Ireland fines Google €403 million for tracking users' location without a lawful basis

21.09.2026 12 min 30

Ireland's Data Protection Commission has fined Google Ireland €403 million for the way it collected, explained and kept users' location data. The decision, announced on 21 September, closes an inquiry opened in February 2020 and covers three settings: Web & App Activity, Location History and Location Accuracy. Google has six months to bring the processing into line with the GDPR. It calls the case "historical" and, according to RTE, intends to appeal.

In brief

  • The regulator found the location processing in Web & App Activity and Location History unlawful and unfair, the explanations for all three features inadequate, and the retention of location data in the first two longer than necessary. For Location Accuracy, Google could not show it had a lawful, fair and transparent basis at all.
  • The period examined is short: 25 May 2018, the day the GDPR took effect, to 4 February 2020. The road to the decision was long: consumer groups filed the first complaints in November 2018, so the fine comes almost eight years later.
  • €403 million is the fourth largest fine the Irish regulator has issued, behind Meta (€1.2 billion), TikTok (€530 million) and Instagram (€405 million). Three more DPC inquiries into Google remain open, the Irish Examiner reports, all at an advanced stage.
  • The same settings still exist under new names. Below is what to check in your own account, and why a VPN does not switch any of them off.

Three switches, one fine

The three features work differently, and the DPC faulted each on different grounds. Web & App Activity is an account setting that stores what you do in Google services and, if a sub-option is ticked, in third-party apps and sites that use Google services, including your location. Location History, now called Timeline, keeps a map of where your signed-in devices have been, even when no Google app is open. Location Accuracy is an Android setting that improves the phone's fix by scanning Wi-Fi networks and cell towers; it works whether or not you have a Google account.

SettingWhat it doesWhat the DPC found
Web & App ActivitySaves searches, app and site activity and location for the account; on by default at sign-up in 2018Location processing not lawful or fair; explanations inadequate; data kept longer than necessary
Location History (Timeline)Opt-in map of visited places, routes and activities from signed-in devicesLocation processing not lawful or fair; explanations inadequate; data kept longer than necessary
Location AccuracyAndroid-level positioning from Wi-Fi and cell signals on top of GPS; no account neededGoogle could not demonstrate compliance with the lawfulness, fairness and transparency principle; explanations inadequate

Deputy Commissioner Graham Doyle put the harm in one sentence: because of these failures "individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data. The retention of users' location data for longer than necessary aggravated this loss of control." The three commissioners who signed the decision, Des Hogan, Dale Sunderland and Niamh Sweeney, ordered compliance within six months. The full text will be published later, so the split of the €403 million between the four infringements is not yet known.

Eight years from complaint to decision

The case began with a report, not a leak. In November 2018 the Norwegian Consumer Council published "Every Step You Take", a walkthrough of how an Android phone steers a new user into location tracking: the setup flow pushed Location History; Web & App Activity was on by default and hidden behind extra clicks; the fact that location feeds advertising was buried; users who declined were asked again in Maps, Assistant and other apps; and features such as the Assistant or location-sorted photos were bundled with the tracking. Consumer organisations in eight countries, coordinated by BEUC, filed GDPR complaints with their national regulators the same month. Because Google's European headquarters are in Dublin, the file landed with the DPC.

  1. The Norwegian Consumer Council publishes "Every Step You Take"; consumer groups from Norway, the Netherlands, Greece, the Czech Republic, Slovenia, Poland, Sweden and Denmark file complaints.
  2. End of the period the DPC examined. The same month the regulator opens an own-volition inquiry as Google's lead supervisory authority.
  3. Ten consumer groups file a second round of complaints about the account sign-up flow: one click turns every data setting on, the private path takes five steps and nine clicks.
  4. The DPC announces the decision: four infringements, €403 million, six months to comply.
  5. Compliance deadline. Google is expected to appeal on legal points, RTE reports.

BEUC welcomed the result and attacked the timing. Its director general Agustín Reyna said the decision "confirms the illegality of the way the tech giant obtained consent to use peoples' location data", but that "the time needed to come to this conclusion is disproportionate with the seriousness of the infringement" and "late enforcement can be as harmful as no enforcement at all". The conduct the fine punishes ended in February 2020, and Google has spent the years since rebuilding the very settings at issue.

€403mthe fine, ordered by Ireland's DPC on 21 September 2026
4thlargest fine in the DPC's history; three more inquiries into Google are still open
20 monthsthe period examined, 25 May 2018 to 4 February 2020
6 monthsto bring the processing into compliance

Where it sits in the Irish league table

The DPC is the lead regulator for most US platforms in the EU, so its fines double as the European scoreboard. Google's €403 million lands just below the €405 million imposed on Instagram in 2022 over children's accounts, and above the €390 million Meta paid in 2023 for running ads on a contract instead of consent.

