Skip to content

Google GDPR fine: Irish DPC's €403M location data decision

Filip LuchianencoUpdated 6 min read

Last updated: 2026-10-02

On September 21, 2026, Ireland's Data Protection Commission (DPC), Google's lead supervisory authority in the EU, announced its final decision fining Google Ireland Limited €403 million over location data processed through three features: Web & App Activity, Location History and Location Accuracy. The Google GDPR fine covers May 25, 2018 to February 4, 2020. The DPC "has ordered Google to bring its processing into compliance within 6 months." The EDPB's summary of the decision lists the provisions as Articles 5, 6, 12 and 13 of the GDPR, the EU's General Data Protection Regulation.

What did the DPC find in the Google GDPR decision?

The DPC's release states that the decision, made by Commissioners Des Hogan, Dale Sunderland and Niamh Sweeney, "finds that Google infringed the GDPR" in four respects:

  • "the lawfulness and fairness of its processing of location data in Web & App Activity and Location History"
  • "its accountability obligations under the GDPR by failing to be able to demonstrate compliance with the lawfulness, fairness and transparency principle regarding its processing of personal data in Location Accuracy"
  • "its transparency obligations in respect of all three features"
  • "its retention of location data in Web & App Activity and Location History"

Deputy Commissioner Graham Doyle described the effect in the same release: "individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data. The retention of users' location data for longer than necessary aggravated this loss of control."

The release gives one total, "administrative fines totalling €403 million", with no split by feature or by article. The release states that "The DPC will issue the full decision in due course"; on October 2, 2026 the most recent entry in the DPC decisions listing was dated June 10, 2026. The release omits the legal basis Google relied on for each feature, the DPC's reasoning on advertising use and the fine calculation; this post will add them once the full decision is published.

Which Google features does the decision cover?

The DPC describes each feature in the background section of its release. Location Accuracy is the only one of the three that is part of Android itself.

Feature DPC description (quoted) Findings, May 25, 2018 to February 4, 2020
Web & App Activity "a Google account setting that is only available to Google Account holders"; the data "can include personal data such as browsing history, search history, and location data" lawfulness and fairness; transparency; retention
Location History "Users must opt-in"; it infers "place visits, activities, and paths between place visits" and "saves the private map of where the user goes with their signed-in devices, even when the user is not using a Google service" lawfulness and fairness; transparency; retention
Location Accuracy "a feature of Android OS that allows an Android device to determine its location with greater accuracy than simply relying on inputs from the GPS unit"; "available to Android users regardless of whether they are Google Account holders" accountability (failure to demonstrate compliance); transparency

Source: DPC release of September 21, 2026.

Google's current Android help page says Location Accuracy "uses information from wireless signals, such as Wi-Fi access points, cellular network towers, and GPS, along with device sensor data, such as accelerometer and gyroscope". That page describes the feature as of October 2, 2026; the decision concerns the feature from 2018 to 2020.

Web & App Activity is also the account setting at issue in the US case covered in the post on the Rodriguez v. Google verdict, where the jury's damages concerned app activity data collected through the Firebase and Google Mobile Ads SDKs from users who had the setting or its supplemental sub-setting off.

How did the Google location data inquiry start?

On November 27, 2018, seven consumer organizations (from Norway, the Netherlands, Greece, the Czech Republic, Slovenia, Poland and Sweden) announced complaints against Google to their national data protection authorities, and Denmark's Forbrugerrådet Tænk reported the practices to the Danish authority. The European Consumer Organisation (BEUC) coordinated them. The complaints are based on the Norwegian Consumer Council's report "Every Step You Take", which BEUC describes as showing "how Google is using deceptive design, misleading information and repeated pushing to manipulate Android users into allowing constant tracking of their movements." Those are the complainants' allegations; the DPC release states its findings in GDPR terms: lawfulness, fairness, accountability, transparency and retention.

The DPC announced its own-volition statutory inquiry on February 4, 2020, under section 110 of the Data Protection Act 2018 and "in accordance with the co-operation mechanism outlined under Article 60 of the GDPR". That announcement date is the end of the period the decision covers.

