# What happened
Ireland's Data Protection Commission (DPC) has fined Google €403 million for breaching the General Data Protection Regulation in how it handled users' location data. The regulator said the company failed to meet GDPR requirements on lawfulness, fairness and transparency for certain location-tracking features.
# Why the DPC acted
The DPC's inquiry — opened in 2020 — found three separate Google functions were processing location data unlawfully. The regulator said location data can reveal highly personal information about a person and stressed that the GDPR requires personal data processing to be lawful, fair and transparent. In its findings, the DPC highlighted that users could have been unaware their movements were being tracked to infer interests or to target them with advertising.
Deputy Commissioner Graham Doyle explained that location data includes information that can determine a person's position alone or combined with other information. He said this kind of data can both enhance online services and reveal inherently private details about individuals. The DPC also said retention of location data for longer than necessary aggravated the loss of user control.
# Penalty and next steps
The €403 million fine ranks among the highest penalties the DPC has imposed since GDPR came into force. The regulator ordered Google to bring the relevant processing into compliance within six months. The DPC's action is framed as enforcement of GDPR requirements rather than a novel legal test: it found specific failings against established standards for fairness, lawfulness and transparency.
# What this means for users and companies
For users: the decision signals that regulators will scrutinize how location signals are collected, combined and used, especially when those uses include profiling or ad targeting. Users whose data is processed in ways they did not expect now have a clearer regulatory basis to challenge opaque tracking practices.
For companies: this is a reminder to review how location data is handled across product ecosystems. That includes ensuring a lawful basis for processing, clear user-facing disclosures about how location data is used, and strict retention policies to avoid holding location data longer than necessary.
# Quick timeline
- 2020: DPC opens investigation into Google's handling of location data.
- 2026 (September): DPC announces a €403 million fine and gives Google six months to comply.
# Practical takeaways
- Audit how location signals are collected and whether users are clearly informed of uses like ad targeting or interest inference.
- Reassess retention schedules for location data and delete or anonymise data once it is no longer needed for the stated purpose.
- Check that any profiling or targeted-ad uses have an appropriate lawful basis under GDPR and that affected users can exercise control.
- Will Google appeal the decision? (No appeal status provided in the DPC statement.)
- How will the six-month compliance deadline be enforced? (The DPC ordered compliance but did not specify enforcement mechanics in the published summary.)
# Bottom line
The DPC applied one of its largest GDPR penalties for failures around location data handling, citing lack of transparency and excessive retention. Organisations that collect or process location information should review lawful bases, disclosures and retention to reduce regulatory risk.