Largest fines issued by Ireland's DPCmillion euro
CompanyFine
Meta, data transfers to the US (2023)1,200 m €
TikTok, transfers to China (2025)530 m €
Instagram, children's accounts (2022)405 m €
Google, location data (2026)403 m €
Meta, legal basis for ads (2023)390 m €
TikTok, children's accounts (2023)345 m €
LinkedIn, ad profiling (2024)310 m €

Google: "historical policies"

Google's statement does not contest the findings in public. "This case centres around historical policies that have since been updated," a spokesperson said. "From 2019 onwards, we've significantly evolved our practices and launched robust tools that make managing location data simple." The tools it points to are real: auto-delete for activity data arrived in 2019; in December 2023 Google announced that Timeline would move from its servers to the phone, with an encrypted cloud backup and a default auto-delete of three months instead of 18; today Google's own help pages say the approximate location and IP address attached to Web & App Activity are deleted after 30 days. Since May 2026 Web & App Activity itself is being split into "Search Services History" and "Personalized Recommendations".

Two regulators outside the EU reached similar conclusions earlier and were paid earlier. In November 2022 Google settled with 40 US states for $391.5 million over the same design: users who turned Location History off between 2014 and 2020 were still tracked through Web & App Activity. In August 2022 Australia's Federal Court fined it A$60 million on the ACCC's case that Android screens presented Location History as the only setting that mattered, when Web & App Activity, on by default, also stored location. Ireland's inquiry covers the same months and the same two switches; it took four more years.

What is not yet known: the DPC has published a press release, not the decision, so the legal reasoning, the split of the fine between the four infringements and any objections raised by other EU regulators under the GDPR's cooperation procedure are not public. Google has not said which "legal issues" it will appeal on. The decision covers conduct up to February 2020 and does not rule on the current settings; the six-month order is the only forward-looking part.

Check your own account

Every setting in the decision still exists, some under a new name, and the defaults have improved rather than disappeared. Turning Timeline off does not stop location being saved elsewhere: Google's help page states that if Search Services History or Web & App Activity is on, the account "may still save location data". The order matters, so go through them one by one.

  • Google Account, Data & privacy, History settings: open Web & App Activity (or Search Services History, the name Google has been rolling out since May 2026) and decide whether it is on. If you keep it, set auto-delete to 3 months.
  • In the same setting, untick "Include Chrome history and activity from sites, apps and devices that use Google services". This box is what brings in activity and location from other apps.
  • History settings, Timeline (or Google Maps, your profile picture, Your timeline): off, or on with the 3-month auto-delete and the encrypted backup you chose yourself.
  • On Android: Settings, Location, Location services, Location Accuracy. Off means GPS and sensors only. Wi-Fi scanning and Bluetooth scanning in the same menu also feed positioning when location is off.
  • My Ad Center (myadcenter.google.com): switch off personalised ads. This is where the "inferred interests" from the DPC's decision end up.
  • myactivity.google.com: delete past activity by date range; in Maps, delete the Timeline or single days.

A VPN belongs on a different list. It replaces the IP address that websites, and Google, see, which is the "general area" written into Web & App Activity from the network side. It does nothing to GPS, Wi-Fi or cell positioning, and nothing to an account that is signed in on the phone: with the switches above on, Google's servers receive the same data through a VPN tunnel as without one. On Android the tunnel itself is not sealed either, as Google's refusal to fix an IP leak past the VPN showed this month. Use a VPN for what it does, hiding your network location from sites and networks, and use the account settings for what the DPC fined.

There is a second reason to care about where this data sits. Location History is what police request when they want to know who was near a crime scene; in June the US Supreme Court held in Chatrie that such requests need a warrant. Data stored only on your phone, with a three-month expiry, is data that cannot be pulled from a server.

What exactly was Google fined for?
Four GDPR infringements found by Ireland's Data Protection Commission: unlawful and unfair processing of location data in Web & App Activity and Location History; a failure to demonstrate a lawful, fair and transparent basis for Location Accuracy; inadequate transparency for all three features; and keeping location data from the first two features longer than necessary. The fine totals €403 million.
Does the fine cover what Google does today?
No. The inquiry examined 25 May 2018 to 4 February 2020. Google says its practices changed from 2019 and points to auto-delete, on-device Timeline and ad controls. The order to bring processing into compliance within six months is the only part that applies to the present, and the full decision has not been published.
Will Google pay?
Not soon. RTE reports that Google will appeal on legal issues "that require clarification beyond this case". DPC decisions are appealed to the Irish courts; Meta took its €1.2 billion fine from 2023 to the High Court.
Does a VPN stop Google from knowing where I am?
Only the part that comes from your IP address. Location History and Location Accuracy use GPS, Wi-Fi and cell signals on the phone, and a signed-in account sends that data through the VPN tunnel like any other traffic. The controls that matter are in the Google Account and in Android's Location settings.
Why did it take six years?
Cross-border GDPR cases go through the lead authority (Ireland for Google) and then a consultation with every other EU regulator, each of which can object. The DPC opened the inquiry in February 2020 and thanked "peer supervisory authorities" for their cooperation. BEUC, which coordinated the 2018 complaints, says the delay is "disproportionate with the seriousness of the infringement".

irelandgooglegdprandroidlocation datalocation trackingdata protectionfinesprivacysurveillanceadvertisingdark patternsregulatorspersonal dataconsumer rightsdpcbeucgoogle maps

Read also