Google's €403m location fine covers 620 days that ended in 2020, and nobody can read the decision yet
Ireland's DPC has fined Google €403 million over Location History, Web & App Activity and Location Accuracy between May 2018 and February 2020. The decision is unpublished, names no articles and is likely to be appealed, but its accountability finding applies to anyone handling location data.
By Parminder Kumar Sharma · · 17 min read

620 days of conduct, 2,421 days of process
The conduct Ireland's Data Protection Commission (DPC) fined Google for today lasted 620 days. It runs from 25 May 2018, the day the GDPR became applicable, to 4 February 2020. That end date is not arbitrary: it is the day the DPC announced its inquiry. The decision published on 21 September 2026 arrives 2,421 days after the inquiry opened, and 2,855 days after seven European consumer groups announced their complaints on 27 November 2018.
The DPC has imposed administrative fines totalling €403 million on Google Ireland Limited and ordered it to bring its processing into compliance within six months. The decision covers three features: Web & App Activity, Location History and Location Accuracy.
Here is what those facts do not establish. They do not show that Google's location handling today is unlawful: the finding is about a window that closed six and a half years ago, and Google says the policies involved "have since been updated". They do not tell us which GDPR articles were breached, how the €403 million splits across the infringements, how many people were affected, or whether UK users were in scope, because the DPC has not published the decision. Its release says the full text will follow "in due course". And they do not tell us the fine will be paid: Irish law gives Google 28 days from formal notice to appeal to the High Court, and Irish reporting says an appeal is expected.
What the DPC actually found
The release lists four findings. It uses the language of GDPR principles but cites no article numbers. The third column below is this briefing's mapping from that language to the GDPR text, and it is inference until the decision is published.
The four findings in the DPC release of 21 September 2026. Article mapping is this briefing's inference from the wording of Articles 5 and 6 GDPR.
| Finding in the release | Features | Likely provision (inferred) | Not stated |
|---|---|---|---|
| Lawfulness and fairness of processing location data | Web & App Activity, Location History | Art 5(1)(a); Art 6 legal basis | Which legal basis Google relied on, and why it failed |
| Accountability: could not demonstrate lawful, fair and transparent processing | Location Accuracy | Art 5(2) with Art 5(1)(a) | Whether the processing itself was unlawful |
| Transparency obligations | All three | Art 5(1)(a); likely Arts 12 to 14 | Which notices or screens were deficient |
| Retention of location data | Web & App Activity, Location History | Art 5(1)(e), storage limitation | How long data was kept, and what period would have been lawful |
The Location Accuracy finding is worth reading twice. The DPC did not say Google processed that data unlawfully. It said Google could not demonstrate that it processed it lawfully, fairly and transparently. Article 5(2) makes the controller "responsible for, and be able to demonstrate compliance" with the principles. A failure of evidence is a finable failure on its own. For a compliance team this is the most transferable part of the decision: the regulator did not need to prove harm from a feature if the company could not prove its own compliance.
The DPC's background notes add one detail that matters for scope. Location Accuracy is an Android feature "available to Android users regardless of whether they are Google Account holders". The accountability finding therefore reaches people who never created a Google account.
Stated and not stated
What the DPC release of 21 September 2026 states, and what it leaves open. Appeal reporting from RTÉ and The Irish Times.
| Question | Stated | Not stated |
|---|---|---|
| Who decided | Commissioners Des Hogan, Dale Sunderland and Niamh Sweeney | Whether other authorities objected |
| Addressee | Google Ireland Limited | How pre-January 2019 conduct is attributed to it |
| Period | 25 May 2018 to 4 February 2020 | Whether any finding runs past that date |
| Penalty | Fines totalling €403 million | Split by infringement or by feature |
| Corrective order | Bring processing into compliance within six months | What compliance requires, and when the clock starts |
| Decision text | To be issued in due course | A date |
| Legal basis cited | GDPR principles by name | Article numbers |
| Affected users | Google account holders; Android users for Location Accuracy | Numbers, countries, whether UK users are in scope |
| Appeal | Nothing in the release | Google's intention (press reports say an appeal is expected) |
Two process details are on the record. The 2020 announcement says the inquiry was opened under section 110 of Ireland's Data Protection Act 2018 and "in accordance with the co-operation mechanism outlined under Article 60". The 2026 release thanks peer supervisory authorities for their cooperation. Neither mentions the Article 65 dispute-resolution procedure, and this briefing found no EDPB binding decision in this case. The inference is that other authorities did not force changes to the DPC's draft through the EDPB, as has happened in some earlier DPC cases, but the release does not say so directly.
