
Ireland’s Data Protection Commission fined Google €403 million ($463 million) on Monday, September 21, after finding that the company infringed the European Union’s General Data Protection Regulation in its handling of location data. The DPC’s final decision announcement covers three features—Web & App Activity, Location History and Location Accuracy—during the period from May 25, 2018, when the GDPR began to apply, through February 4, 2020.
The regulator found unlawful and unfair processing in Web & App Activity and Location History, transparency failures across all three features, an accountability failure involving Location Accuracy, and excessive retention of location data in Web & App Activity and Location History. It ordered Google to bring the processing into compliance within six months. The DPC said the full decision would be published later, so the precise changes required by that order are not yet public.
Key facts
- Fine: €403 million, or about $463 million at the exchange rate used in contemporaneous reporting.
- Decision date: September 21, 2026.
- Period examined: May 25, 2018, to February 4, 2020.
- Products: Web & App Activity, Location History—now presented to users through Timeline—and Android’s Location Accuracy feature.
- Remedy: bring the processing into GDPR compliance within six months; the DPC has not yet published the detailed decision defining the order’s full scope.
- What remains open: Google had not publicly confirmed an appeal at the reporting cutoff, and three separate DPC statutory inquiries concerning the company were described by the regulator as being at an advanced stage.
What happened
The DPC opened an own-volition inquiry in February 2020 after receiving complaints from European consumer groups, including the European Consumer Organisation, BEUC. Because Google’s European headquarters are in Dublin, Ireland acts as the company’s lead supervisory authority for cross-border GDPR matters in the EU.
The commissioners—Des Hogan, Dale Sunderland and Niamh Sweeney—concluded that Google’s processing through Web & App Activity and Location History failed the GDPR tests of lawfulness and fairness. They also found that Google failed to meet transparency obligations for all three features and could not demonstrate that Location Accuracy complied with the lawfulness, fairness and transparency principle. For the first two services, the decision additionally found that location information was kept longer than necessary.
DPC Deputy Commissioner Graham Doyle connected those legal findings to the practical information gap users faced. He said people could have been unaware that their whereabouts were being used to influence them with advertising or infer their interests, leaving them with less control over personal data. Longer-than-necessary retention, he said, aggravated that loss of control.
Google responded that the case “centers around historical policies that have since been updated.” A spokesperson said: “From 2019 onwards, we’ve significantly evolved our practices and launched robust tools that make managing location data simple.” Reuters reported that the company pointed to rolling auto-delete controls, on-device Timeline storage and advertising controls among the changes made since the period under review.
The three features, in plain language
Web & App Activity is a Google Account setting. When it is enabled, Google processes activity across its services, sites and apps. That record can include browsing history, search history and location information. A person may understand the setting as a history of searches and app use while missing that place data can travel with those events.
Location History is opt-in and records the movement of compatible, signed-in mobile devices. Google can use it to infer visits, activities and routes, then display them on a private map in Google Maps. The user-facing feature is now called Timeline. It can record where signed-in devices go even while the user is not actively using a Google service.

Location Accuracy sits at the Android operating-system level. It combines signals such as GPS, nearby Wi-Fi access points, mobile network towers and device sensors to estimate a device’s position more precisely than GPS alone. Unlike the two account settings, it is available to Android users whether or not they have a Google Account. That wider reach helps explain why the DPC treated Google’s ability to demonstrate lawful, fair and transparent processing as a distinct accountability question.
Why this matters
Location became advertising infrastructure because a place is rarely just a point on a map. Repeated observations can suggest where someone lives and works, which shops they visit, how they travel and what kinds of services may interest them. That makes location useful for navigation and local search, but also commercially valuable for audience selection, measurement and profiling.
The deeper significance of the ruling is therefore not that location data is forbidden. The GDPR permits data processing on specified legal bases. The question is whether a company can clearly explain what happens, establish a lawful basis, treat people fairly and delete data when its purpose no longer justifies retention. A consent screen is not a complete defense if the surrounding product design leaves users unable to understand the processing or exercise meaningful control.
That principle reaches beyond Google. Many digital businesses rely on a sequence in which a permission, an account setting and a product benefit are presented together, while advertising or analytics uses sit elsewhere in the explanation. The DPC decision signals that regulators will examine the full chain—from how a choice is framed to how long resulting data remains available—not merely whether a button was clicked.
This is analysis rather than a finding that every current Google location feature violates the GDPR. The inquiry assessed historical processing ending in February 2020. Google says its practices have changed, and the DPC has not yet said publicly whether every later change satisfies the compliance order.
From the 2018 complaints to a 2026 verdict
The case began outside the regulator. In November 2018, seven consumer organisations in the BEUC network filed complaints with their national data-protection authorities based on research by Norway’s Forbrukerrådet. The complaints challenged Google’s location-tracking practices, particularly how users were guided through choices and how consent was obtained.
The DPC, acting as Google’s lead EU authority, opened its own inquiry in February 2020. The investigated period ended on February 4 of that year. More than six years then passed before the September 2026 decision, a timeline that sharpened the criticism even among groups that welcomed the outcome.
