Ireland's Data Protection Commission fined Google €403 million for GDPR violations from May 2018 to February 2020. The company's handling of location data through Web & App Activity, Location History, and Location Accuracy failed to meet transparency, lawfulness, and data retention requirements. The inquiry took more than 6.5 years to conclude.
This isn't about a breach or hack. It's about control design failures in features millions use daily, highlighting the risks of delayed GDPR enforcement on enterprise compliance strategies.
What Happened
Google processed location data through three mechanisms without adequate transparency or lawful basis. Web & App Activity collected activity data, including location, when users enabled the account setting. Location History tracked signed-in device movements even when users weren't actively using Google services. Location Accuracy refined device positioning beyond GPS for all Android users, regardless of account status.
The DPC found Google violated GDPR requirements for lawful and fair processing, transparency, and data retention across the first two features. For Location Accuracy, the violations centered on transparency and accountability, specifically Google's inability to demonstrate lawful, fair, and transparent processing.
Users might have been unaware their location influenced ad targeting or interest profiling. They lost control of Personally Identifiable Information, and extended retention periods amplified that loss.
Timeline
November 2018: BEUC member groups filed complaints with national data protection authorities.
February 2020: The DPC opened its formal inquiry. The examination period ended February 4, 2020.
May 2019: During the inquiry period, Google introduced auto-delete controls for Location History and Web & App Activity, offering 3- or 18-month deletion windows.
June 2020: Google made 18-month auto-delete the default for new Web & App Activity accounts and first-time Location History users.
December 2023: Google announced Timeline data would remain on-device, with 3-month auto-delete as the default for new Location History users.
September 2026: The DPC issued its decision and €403 million fine, ordering compliance within six months. The fine becomes payable only after an Irish court confirms it.
Which Controls Failed
Transparency failures: Users couldn't reasonably understand what data Google collected, how it used location information, or how long it retained that data. The GDPR requires you to tell data subjects what you're doing with their information before you do it.
Lawful basis deficiencies: Google couldn't demonstrate it had established a proper legal ground for processing location data. Article 6 of the GDPR requires one of six lawful bases: consent, contract, legal obligation, vital interests, public task, or legitimate interests. You must identify and document your basis before processing begins.
Retention period violations: Google kept location data longer than necessary for its stated purposes. Article 5(1)(e) requires storage limitation: you keep Personally Identifiable Information only as long as needed to accomplish the purpose you collected it for.
Accountability gaps: For Location Accuracy specifically, Google failed to demonstrate compliance. Article 5(2) places the burden on you to prove your processing meets GDPR requirements.
What the Standard Requires
The General Data Protection Regulation establishes clear obligations that apply before you start processing Personally Identifiable Information.
Article 5(1)(a) requires lawfulness, fairness, and transparency. You must process data lawfully, treat data subjects fairly, and communicate clearly about what you're doing. If your privacy notice requires a law degree to parse, you're not transparent.
Article 6 requires a lawful basis. You need one before you collect the first byte of Personally Identifiable Information. Consent must be freely given, specific, informed, and unambiguous. Pre-ticked boxes don't count. If users can't say no without losing unrelated functionality, it's not valid consent.
Article 5(1)(e) limits storage duration. Define retention periods based on purpose, not convenience. If you can't articulate why you need data beyond a specific timeframe, you shouldn't keep it.
Article 5(2) makes you prove it. Document your lawful basis. Record your retention decisions. Map data flows. The accountability principle means you demonstrate compliance on demand.
Article 12 requires clear communication. Your privacy information must be concise, transparent, intelligible, and easily accessible. Write for your actual users, not your legal team.
Lessons and Action Items
Map every location data flow before you process it. Document what you collect, from which features, under what lawful basis, for what purpose, and for how long. If you can't complete this exercise for a feature, don't ship it.
Default to minimal retention. Google introduced auto-delete controls in 2019 and made them default in 2020. Those should have been the launch settings in 2018. Set the shortest defensible retention period as your default.
Test your privacy notices with actual users. If your target audience can't explain what you're doing with their data after reading your notice, rewrite it. The DPC found users could have been unaware of location-based ad targeting. That's a transparency failure you can catch before a regulator does.
Separate consent requests by purpose. Don't bundle location tracking with account functionality. Don't make Location History a prerequisite for using Google Maps. Each processing purpose needs its own lawful basis and clear explanation.
Document your compliance decisions in real time. The accountability principle requires you to demonstrate lawfulness, fairness, and transparency. Write down why you chose your lawful basis, why your retention period is necessary, and how you determined your processing is fair.
Audit legacy features against current standards. Google's statement referenced "historical policies that have since been updated." Your 2018 feature designs may not meet 2026 regulatory expectations. Review existing data processing activities with the same rigor you'd apply to new features.
Accept that late enforcement still counts as enforcement. BEUC's director general noted that late enforcement can be as harmful as no enforcement. The 6.5-year gap between inquiry and decision doesn't erase the violations. Your compliance timeline needs to assume regulators will eventually catch up, even if it takes years.
The €403 million fine represents the fourth-largest penalty the DPC has issued. More importantly, it demonstrates that operational features with privacy implications require the same control rigor you'd apply to security architecture. Transparency is a legal requirement with measurable financial consequences when you get it wrong.