The 242-day question
The GDPR's one-stop shop gives a single lead authority to a company with a main establishment in the EU. The DPC is Google's lead authority because Google Ireland Limited is that main establishment. But it was not always so.
In January 2019 France's CNIL fined Google LLC €50 million over consent and transparency at Android account creation, and asserted jurisdiction because Google had no EU main establishment for that processing. France's highest administrative court upheld that in June 2020. Its decision records that Google Ireland "was not assigned new responsibilities with regard to processing carried out by Google in Europe until 22 January 2019", and that before then it had no decision-making power over the processing in dispute.
The DPC's window starts on 25 May 2018. By this briefing's count, 242 of its 620 days fall before 22 January 2019, and 378 after. The release attributes the whole window to Google Ireland without explaining how the earlier portion is handled. There may be a good answer: the Conseil d'Etat was ruling on Android account creation, not on Location History, and the DPC may have treated the processing differently. But the question is visible from the public record and the release does not answer it. This is inference, not a finding, and the full decision should be read for it.
Where €403m sits in the 2023 calculation method
This site's briefing earlier today on the EDPB's new fining guidelines explained that the 2026 draft changes whether a regulator fines, not how much, and that the amount still comes from Guidelines 04/2022. The Google decision is a first chance to hold a real number against that method. The DPC's arithmetic is not public, so what follows is an illustration using public inputs, not a reconstruction.
Article 83(5) caps fines for breaches of the basic principles, which include Articles 5 and 6, at €20 million or 4% of total worldwide annual turnover of the preceding financial year, whichever is higher. The EDPB says the relevant turnover is that of the undertaking, using the consolidated accounts of the parent, and that "preceding" is measured from the date of the fining decision. On that basis the relevant figure would be Alphabet's 2025 revenue, which its results release gives as $402,836 million.
The arithmetic behind the diagram. All steps by this briefing.
| Step | Input | Result |
|---|---|---|
| Turnover in euros | $402,836m divided by 1.149 (ECB, 21 Sep 2026) | About €350.6bn |
| Article 83(5) maximum | 4% of €350.6bn | About €14.0bn |
| Fine as share of maximum | €403m divided by €14.0bn | 2.9% |
| Fine as share of revenue | €403m divided by €350.6bn | 0.11% |
| Low-seriousness band ceiling | 10% of €14.0bn | About €1.40bn |
At 2.9% of the illustrative maximum, €403 million sits inside the range 04/2022 gives for a low-seriousness starting point (0 to 10% of the maximum), not the high band (20 to 100%). That is the headline this number invites, and it should be resisted for three reasons.
First, a starting point is not a final amount. The 04/2022 method adjusts for aggravating and mitigating factors after the starting point, and the DPC may have reached €403 million by a route that does not look like this at all. Second, Article 83(3) says that where the same or linked processing operations breach several provisions, the total "shall not exceed the amount specified for the gravest infringement". Four findings across three features might be one conduct or several, and we cannot tell which. Third, the turnover figure is an assumption. The DPC has not said which entity's turnover it used, and a different figure changes every line of the table.
What the arithmetic does establish is scale. Even a fine that is the fourth largest in DPC history, behind Meta's €1.2 billion, TikTok's €530 million and Instagram's €405 million according to The Irish Times, is a small fraction of what the GDPR permits for a company of this size. The question a board should take from that is not whether €403 million hurts Google. It is what the same method would produce against its own turnover, and that is where the sister briefing's worked example is the better guide.