The EDPB's register of binding decisions, checked on October 2, 2026, lists Article 65 disputes from Irish cases on WhatsApp, Meta and TikTok; none of them concerns Google. The DPC release thanks its "peer supervisory authorities" for "cooperation and assistance". Whether any concerned authority objected under Article 60(4) is unknown until the full decision is published.

BEUC's statement on the decision quotes Director General Agustín Reyna: the decision "confirms the illegality of the way the tech giant obtained consent to use peoples' location data." The word "consent" appears nowhere in the DPC's release, which speaks of lawfulness and fairness; whether the decision turns on consent is open until the full text is published. BEUC also states that it and several members filed a second complaint in 2022; the September 21 decision covers the 2018 to 2020 period only.

Can Google appeal the €403 million fine?

Under section 142 of the Data Protection Act 2018, a controller fined by the DPC "may, within 28 days from the date on which notice of the decision concerned was given to it ... appeal to the court against the decision", and for a fine above €75,000 the court is the High Court. The court may "confirm the decision", replace it "including a decision to impose a different fine or no fine", or "annul the decision". If no appeal is brought, section 143 requires the DPC to apply to the Circuit Court for confirmation. The date notice was given to Google is not public, so the end of the 28-day window cannot be computed from the release.

The DPC's decisions page states that "fines imposed by the DPC do not become payable until they are confirmed in Court" and that, under appeal, "the fine cannot be collected pending that appeal".

A Google spokesperson told the BBC: "This case centres around historical policies that have since been updated. From 2019 onwards, we've significantly evolved our practices and launched robust tools that make managing location data simple." RTÉ reported that "It is understood that Google will appeal the ruling focused on legal issues that require clarification beyond this case"; the Irish Times reported that Google "may appeal elements of the decision". On October 2, 2026, the DPC's pages and the reports cited here gave no filing date for an appeal; Irish High Court records were not searched for this post.

What does an Android app send about location today?

The DPC decision concerns Google's own account settings and an Android system feature between 2018 and 2020. Apps installed on a phone today are separate from those features: each app requests its own location permission, sends what it collects to its own servers, and the SDKs built into it send data to their own hosts. On Android, ACCESS_COARSE_LOCATION gives an estimate "accurate to within about 3 square kilometers" and ACCESS_FINE_LOCATION one "usually within about 50 meters (160 feet)", when the estimate comes from Android's LocationManagerService or the fused location provider. Location in an app request can take the form of coordinates, an accuracy radius, Wi-Fi access point identifiers or cell tower identifiers.

When I scan an Android app, the report lists the SDKs found in the binary, including Google SDKs such as Firebase, Google Mobile Ads and Play services location; the location and Wi-Fi state permissions the app declares, with Wi-Fi method references such as WifiInfo.getBSSID in the code; and the consent flow on first launch. The capture on the test device records each request body, so the report shows which requests contained coordinates, accuracy values, Wi-Fi or cell identifiers, which host received each one (Google hosts included), and whether each was sent before or after the consent prompt. Every static finding cites its file and line; every traffic finding cites its capture. SDK presence in a binary shows the code is there; only a capture shows location data was sent. A capture records what the app sent on one test device on one date; what the recipient does with the data, such as retention or ad use, is outside what a capture shows. What a scan checks and the limits of a scan are on the methodology page.

Two other location cases on this blog: the EFF study on ad SDKs and precise location and the FTC's Kochava order on sensitive location data.

I run these location investigations for lawyers and for researchers working with lawyers, on one app or on a list of apps in bulk: permissions, SDKs and the location fields in captured traffic. Sign up for a CanITrustThat account to run your own research, let us run an investigation for you, or browse the scanned apps.

App privacy law, applied to real apps.

Posts on new laws, fines and studies, and teardowns of the apps those laws apply to.

How we use your address: privacy notice. Prefer a feed reader? Use the RSS feed.