SecurityBrief UK - Technology news for CISOs & cybersecurity decision-makers
United Kingdom
Ireland fines Google €403 million over location data

Ireland fines Google €403 million over location data

Mon, 21st Sep 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

Ireland's Data Protection Commission has fined Google €403 million after an inquiry into its processing of location data. It also ordered the company to bring its processing into compliance within six months.

The decision followed an investigation opened by the Irish regulator in its role as Google's lead supervisory authority in Europe. The inquiry began after complaints from several European consumer rights groups, including BEUC, about how the company handled location data linked to certain services and products.

The regulator examined three features used between the start of the GDPR regime and early February 2020: Web & App Activity, Location History and Location Accuracy. It found infringements relating to the lawfulness and fairness of processing in Web & App Activity and Location History; accountability failures linked to Location Accuracy; transparency failures across all three features; and excessive retention of location data in Web & App Activity and Location History.

Because Google's European base is in Ireland, major privacy cases involving the company are typically led by the Irish authority under the GDPR's one-stop-shop system. That makes the Dublin-based regulator the main enforcement authority for many large technology groups operating across the European Economic Area.

Scope of case

Web & App Activity is a Google account setting available to account holders. When enabled, it allows the company to process information connected to activity across Google services, sites and apps, including browsing history, search history and location data.

Location History is a separate service that tracks a user's location while they have a compatible mobile device and requires users to opt in. The regulator said the feature can infer place visits, activities and travel paths, and uses a Timeline function in Google Maps to display a private map of where a user has travelled.

The third feature, Location Accuracy, is part of Android and is designed to determine a device's location more precisely than GPS alone. Unlike the other two features, it is available to Android users whether or not they have a Google account.

The inquiry focused on how Google processed location data through these features rather than on a single product line. The regulator concluded that users may not have been given enough clarity about how their location data was collected, used and retained.

Deputy Commissioner Graham Doyle set out the regulator's concerns in a statement accompanying the decision.

"Location data is a type of personal data which is processed by way of location tracking, and includes data collected or processed by Google, which by itself or in conjunction with other information an individual's location can be inferred. Location data can bring both benefits and harms to individuals. It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private. The GDPR provides a high level of protection of personal data throughout the EEA, and requires that the processing of personal data must be carried out in a lawful, fair and transparent manner. As a result of Google's failures in this regard, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data. The retention of users' location data for longer than necessary aggravated this loss of control," said Graham Doyle, Deputy Commissioner, Data Protection Commission.

Regulatory pressure

The ruling adds to a series of large European privacy penalties imposed on major technology companies as regulators test how far the GDPR can reshape data practices. Location information has drawn particular scrutiny because, when combined with other data points, it can reveal patterns of movement, habits and sensitive personal details.

For Google, the case centres on settings and services that form part of widely used consumer products, including Android and Google Maps. The findings show regulators are prepared to look beyond headline privacy policies and examine whether separate product settings, user controls and data retention practices meet legal standards for fairness, transparency and accountability.

The Data Protection Commission said the decision was made by Commissioners for Data Protection Dr Des Hogan, Dale Sunderland and Niamh Sweeney. It also said it received cooperation and assistance from peer supervisory authorities in the case.

The authority has yet to publish the full text of the decision. For now, the headline outcome is one of the larger financial sanctions issued by the Irish regulator, along with a formal order requiring changes to how Google handles location data in the areas covered by the inquiry.