Google's defence and the friendly names
Google's statement to BleepingComputer says the case "centers around historical policies that have since been updated" and that "from 2019 onwards" it has evolved its practices. The record supports part of that. On 1 May 2019 Google announced auto-delete controls for Location History and Web & App Activity, letting users choose 3 or 18 months. In December 2023 it said Timeline would move to the device, with auto-delete defaulting to three months for new users, down from 18.
The timing cuts both ways. The May 2019 control arrived inside the DPC's window: by this briefing's count 341 days of the window came before it and 279 after. The DPC still found a retention infringement across the window. An option the user must find and set is not the same as a retention period the controller has fixed, and the release describes retention "longer than necessary" as aggravating the loss of control.
Several comfortable labels in this story are not controls.
"Opt-in". The DPC says users must opt in to Location History. It still found the processing unlawful and unfair. An opt-in screen is a mechanism for collecting consent; it is not evidence that the consent is valid, or that the user knew what they were agreeing to. BEUC's 2018 complaint argued that consent obtained this way was "not freely given".
"Historical". The conduct is historical. The legal reasoning is not. Whatever the decision says about lawful basis, transparency and retention will apply to any controller doing something similar now.
"Accuracy". Location Accuracy sounds like a technical service, not a data collection. The DPC treated it as processing of personal data that Google had to be able to justify, including for Android users with no account.
"Auto-delete". A deletion setting is only a retention control if it applies by default and the controller can show what is kept, where and for how long.
Same settings, other enforcers
Google's location settings have been through enforcement elsewhere, and the primary records are clear enough to compare. They are different laws with different tests: the US and Australian cases are consumer-protection actions about misleading users, not data protection decisions about lawful basis, so the amounts are not comparable as measures of seriousness.
Location-data enforcement against Google on the primary record. Amounts in the currency stated by each authority.
| Enforcer and date | Outcome | What it covered | What it does not establish |
|---|---|---|---|
| Federal Court of Australia (ACCC case), 12 Aug 2022 | A$60m penalty | Representations that Location History was the only setting controlling location collection, Jan 2017 to Dec 2018; about 1.3m users may have seen the screens | Anything about GDPR lawful basis |
| Arizona Attorney General, 4 Oct 2022 | $85m settlement | Alleged collection through Web & App Activity after Location History was turned off | A court finding of liability |
| 40 US state attorneys general, 14 Nov 2022 | $391.5m settlement plus disclosure and control changes | Alleged misleading of users about location tracking since at least 2014 | A court finding of liability |
| Texas Attorney General, settled 9 May 2025, finalised 31 Oct 2025 | $1.375bn | Geolocation, incognito browsing and biometric claims combined | How much relates to location |
| Irish DPC, 21 Sep 2026 | €403m fines and a six-month compliance order | Lawfulness, fairness, transparency, retention and accountability, May 2018 to Feb 2020 | Per-infringement split, final outcome after appeal |
Two patterns stand out. The same two settings, Location History and Web & App Activity, sit at the centre of every case. The New Jersey release for the 40-state settlement says the investigation followed a 2018 Associated Press story that Google "records your movements even when you explicitly tell it not to". And the European decision comes last: Australia's penalty and the 40-state settlement both landed about four years before today's decision on complaints filed in Europe in 2018.
The Texas figure needs care. The Attorney General's May 2025 and October 2025 releases describe the $1.375 billion as settling geolocation, incognito and biometric claims together. Anyone who puts it alongside the DPC's fine as a location-data penalty is comparing different things.
The appeal and the six-month clock
Section 142 of Ireland's Data Protection Act 2018 lets a company appeal a DPC fine within 28 days of formal notice of the decision. For any fine over €75,000 the appeal goes to the High Court, which may confirm the decision, replace it "including a decision to impose a different fine or no fine", or annul it. If there is no appeal, section 143 requires the DPC to apply to the Circuit Court for confirmation. The notice date is not public, so the appeal deadline cannot be calculated.
RTÉ reports that "it is understood" Google will appeal on legal issues that need clarification beyond this case. The Irish Times says Google "may appeal elements of the decision". Google's published statement does not mention an appeal. Treat the fine as a first-instance decision.
