Skip to main content
€403m Fine Shows Why Location Data Is Your Riskiest AssetData Protection & Privacy
5 min readFor Legal & Compliance Officers

€403m Fine Shows Why Location Data Is Your Riskiest Asset

The Challenge

Between May 2018 and February 2020, Google processed location data through Web & App Activity, Location History, and Location Accuracy in ways that violated four GDPR requirements. The Irish Data Protection Commission found that users of Google Maps and Android location services couldn't reasonably understand how their location data was used to infer interests and serve targeted ads. Worse, Google retained this data longer than necessary, further compromising users' control over their Personally Identifiable Information.

This wasn't a technical vulnerability or a data breach. It was a design failure: Google's interfaces and documentation didn't meet the transparency required under Articles 5 and 6 of the GDPR. The company also failed its accountability obligation under Article 5(2) by not demonstrating compliance with principles of lawfulness, fairness, and transparency for Location Accuracy processing.

The €403m penalty reflects the sensitivity of location data and Google's vast user base. The real lesson isn't the fine amount, it's that even sophisticated organizations can misjudge what "transparent" and "lawful" mean when regulators scrutinize user interfaces and data flows.

The Environment and Constraints

The investigation began the day GDPR took effect: May 25, 2018. Google, under intense scrutiny as a major tech platform, faced an inquiry by the Irish DPC in February 2020, concluding over two years later.

Google faced a structural tension: location data powers core functions like navigation and local search but is also highly sensitive. The DPC noted that location data "can reveal a significant amount of information about an individual, including inherently private details." Inferring someone's home address, workplace, or political affiliations from location patterns creates privacy risks even without explicitly collecting those attributes.

The regulatory constraint was clear: GDPR Article 5 requires processing to be lawful, fair, and transparent. Article 6 requires a valid legal basis. Article 5(1)(e) limits retention to what's necessary. Google's challenge was showing that users understood and genuinely consented, not just clicked through a setup screen.

The Approach Taken

During the investigation, Google relied on layered disclosures: privacy policies, feature-specific explanations, and settings interfaces. Location data processing was treated as part of broader account activity tracking, with Web & App Activity enabled by default for many users.

This design prioritized product functionality over explicit, granular consent. Google argued its policies and controls were sufficient, users could disable location features, review their data, and delete history through settings.

Google claimed that location data supported legitimate product improvements and security features, not just advertising. Location Accuracy, for instance, improves GPS precision and Wi-Fi positioning.

But the DPC found this approach lacking. Transparency requires more than accurate privacy policies buried in settings. Users must understand, at data collection, what's being collected and why. Google's interfaces didn't clarify that enabling location features meant their movements would be analyzed for ad targeting.

The lawfulness finding suggests the consent Google obtained wasn't sufficiently informed or specific. The retention violation indicates Google kept location data longer than justified for the stated purposes.

Results and Metrics

The €403m fine is among the largest GDPR penalties. For context, Google agreed to pay $391.5m to settle similar allegations in the US in November 2022, showing the issue extended beyond the EU.

Beyond the financial penalty, the DPC imposed a six-month compliance deadline requiring Google to align its practices with GDPR. This meant redesigning user interfaces, consent flows, and data retention policies.

Google's response acknowledged the issue: "This case centers around historical policies that have since been updated. From 2019 onwards, we've significantly evolved our practices and launched robust tools that make managing location data simple."

The timeline matters. The investigation covered May 2018 through February 2020, but Google began updating its approach in 2019, before the inquiry concluded. This suggests the company recognized the compliance gap independently or in response to early regulatory feedback.

The reputational cost is significant. Each major GDPR fine reinforces the narrative that tech platforms prioritize data extraction over user privacy, complicating trust-building efforts with users and enterprise customers.

What They Would Do Differently

Google's post-2019 changes suggest several lessons learned. The company now provides more prominent location controls during initial device setup and in-app. It offers auto-delete options for location history and clearer explanations of how location data connects to advertising.

If Google were designing these features today with 2018 knowledge, the critical changes would be:

Unbundle consent. Don't treat location tracking for navigation, ad targeting, and product improvement as a single decision. Each purpose requires separate, specific consent.

Default to minimal collection. Enable location services for core functionality but require explicit opt-in for advertising and analytics uses.

Make retention policies visible. Show users how long their location history will be kept and why, with clear controls to shorten that period.

Test interfaces with real users. Legal teams reviewing privacy policies isn't enough. Ensure actual users understand what they're agreeing to when they enable location features.

Document the legal basis. For each processing activity, identify which Article 6 legal basis applies and maintain evidence that the conditions are met. Google's accountability failure suggests this documentation was incomplete or unconvincing.

Takeaways for Your Team

If you're processing location data, through mobile apps, fleet tracking, workplace access systems, or marketing analytics, this case exposes three critical compliance gaps:

Your privacy policy isn't your consent mechanism. A technically accurate policy doesn't mean users understand what you're doing with their data. The test is whether someone could reasonably predict, from the interface they interact with, that enabling location services will result in behavioral profiling for advertising. If that connection isn't obvious, your transparency is insufficient.

Purpose limitation matters more than you think. Collecting location data for one purpose and using it for another requires separate legal justification. You can't assume that consent for the primary purpose extends to secondary uses, even if they're disclosed somewhere in your documentation.

Retention periods need business justification. Keeping location data indefinitely "in case it's useful later" won't survive regulatory scrutiny. For each category of location data, document why you need it, how long that need persists, and what happens when the retention period expires. Implement automated deletion.

Run this diagnostic: Pull up your mobile app or service on a fresh device. Go through the setup flow as a new user would. At what point would you understand that your location is being used for advertising? If the answer is "never" or "only if I read the full privacy policy," you've got a transparency problem.

Review your data processing records under Article 30. For each location data processing activity, can you point to the specific legal basis (consent, legitimate interest, contract performance) and explain why it applies? Can you show evidence that users understood what they were agreeing to? If not, start there.

The €403m fine isn't just a Google problem. It's a signal that regulators now have the resources and political mandate to scrutinize how location data flows through your systems, and that "industry standard" practices aren't a defense if those standards fall short of GDPR requirements.

You Might Also Like