Ireland fines Google €403 million for tracking users' location without a lawful basis
Ireland's Data Protection Commission has fined Google Ireland €403 million for the way it collected, explained and kept users' location data. The decision, announced on 21 September, closes an inquiry opened in February 2020 and covers three settings: Web & App Activity, Location History and Location Accuracy. Google has six months to bring the processing into line with the GDPR. It calls the case "historical" and, according to RTE, intends to appeal.
In brief
- The regulator found the location processing in Web & App Activity and Location History unlawful and unfair, the explanations for all three features inadequate, and the retention of location data in the first two longer than necessary. For Location Accuracy, Google could not show it had a lawful, fair and transparent basis at all.
- The period examined is short: 25 May 2018, the day the GDPR took effect, to 4 February 2020. The road to the decision was long: consumer groups filed the first complaints in November 2018, so the fine comes almost eight years later.
- €403 million is the fourth largest fine the Irish regulator has issued, behind Meta (€1.2 billion), TikTok (€530 million) and Instagram (€405 million). Three more DPC inquiries into Google remain open, the Irish Examiner reports, all at an advanced stage.
- The same settings still exist under new names. Below is what to check in your own account, and why a VPN does not switch any of them off.
Three switches, one fine
The three features work differently, and the DPC faulted each on different grounds. Web & App Activity is an account setting that stores what you do in Google services and, if a sub-option is ticked, in third-party apps and sites that use Google services, including your location. Location History, now called Timeline, keeps a map of where your signed-in devices have been, even when no Google app is open. Location Accuracy is an Android setting that improves the phone's fix by scanning Wi-Fi networks and cell towers; it works whether or not you have a Google account.
| Setting | What it does | What the DPC found |
|---|---|---|
| Web & App Activity | Saves searches, app and site activity and location for the account; on by default at sign-up in 2018 | Location processing not lawful or fair; explanations inadequate; data kept longer than necessary |
| Location History (Timeline) | Opt-in map of visited places, routes and activities from signed-in devices | Location processing not lawful or fair; explanations inadequate; data kept longer than necessary |
| Location Accuracy | Android-level positioning from Wi-Fi and cell signals on top of GPS; no account needed | Google could not demonstrate compliance with the lawfulness, fairness and transparency principle; explanations inadequate |
Deputy Commissioner Graham Doyle put the harm in one sentence: because of these failures "individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data. The retention of users' location data for longer than necessary aggravated this loss of control." The three commissioners who signed the decision, Des Hogan, Dale Sunderland and Niamh Sweeney, ordered compliance within six months. The full text will be published later, so the split of the €403 million between the four infringements is not yet known.
Eight years from complaint to decision
The case began with a report, not a leak. In November 2018 the Norwegian Consumer Council published "Every Step You Take", a walkthrough of how an Android phone steers a new user into location tracking: the setup flow pushed Location History; Web & App Activity was on by default and hidden behind extra clicks; the fact that location feeds advertising was buried; users who declined were asked again in Maps, Assistant and other apps; and features such as the Assistant or location-sorted photos were bundled with the tracking. Consumer organisations in eight countries, coordinated by BEUC, filed GDPR complaints with their national regulators the same month. Because Google's European headquarters are in Dublin, the file landed with the DPC.
- The Norwegian Consumer Council publishes "Every Step You Take"; consumer groups from Norway, the Netherlands, Greece, the Czech Republic, Slovenia, Poland, Sweden and Denmark file complaints.
- End of the period the DPC examined. The same month the regulator opens an own-volition inquiry as Google's lead supervisory authority.
- Ten consumer groups file a second round of complaints about the account sign-up flow: one click turns every data setting on, the private path takes five steps and nine clicks.
- The DPC announces the decision: four infringements, €403 million, six months to comply.
- Compliance deadline. Google is expected to appeal on legal points, RTE reports.
BEUC welcomed the result and attacked the timing. Its director general Agustín Reyna said the decision "confirms the illegality of the way the tech giant obtained consent to use peoples' location data", but that "the time needed to come to this conclusion is disproportionate with the seriousness of the infringement" and "late enforcement can be as harmful as no enforcement at all". The conduct the fine punishes ended in February 2020, and Google has spent the years since rebuilding the very settings at issue.
