Ireland's Data Protection Commission has served as the lead supervisory authority for many of the largest United States technology companies since the European Union's General Data Protection Regulation took effect on May 25, 2018, a role it holds because those firms base their European headquarters in Dublin. On September 21, 2026, the authority, known as the DPC, concluded one of its longest running examinations of Google, the search and advertising unit of Alphabet Inc., by issuing an administrative fine of EUR 403 million over the company's handling of user location data.
The decision follows an own-volition inquiry that the DPC opened in February 2020, after several European consumer rights organisations, including the European Consumer Organisation, BEUC, filed complaints about the way Google collected and used location information. The investigation covered three features: Web and App Activity, a setting that records browsing and search history; Location History, a service that maps the places a user has visited with a mobile phone; and Location Accuracy, an Android operating system feature that governs the precision of location signals.
The DPC examined Google's conduct between May 25, 2018, when the GDPR became applicable, and February 4, 2020, a window of 620 days. Within that period the regulator found that Google infringed the GDPR on lawfulness, fairness, transparency, accountability and retention grounds. The penalty is the fourth largest fine the DPC has issued.
Google Ireland Limited, the entity named in the decision, was given six months to bring its location data processing into compliance. The company has said the case concerns historical policies that have since been updated, and it is understood to plan an appeal focused on legal issues that require clarification beyond this case.
Key Facts
The DPC announced the final decision on September 21, 2026, stating that Google infringed the GDPR across three location features between May 25, 2018 and February 4, 2020. The authority imposed administrative fines totalling EUR 403 million, which Reuters reported amounts to about $463 million at an exchange rate of $1 to 0.8712 euros. The decision was made by the Commissioners for Data Protection, Dr Des Hogan, Mr Dale Sunderland and Ms Niamh Sweeney.
According to the DPC's official statement, the regulator found four categories of infringement. Google fell short on the lawfulness and fairness of its processing of location data in Web and App Activity and Location History; it failed to demonstrate compliance with lawfulness, fairness and transparency for Location Accuracy, breaching its accountability obligations; it breached transparency obligations for all three features; and it retained location data in Web and App Activity and Location History for longer than necessary. Alongside the fine, the DPC ordered Google to bring its processing into compliance within six months.
Reuters reported on September 21 that Ireland's Data Protection Commission found Google had infringed the GDPR through the three specific features from 2018 to 2020 and gave the company six months to comply. A Google spokesperson told Reuters that the case centred on historical policies and that the company had launched robust tools and significantly evolved its practices on managing location data since 2019. Google is subject to three separate ongoing statutory inquiries that the DPC said were at an advanced stage.
The Associated Press reported on September 21 that the fine was the fourth biggest European Union privacy penalty issued by the Irish watchdog, which has previously handed out larger fines to TikTok and Meta, including a EUR 1.2 billion fine for Meta. The regulator still has three other ongoing privacy investigations involving Google.
RTE reported on September 21 that the investigation covered location settings on services such as Google's search engine and Google Maps, as well as location accuracy features on Android devices. The broadcaster said Google is understood to plan an appeal focused on legal issues that require clarification beyond this case. Deputy Commissioner Graham Doyle said location data is a type of personal data processed by way of location tracking, and that the retention of users' location data for longer than necessary aggravated the loss of control.
Analysis
What this really means is that Europe's privacy enforcement against the largest technology platforms has entered a phase where the size of the fine matters less than the compliance order attached to it. The EUR 403 million penalty equals roughly 0.1 percent of Alphabet's 2025 revenues, which passed $400 billion for the first time, according to an analysis published by ppc.land on September 21. For a company of that scale the payment is manageable. The six-month deadline to change how location data is processed, however, strikes at the design of products at the centre of Google's advertising business, including Search, Maps and the Android operating system.
The bigger picture here is that the DPC has built a pattern of enforcement that reaches from data retention to transparency, and that pattern is colliding with a political environment in which European Union institutions are considering loosening some data rules for artificial intelligence training. ppc.land reported on September 21 that the penalty arrived the same day that noyb published a Council of the European Union working text proposing to permit personal data processing for AI training on a legitimate-interest basis. The timing sharpens a question regulators, companies and consumer groups have argued over for years: how far can existing privacy rules constrain the data pipelines that feed both advertising and machine learning?
The findings also show how slow the machinery can be. Seven years and ten months separate the complaint from the penalty. On November 27, 2018, consumer organisations in seven countries filed coordinated grievances about the way Google collected location data on Android phones, complaints coordinated by BEUC and built on a Norwegian Consumer Council report titled Every Step You Take: How deceptive design lets Google track users 24/7. The DPC did not open its own inquiry until February 2020, and the final decision came more than six years after that.
Google's own account of its remediation matters to how the case will be remembered. The company said it has introduced updates since the period investigated that allow users to automatically delete personal data on a rolling basis, store timeline data directly on a device, and manage how data, including location, is used for ads. It also stores an estimated general area rather than a precise device location when a user searches on Google. ppc.land reported that remediation since 2019 includes auto-delete on three, eighteen or thirty-six month rolling cycles and the shift of Maps Timeline to on-device storage, with default retention cut from eighteen months to three.
Why It Matters
Location data is not an ordinary category of personal information. A pattern of movements can reveal a person's home, workplace, medical appointments or political activity. Graham Doyle, the DPC's Deputy Commissioner, said that as a result of Google's failures, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data. That language connects the legal findings to a concrete consumer harm: people making decisions about their lives without knowing what inferences were being drawn from where they had been.
The case also tests the credibility of the one-stop-shop model at the heart of the GDPR. Ireland is the lead regulator for Google in the 27-nation European Union because the company's European headquarters is based in Dublin, and the same arrangement applies to many other large technology firms. When a single authority handles complaints that originate in several countries, its speed, resources and willingness to impose structural remedies become the practical limit of privacy protection for hundreds of millions of people. The DPC has now issued more than EUR 4 billion in total fines, but long inquiries and appeals mean the deterrent effect arrives years after the conduct it targets.
Consumer organisations that filed the original complaints will be watching whether the compliance order produces changes that users can see. The 2018 complaints alleged that refusing Location History required repeated actions across multiple Google products and that Web and App Activity was switched on by default. If the six-month compliance deadline leads to clearer choices, the case will have achieved something beyond a headline number. If it leads mainly to further litigation, the gap between the finding and the fix will remain the central criticism of European privacy enforcement.
Next Up
Google is expected to appeal, with the company understood to be focused on legal issues that require clarification beyond this case, according to RTE. The DPC said it will issue the full decision in due course, and that document will give both sides the detailed reasoning they need to argue the appeal. The six-month compliance clock is already running, and the company's three other statutory inquiries remain open at an advanced stage, meaning further decisions involving Google are still to come.
For now, the EUR 403 million penalty stands as the fourth largest the DPC has issued, behind the EUR 1.2 billion fine for Meta in May 2023 and a EUR 530 million fine for TikTok in April 2025. Whether it becomes a turning point for location privacy or another entry in a long ledger of appeals will depend on what the compliance order actually changes, and on how quickly the remaining inquiries are resolved.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.