Summary
- Ireland’s Data Protection Commission has fined Google €403 million following a six-year investigation into three location-related services.
- The decision covers Web & App Activity, Location History, and Location Accuracy, including findings on lawfulness, transparency, accountability, and retention.
- Google must bring the affected processing into compliance within six months, although the company says its location controls have changed since the period examined.
Ireland’s privacy regulator has fined Google €403 million after concluding that the company breached European data-protection rules in the way it processed location information across several widely used services.
The Data Protection Commission, which acts as Google’s lead supervisory authority in the EU, examined Web & App Activity, Location History, and Location Accuracy over a period running from 25 May 2018, when the General Data Protection Regulation became applicable, to 4 February 2020. Its inquiry began in February 2020 after complaints from European consumer organisations and has ended with both a financial penalty and an order requiring Google to bring the affected processing into compliance within six months.
The regulator found infringements covering the lawfulness and fairness of location-data processing in Web & App Activity and Location History, while it also identified accountability failures around Location Accuracy. Transparency obligations were breached across all three features, according to the decision, and the DPC objected to the retention of location information in Web & App Activity and Location History.
Although the full regulatory decision has not yet been published, the findings put the mechanics of everyday platform data collection back at the centre of European privacy enforcement. Location information is unusually revealing because it can connect digital activity with movements, visits, routines, and inferred interests, while its commercial value extends into advertising, personalisation, mapping, and other services.
Historical systems still create current liabilities
Google has argued that the case concerns historical practices that have since changed, pointing to stronger user controls, automatic deletion options, and changes to the precision and storage of location information. Those product changes do not remove regulatory exposure for earlier processing, however, because GDPR enforcement can arrive years after the systems and interfaces under investigation have been redesigned.
The delay is notable in its own right. The inquiry began more than six years before the final decision, illustrating the gap between the speed at which digital products change and the much slower cycle of cross-border regulatory investigation. By the time an enforcement action is completed, the service involved may have undergone several rounds of redesign, but organisations can still be required to demonstrate that earlier data collection, retention, and user disclosures met the law that applied at the time.
That creates a long compliance memory for organisations handling large volumes of behavioural or location information. Product teams may think primarily in terms of the current consent flow or privacy dashboard, while regulators can reconstruct decisions made years earlier from policy documents, interface designs, retention settings, internal governance records, and technical behaviour. Accountability under GDPR therefore reaches beyond whether a company has subsequently built better controls.
The DPC’s findings also extend across more than one part of Google’s technology stack. Web & App Activity is an account setting capable of processing browsing, search, and location information, while Location History records movements associated with compatible devices and presents them through Timeline. Location Accuracy, meanwhile, is an Android capability intended to improve positioning beyond information obtained from GPS alone and can apply even where the user does not hold a Google account.
Location governance reaches across the stack
That spread helps explain why location governance is more difficult than a single permission screen suggests. Information can originate from operating-system functions, account settings, applications, sensors, and network signals before being combined or reused elsewhere, leaving separate teams responsible for collection, advertising, analytics, retention, and user interfaces while the individual experiences the result as one continuous data relationship.
European privacy law places responsibility on the organisation to make that relationship lawful, fair, transparent, and demonstrable. As companies add machine-learning systems and more automated personalisation to existing datasets, the ability to trace where information came from, why it remains retained, and which purposes are still authorised becomes more demanding.
The enforcement action also arrives while large technology companies are managing overlapping European requirements covering privacy, digital markets, online platforms, cybersecurity, and artificial intelligence. Those regimes regulate different problems, but they increasingly meet inside the same product architecture: identity systems, data stores, recommendation engines, advertising platforms, and software-development processes can each fall under several governance frameworks at once.
Google now has six months to comply with the DPC order, while the regulator has said that its full decision will be published later. That document should provide considerably more detail on how the authority assessed the individual services, the evidence presented by Google, and the reasoning behind the €403 million penalty.
Even before that fuller account arrives, the enforcement action demonstrates how long the regulatory consequences of a product design can persist. Systems may be replaced and interfaces rewritten, but the data-processing decisions behind them remain capable of attracting scrutiny years after the original code has disappeared.












