Skip to main content

The Identity at the Core

The Definitive Chronicle of Identity & Access Management

Irish DPC fines Google 403 million EUR over location data processing under GDPR

The Irish DPC fined Google Ireland 403 million EUR and issued a compliance order over location data processing in three features between 2018 and 2020.

By Paulo Barrilli
3 min read0 views0 comments

The Irish Data Protection Commission (DPC) has fined Google Ireland Limited 403,000,000 EUR and issued a compliance order following an inquiry into how the company processed users' location data. The European Data Protection Board published the decision summary, dated 21 September 2026, on its news page.

The decision was made by the Commissioners for Data Protection. It finds that Google infringed the GDPR in respect of the lawfulness and fairness of its processing of location data. The legal references listed are Article 5 (principles relating to processing of personal data), Article 6 (lawfulness of processing), Article 12 (transparent information and modalities for exercising data subject rights) and Article 13 (information to be provided where personal data are collected from the data subject). In plain terms: the regulator's case rests on whether Google had a valid legal basis for the processing, whether the processing was fair, and whether users were told clearly what was happening to their location data.

The inquiry was an own-volition inquiry, meaning the DPC opened it itself rather than acting on a single complaint. It did so in February 2020 in its role as Lead Supervisory Authority for Google, after receiving complaints from several European consumer rights organisations, including BEUC. The scope was narrow and specific: Google's processing of location data in three features between 25 May 2018, the date the GDPR became applicable, and 4 February 2020. Those features are:

  • Web & App Activity
  • Location History
  • Location Accuracy

Anyone who has ever tried to switch off location tracking on an Android device and found it had quietly survived in a different menu will not need the regulator to explain why those three settings were the ones under the microscope.

The published summary available at the time of writing is truncated. It states that Google infringed the GDPR in respect of the lawfulness and fairness of its processing of location data, and the text breaks off part way through the list of findings. The full breakdown of findings, the reasoning behind the fine amount, and the specific terms of the compliance order are not in the material published so far. Readers should treat any secondhand reporting of those details with care until the full decision is available. The EDPB has tagged the case with the keywords GDPR enforcement, technology, accountability and data subjects rights, which gives a fair picture of where the emphasis lies.

A few points are worth pulling out for practitioners. First, the processing under scrutiny took place between 2018 and early 2020. The decision arrived years later. Enforcement in the EU is slow, but it is not forgetful, and the period a regulator examines can be long closed by the time the bill lands. Second, the case is national, handled by the DPC as Lead Supervisory Authority, which is the standard one-stop-shop route for a company whose main EU establishment is in Ireland. Third, the decision combines a fine with a compliance order, so this is not only about money. It is about changing how the processing works.

For identity and access teams, the useful part of this is not the number. Location data is one of the classic attributes that identity systems collect for good reasons (risk-based authentication, impossible travel detection, fraud scoring) and then keep for reasons nobody can quite remember. The DPC's findings on lawfulness, fairness and transparency apply just as much to a CIAM platform's sign-in telemetry as they do to a consumer maps product. The encouraging news is that most teams already have the tooling to fix this. They simply have not pointed it at their own data.

What to check: review every place your authentication and CIAM stack collects, stores or derives location (IP geolocation, device GPS, Wi-Fi and Bluetooth signals) and confirm each one is tied to a documented legal basis under Article 6 and a retention period someone actually enforces. Read the notices and consent screens your users see at sign-up and at the point of collection against Articles 12 and 13, and check they describe location processing accurately rather than aspirationally. Test what happens when a user turns a location setting off: does the data stop flowing everywhere, or only in the one feature they touched? If the answer takes longer than a minute to find, that is the finding, and it is far cheaper to discover it yourself than to have a regulator do it for you.

#eu#policy#ciam#vendor-news#gdpr#privacy
Share:XLinkedInFacebook

Be the first to comment

Members only: sign up if you have something worth saying.

Want to weigh in? Sign in or create a free account.

No comments yet.