BEUC Director General Agustín Reyna said the ruling holds Google accountable for how consent was obtained, while arguing that consumer rights need to be upheld faster. The criticism matters because delayed enforcement changes the economics of compliance: a practice can affect users for years while regulators coordinate, investigate and litigate. Google’s answer—that the policies are historical—also gains force from the delay, even though later reforms do not erase a finding about earlier conduct.
The fine also fits Ireland’s broader role. Many large U.S. technology companies locate their EU operations in Ireland, making the DPC their lead privacy regulator under the GDPR’s cross-border system. Reuters reported that the watchdog has levied more than €4 billion in total fines since 2018.
Who benefits—and who bears the cost
Consumer groups gain a precedent that treats location settings as a connected processing system rather than isolated toggles. EU regulators gain a large enforcement decision spanning lawfulness, fairness, transparency, accountability and retention. Privacy-first competitors gain a clearer commercial argument: simpler data collection and shorter retention can be product features, not merely legal overhead.
Google bears the direct financial and compliance cost, but the strategic pressure falls on its advertising model. If a service can infer interests from movement, the company must be able to explain and justify that use without relying on fragmented controls or assumptions about what a user understood. Redesigning that chain can reduce the volume, duration or usefulness of data available for profiling.
Users occupy both sides of the ledger. Location data powers directions, traffic estimates, local recommendations and a personal travel history. Stronger limits may reduce some convenience or personalization. The trade becomes defensible only when people can see it clearly. The DPC’s central concern was that users might not have understood the advertising and interest-inference consequences well enough to remain in control.
Critics will read the outcome differently. BEUC’s complaint is that six years is too slow for meaningful consumer protection. Google’s defense is that regulators are judging a historical system after the company introduced new tools. Both points can be true: enforcement can be slow, and past conduct can still require a legal judgment.
The numbers in context
The €403 million penalty ranks fourth among DPC fines. The three larger Irish decisions were Meta’s €1.2 billion data-transfer fine in 2023, TikTok’s €530 million transfer and transparency fine in 2025, and Instagram’s €405 million children’s-data fine in 2022. The two-million-euro gap between the Instagram and Google cases illustrates how close fourth place is to third; the distance to the record Meta decision is much larger.
GDPR’s upper-tier ceiling can reach €20 million or 4% of the undertaking’s preceding worldwide annual turnover, whichever is higher. That is a maximum, not an automatic tariff, and the DPC’s full calculation for Google is not yet public. Alphabet’s 2025 annual report recorded $402.836 billion in revenue. Using the reported $463 million dollar equivalent, this fine equals about 0.115% of that annual revenue. Four percent of the same revenue would be roughly $16.1 billion, more than 34 times the penalty.
Those comparisons do not show what the fine “should” have been. Article 83 requires regulators to assess factors including the nature, gravity and duration of an infringement, intent or negligence, mitigation, prior infringements and cooperation. Until the complete decision is published, readers cannot evaluate how the DPC weighed each factor or allocated the €403 million across the findings.
What happens next
The six-month compliance window points to roughly March 21, 2027, if counted from the September 21 announcement. That date is an approximate editorial calculation, not a separately published DPC deadline, and the formal notice may control the legal timetable. The DPC has not yet specified publicly exactly which processing steps Google must alter.
Google can challenge the decision through Ireland’s courts, but at the reporting cutoff the company had not publicly said whether it would appeal. The route and timing will become clearer after formal notice and publication of the decision. Any appeal could affect payment or enforcement, but it should not be assumed before Google files one.
The DPC also says three separate statutory inquiries involving Google are at an advanced stage. Their subjects and outcomes should not be inferred from this case. What can be said is that the location-data decision does not end the company’s Irish regulatory exposure.
The most important near-term document is the full decision. It should reveal the legal reasoning, the division of fines among infringements and the exact compliance measures. Until then, the headline number is clear, while the operational consequences remain only partly visible.
Sources and reporting notes
- Irish Data Protection Commission, September 21, 2026: official decision announcement, findings, period examined, product descriptions and six-month order
- Reuters: fine, Google response, DPC enforcement total and three ongoing inquiries
- Associated Press, via The Business Standard: findings, Irish lead-regulator role and penalty ranking
- Dow Jones Newswires, via Morningstar: Google and BEUC responses
- The Hacker News: feature explanations, appeal framework and post-2019 product changes
- Digital Watch Observatory: 2018 complaints, Forbrukerrådet research, inquiry timeline and feature detail
- Security Affairs: Android reach, GDPR findings and enforcement context
- Technology.org: ranking of the four largest DPC fines and Irish appeal mechanics
- Alphabet 2025 Form 10-K: $402.836 billion annual revenue
- European Data Protection Board: guidelines on calculating GDPR administrative fines
Reporting cutoff: September 22, 2026. The DPC had not yet published the full decision, Google had not publicly confirmed an appeal, and the exact scope and legal timetable of the six-month compliance order remained uncertain. Percentage and March 2027 comparisons are Signal Post News calculations from cited figures; business-model, winners-and-losers and consent analysis is Signal Post News’s synthesis.