Ireland’s Data Protection Commission: investigation and headline finding
The Data Protection Commission (DPC) in Ireland concluded that Google violated the EU General Data Protection Regulation (GDPR) in the way it processed users’ location data, and has imposed administrative fines totaling €403 million. The investigation began in February 2020 after the DPC received multiple complaints from consumer rights organizations and examined Google activity during the GDPR application window of May 25, 2018 through February 4, 2020.
Three Google features under scrutiny: what the DPC reviewed
The DPC focused on three distinct features that handle location-related information:
- Web & App Activity — a Google Account setting that allows Google to process activity across services and can include browsing history, search history, and location data;
- Location History — an opt-in service that tracks compatible mobile devices, can infer visited places, activities and routes, and displays the information in a private Google Maps Timeline even when users are not actively using a Google service;
- Location Accuracy — an Android feature that improves device positioning beyond GPS and is available regardless of whether a user has a Google Account.
The DPC found failings across these three features. It determined that Google processed location data through Web & App Activity and Location History without meeting GDPR requirements, and that the company failed to demonstrate compliance with GDPR principles when processing personal data through Location Accuracy. The authority also found transparency obligations were not met for all three features.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleRetention, transparency and the basis for the fine
Alongside transparency failures, the DPC concluded Google retained location data collected through Web & App Activity and Location History longer than necessary — a factor the regulator said aggravated users’ loss of control over their personal data. Deputy Commissioner Graham Doyle explicitly linked the retention and lack of transparency to practical risks, noting users could have been unaware their location was being used to influence them with advertising or to infer interests.
For these findings the DPC imposed a combined administrative penalty of €403 million and ordered Google to bring its user data processing into compliance within six months. The authority has not yet published its full decision but has promised to do so in the future.
Google’s response and product changes it cites
In a statement to BleepingComputer, a Google spokesperson described the case as centering on what the company called “historical policies” that have since been updated. The spokesperson said that "From 2019 onwards, we've significantly evolved our practices and launched robust tools that make managing location data simple," and that Google has implemented a mechanism for easier location data management.
Google highlighted specific controls it says were added: users can define a timeline for automatic deletion of stored data, and Google Maps Timeline information is now stored on the device and automatically removes data older than three months. The company also stated it does not save precise device location in Web & App Activity but records an estimated general area.
What this means for end users, regulators, and technologists
End users: The DPC’s findings and Doyle’s comments emphasize a practical change for people who relied on default settings or limited transparency — users are the group the regulator explicitly framed as having lost control. Google’s cited product changes — in-device Maps Timeline storage, three-month automatic removal, and user-set auto-delete timelines — are the measures the company points to as restoring control.
Regulators and policymakers: The DPC demonstrated enforcement reach by examining activity across a defined GDPR period and issuing a substantial fine plus a six-month compliance deadline. The authority has signaled it will publish the full decision, a document regulators and lawmakers will likely scrutinize to see how obligations on transparency and data retention are interpreted and enforced.
Technologists and product teams: The DPC’s attention to Location Accuracy — an Android feature available irrespective of account status — underscores how device-level services can fall under GDPR scrutiny. Google’s assertion that Web & App Activity stores only an estimated general area rather than precise location is a concrete technical claim; engineers and privacy architects will watch the forthcoming DPC decision to learn how such distinctions are weighed against transparency and data-minimisation obligations.
The DPC’s final decision, when published, will be the clearest source for technical and legal specifics the regulator expects Google to meet. For now, the regulator has set a six-month clock and levied a €403 million fine; whether Google’s post-2019 product changes satisfy the DPC's requirements will be determined in the documents the authority has promised to release and by whether Google meets the enforced compliance deadline.
Source: BleepingComputer — Google fined €403 million over location data privacy violations




