory scrutiny, the cost can be measured not only in euros, but also in trust.

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.