The six-month order has its own uncertainty. The release does not say when the period starts. Counted from today it would end on 21 March 2027, but that date is this briefing's inference. Whether an appeal would pause the order is also open: reporting by PPC Land notes the High Court granted TikTok a conditional stay of a DPC order in November 2025. This briefing has not read that judgment.
The UK angle
Whose users. Google's current privacy policy, effective 2 April 2026, names Google Ireland Limited as controller for users in the EEA and Switzerland, and Google LLC for users in the UK. The DPC's order is addressed to Google Ireland, so any change it forces applies to EEA and Swiss users by its own terms. Whether Google extends the changes to UK users is its choice. This briefing found no primary record of the date on which UK users moved to Google LLC.
Whose window. The UK left the EU at 11pm on 31 January 2020, four days before the DPC's window closed. For almost all of the 620 days the UK was a member state. The release does not say whether UK users during that period are counted, and nothing in it suggests a UK remedy.
What the ICO has said. This briefing found no ICO statement on the DPC decision as of 21 September 2026. The ICO's 2025 online tracking strategy lists location among the things tracking can reveal, alongside sexuality, beliefs and health, and its focus has been cookie compliance on the top 1,000 UK websites rather than location specifically. Its guidance is scattered:
- Its DPIA list names "tracking an individual's geolocation or behaviour" as processing that requires a DPIA when combined with another high-risk criterion. Its worked example is company cars with location tracking that employees also use privately.
- Its children's code says geolocation options should be off by default, with an obvious sign when tracking is active.
- Its PECR guidance applies the strict regulation 14 rules to network-derived location, such as mobile base station data. It says GPS location from devices "does not generally" fall under that rule but is still covered by data protection law, and that a hard-to-find privacy policy cannot show consent.
The PECR and DPIA pages both carry a notice that they are under review following the Data (Use and Access) Act 2025.
The practical point for a UK organisation is that the DPC's reasoning, once published, will be the most detailed regulator analysis yet of consent screens, transparency and retention for location data. It will not bind the ICO, but a UK controller running a similar design is running the same argument.
Method, not accusation
Everyone quoted here has an interest. BEUC coordinated the complaints and, through its director general, called the decision good news while criticising the time taken as "disproportionate". Google has an obvious interest in describing the conduct as historical. The Texas Attorney General's releases compare his settlement favourably with other states. The DPC, whose pace BEUC criticised today, is announcing a large number without publishing the reasoning behind it.
None of that makes any of them wrong. It is a reason to wait for the full decision before treating the four findings as settled law, and to judge Google's "since updated" claim against what the decision says compliance requires, not against Google's summary of its own controls.
What to check, in order
Take this with you
For a UK organisation that collects location data or builds on Google services
- List every route by which location enters your systems: your own apps (GPS and network location), SDKs and analytics tags, mapping and places APIs, ad platforms, fleet and vehicle telematics, and corporate mobile device management.
- For each route, write down the purpose and the lawful basis, one purpose at a time. If one consent screen covers navigation and advertising together, split it.
- Check that people are told about location use at the moment it starts, on the screen where they make the choice, not only in the privacy notice.
- Set a fixed retention period for raw location data and for anything inferred from it, apply it by default, and test that deletion actually happens in backups and downstream stores.
- Make sure you could demonstrate compliance for every location feature, including background or accuracy features users never see. The Location Accuracy finding was about missing evidence, not proven harm.
- Run or refresh a DPIA wherever you track employees, customers or children by location. The ICO lists geolocation tracking as a DPIA trigger when combined with other risk factors.
- For services likely to be used by children, confirm geolocation is off by default and that visible-to-others settings revert to off after each session.
- If you serve EU users, treat the DPC decision as live guidance: diary a check for the published text and compare your consent, transparency and retention design against it.
- Record who in your organisation owns location data decisions, so that a regulator's question can be answered by one person with the evidence to hand.
The question that exposes the gap
Google is being told in 2026 that its 2018 location settings were unlawful, and Google answers that the settings have changed. Both statements can be true. The one that matters to everyone else is the Location Accuracy finding, because it did not depend on proving harm. So the question for any organisation that touches location data is this: for every place your products learn where a person is, could you produce today the document that shows why you collect it, what you told them, and when you delete it?
