Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Sep 22, 2026 · 7 min read

Google Fined €403M Over Location Data in Ireland

Ireland's Data Protection Commission closed a six year inquiry on September 21, 2026 with the first fine it has ever levied against Google, and the findings are about disclosure and deletion rather than consent.

The inquiry opened in February 2020 and examined twenty months of conduct. It took seventy nine months to decide. That ratio, roughly four months of regulatory process for every month of behavior under review, is the part compliance teams should sit with, because the compliance order attached to the decision runs for six months flat.

Key Takeaways

  • Ireland's Data Protection Commission fined Google Ireland Limited €403 million on September 21, 2026, according to the DPC's own announcement.
  • Three features were in scope: Web & App Activity, Location History and Location Accuracy, over the period May 25, 2018 to February 4, 2020.
  • The DPC found infringements of lawfulness and fairness, accountability, transparency across all three features, and retention of location data for longer than necessary.
  • Google has six months to bring its processing into compliance under a corrective order attached to the fine.
  • The €403 million penalty is the fourth largest the DPC has issued and the first it has ever imposed on Google, eight years into its role as Google's lead supervisory authority.

What Did the DPC Actually Find?

The DPC found four categories of infringement, and only one is about whether Google had a legal basis at all. In the regulator's own wording, Google infringed the GDPR in respect of the lawfulness and fairness of its processing in Web & App Activity and Location History; its accountability obligations, by failing to demonstrate compliance with the lawfulness, fairness and transparency principle in Location Accuracy; its transparency obligations across all three features; and its retention of location data in Web & App Activity and Location History.

The DPC's public statement does not enumerate the specific GDPR article numbers, and the full decision text had not been published at the time of writing. The categories map onto the transparency and storage limitation duties in Article 5, but until the decision is out, the honest description is the regulator's own. Coverage at BleepingComputer and The Record stops at the same point.

Deputy Commissioner Graham Doyle framed the harm as loss of control, not exposure. Individuals, he said, "could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests," and the "retention of users' location data for longer than necessary aggravated this loss of control." Location data, he added, "can also reveal a significant amount of information about an individual, including information that is inherently private."

The inquiry began after complaints from several European consumer rights organisations, including BEUC, in early 2020. Google told BleepingComputer the case "centers around historical policies that have since been updated," pointing to controls shipped from 2019 onward and to Maps Timeline data now stored on the device and auto deleted after three months.

Why Does the Six Month Clock Matter?

The corrective order, not the fine, is the part that changes engineering roadmaps. Google must bring its processing into compliance within six months, which means the DPC will be assessing remediation against findings that include retention periods and the clarity of disclosures, not just whether a consent toggle exists.

Fines get appealed and take years to resolve. Compliance orders run on their own clock the whole time. For a privacy officer reading this as a template, the work behind "bring processing into compliance" is narrow and unglamorous: documented retention schedules per data category with an enforceable deletion job behind them, as the storage limitation principle requires, notices that state the purpose at the point of collection rather than in a policy three clicks away, and accountability artefacts that demonstrate both on demand. The third item is what caught Location Accuracy. Google was not found to have no basis for it; it was found unable to show one.

A smartphone resting face up on a folded paper street map on a wooden desk, a single blue location dot glowing on the screen, lit by soft natural window light

How Does This Compare to Google's Other 2026 Payouts?

This is the second nine figure penalty in 2026 over the same setting, and the comparison is unusually clean because both actions name Web & App Activity by name. In May, a California federal jury ordered Google to pay more than $425 million to 98 million users who switched Web & App Activity off and were tracked anyway. Four months later a European regulator fined the same feature €403 million, about $463 million at the time of the decision.

Two legal systems, one product surface, and the EU number came in larger in dollar terms than the US jury award. The two arrived by opposite routes: a jury found a broken promise to users who had opted out, while the DPC found inadequate disclosure and excessive retention for users who never opted out of anything. Same feature, two independent failure modes.

Stack the year up and the pattern is a tally rather than an incident. Google also agreed to a $135 million settlement over Android phones sending cellular data in the background, paid $1.375 billion to Texas, and separately began using Gmail IP addresses for ad personalization in August. Location inference did not stop being commercially useful because it became legally expensive.

Where €403 Million Ranks Among GDPR Fines

It is the fourth largest fine the DPC has issued, and it lands remarkably close to the one above it. Meta's €1.2 billion transfer penalty from 2023 leads the Irish list, followed by TikTok at €530 million in 2025 and Instagram at €405 million. Google's €403 million sits two million euro below Instagram. Across the EU, the GDPR Enforcement Tracker records Irish decisions accounting for the majority of total fine value, a consequence of the one stop shop mechanism that makes the DPC lead supervisory authority for most large US technology firms headquartered in Dublin.

The surprising number is zero. Despite holding lead authority since GDPR took effect in May 2018, this is the first time the DPC has fined Google at all, a span in which it produced billion euro decisions against Meta and half billion euro decisions against TikTok. Anyone modelling regulatory exposure on the idea that a quiet regulator is a permissive one just got a counterexample with a six month deadline attached.

What This Means for Your Inbox

Strip the location specifics out and the finding applies to email marketing analytics almost word for word. The DPC did not say Google lacked a way to collect the data. It said users were not told clearly enough what the collection was for, and that the data outlived its purpose. Every email platform logging opens, click destinations, device type, IP derived geography and timestamps runs the same shape of processing, usually with the same two weaknesses.

Ask the retention question of your own stack and it gets uncomfortable fast. Most marketing platforms keep engagement event logs indefinitely by default, because storage is cheap and nobody owns the deletion decision. Apply the reasoning in this decision to an open and click log from 2019 and the defence has to be a documented purpose that still needs a six year old read timestamp. That is hard to write.

The transparency half generalizes just as broadly. "Influence them with ads or to infer their interests" describes what engagement data is for, and it rarely appears in that language anywhere a recipient will read it. Location is the higher profile case, with regulators converging on it from every direction, from the FTC's ban on Kochava selling location data to state legislation. But the legal theory the DPC used here was never location specific.

Looking Ahead

Two things to watch. First, publication of the full decision, which should name the article numbers and show how the DPC weighted each finding in arriving at €403 million; the DPC publishes its decisions after the announcement, and the reasoning is where the precedent lives. Second, March 2027, when the six month window closes.

Google's position is that it fixed this years ago, which may well be true of the specific 2018 to 2020 conduct. The corrective order is not aimed at 2019 though. It is aimed at whatever Web & App Activity, Location History and Location Accuracy do today.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.