Key facts
Sources
- PrimaryDecision announcement of 21 September 2026: findings, features, period, €403m fines, six-month order, full decision to followData Protection Commission (Ireland)accessed 2026-09-21
- PrimaryInquiry launch of 4 February 2020 under section 110 of the Data Protection Act 2018 and Article 60 GDPRData Protection Commission (Ireland)accessed 2026-09-21
- PrimaryPress release of 27 November 2018: seven consumer groups announce GDPR complaints about location trackingBEUCaccessed 2026-09-21
- PrimaryDecision 430810 of 19 June 2020 upholding the CNIL's €50m fine; Google Ireland not assigned new responsibilities until 22 January 2019Conseil d'Etat (via CNIL)accessed 2026-09-21
- PrimaryBlog post of 1 May 2019 announcing 3 or 18 month auto-delete for Location History and Web & App ActivityGoogleaccessed 2026-09-21
- PrimaryBlog post of 12 December 2023: Timeline on device, auto-delete default of three months for new usersGoogleaccessed 2026-09-21
- PrimaryUK privacy policy effective 2 April 2026: Google Ireland controller for EEA and Switzerland, Google LLC for UK usersGoogleaccessed 2026-09-21
- Primary40-state $391.5m location tracking settlement, 14 November 2022New Jersey Office of Attorney Generalaccessed 2026-09-21
- Primary$85m settlement of 4 October 2022 over Location History and Web & App ActivityArizona Attorney Generalaccessed 2026-09-21
- PrimarySettlement in principle of 9 May 2025, $1.375bn covering geolocation, incognito and biometric claimsTexas Attorney Generalaccessed 2026-09-21
- PrimarySettlement finalised 31 October 2025Texas Attorney Generalaccessed 2026-09-21
- PrimaryFederal Court penalty of A$60m, 12 August 2022, conduct January 2017 to December 2018 (read via a fetch tool; direct access blocked)ACCCaccessed 2026-09-21
- PrimaryQ4 and fiscal year 2025 results: revenues of $402,836 millionAlphabet Inc. (SEC filing)accessed 2026-09-21
- PrimaryUSD per EUR reference rate of 1.149 on 21 September 2026European Central Bankaccessed 2026-09-21
- PrimaryGuidelines 04/2022 v2.1: starting-point bands, dynamic maximum, turnover of the preceding financial yearEuropean Data Protection Boardaccessed 2026-09-21
- PrimaryGDPR text: Articles 5, 6 and 83(3) and 83(5)EUR-Lexaccessed 2026-09-21
- PrimaryData Protection Act 2018 sections 142 and 143: appeal within 28 days, High Court over €75,000, Circuit Court confirmationIrish Statute Bookaccessed 2026-09-21
- PrimaryEuropean Union (Withdrawal) Act 2018 section 20: exit day 11pm, 31 January 2020legislation.gov.ukaccessed 2026-09-21
- PrimaryPECR regulation 14 guidance on location data, GPS excluded, consent standardInformation Commissioner's Officeaccessed 2026-09-21
- PrimaryChildren's code standard 10: geolocation off by defaultInformation Commissioner's Officeaccessed 2026-09-21
- PrimaryDPIA list: geolocation tracking as a trigger; company car exampleInformation Commissioner's Officeaccessed 2026-09-21
- Primary2025 online tracking strategy: location listed among harms; top 1,000 websites focusInformation Commissioner's Officeaccessed 2026-09-21
- PrimaryCompanion briefing on EDPB Guidelines 04/2026 and the unchanged 04/2022 calculation methodpk-sharma.comaccessed 2026-09-21
- Reported byLead report and Google's statementBleepingComputeraccessed 2026-09-21
- Reported byReport that Google is understood to be appealingRTÉaccessed 2026-09-21
- Reported byRanking as fourth-largest DPC fine, BEUC reaction, possible appealThe Irish Timesaccessed 2026-09-21
- Reported byReport on the TikTok stay precedentPPC Landaccessed 2026-09-21