Where it sits in the Irish league table
The DPC is the lead regulator for most US platforms in the EU, so its fines double as the European scoreboard. Google's €403 million lands just below the €405 million imposed on Instagram in 2022 over children's accounts, and above the €390 million Meta paid in 2023 for running ads on a contract instead of consent.
| Company | Fine |
|---|---|
| Meta, data transfers to the US (2023) | 1,200 m € |
| TikTok, transfers to China (2025) | 530 m € |
| Instagram, children's accounts (2022) | 405 m € |
| Google, location data (2026) | 403 m € |
| Meta, legal basis for ads (2023) | 390 m € |
| TikTok, children's accounts (2023) | 345 m € |
| LinkedIn, ad profiling (2024) | 310 m € |
Google: "historical policies"
Google's statement does not contest the findings in public. "This case centres around historical policies that have since been updated," a spokesperson said. "From 2019 onwards, we've significantly evolved our practices and launched robust tools that make managing location data simple." The tools it points to are real: auto-delete for activity data arrived in 2019; in December 2023 Google announced that Timeline would move from its servers to the phone, with an encrypted cloud backup and a default auto-delete of three months instead of 18; today Google's own help pages say the approximate location and IP address attached to Web & App Activity are deleted after 30 days. Since May 2026 Web & App Activity itself is being split into "Search Services History" and "Personalized Recommendations".
Two regulators outside the EU reached similar conclusions earlier and were paid earlier. In November 2022 Google settled with 40 US states for $391.5 million over the same design: users who turned Location History off between 2014 and 2020 were still tracked through Web & App Activity. In August 2022 Australia's Federal Court fined it A$60 million on the ACCC's case that Android screens presented Location History as the only setting that mattered, when Web & App Activity, on by default, also stored location. Ireland's inquiry covers the same months and the same two switches; it took four more years.
Check your own account
Every setting in the decision still exists, some under a new name, and the defaults have improved rather than disappeared. Turning Timeline off does not stop location being saved elsewhere: Google's help page states that if Search Services History or Web & App Activity is on, the account "may still save location data". The order matters, so go through them one by one.
- Google Account, Data & privacy, History settings: open Web & App Activity (or Search Services History, the name Google has been rolling out since May 2026) and decide whether it is on. If you keep it, set auto-delete to 3 months.
- In the same setting, untick "Include Chrome history and activity from sites, apps and devices that use Google services". This box is what brings in activity and location from other apps.
- History settings, Timeline (or Google Maps, your profile picture, Your timeline): off, or on with the 3-month auto-delete and the encrypted backup you chose yourself.
- On Android: Settings, Location, Location services, Location Accuracy. Off means GPS and sensors only. Wi-Fi scanning and Bluetooth scanning in the same menu also feed positioning when location is off.
- My Ad Center (myadcenter.google.com): switch off personalised ads. This is where the "inferred interests" from the DPC's decision end up.
- myactivity.google.com: delete past activity by date range; in Maps, delete the Timeline or single days.
A VPN belongs on a different list. It replaces the IP address that websites, and Google, see, which is the "general area" written into Web & App Activity from the network side. It does nothing to GPS, Wi-Fi or cell positioning, and nothing to an account that is signed in on the phone: with the switches above on, Google's servers receive the same data through a VPN tunnel as without one. On Android the tunnel itself is not sealed either, as Google's refusal to fix an IP leak past the VPN showed this month. Use a VPN for what it does, hiding your network location from sites and networks, and use the account settings for what the DPC fined.
There is a second reason to care about where this data sits. Location History is what police request when they want to know who was near a crime scene; in June the US Supreme Court held in Chatrie that such requests need a warrant. Data stored only on your phone, with a three-month expiry, is data that cannot be pulled from a server.
What exactly was Google fined for?
Does the fine cover what Google does today?
Will Google pay?
Does a VPN stop Google from knowing where I am?
Why did it take six years?
• Data Protection Commission fines Google €403 million following Inquiry into Google's processing of location data - Data Protection Commission
• Google fined for invasive location tracking after BEUC complaint - BEUC
• Google fined €403m by Irish data watchdog over location data - RTE
• Irish data protection watchdog fines Google €403m over GDPR breaches - The Irish Times
• Google manipulates users into constant tracking - Forbrukerrådet
• European consumer groups take action against Google for pushing users towards its surveillance system - BEUC
• Updates to Location History and new controls coming soon to Maps - Google
• Manage your Timeline - Google Account Help
• Forty Attorneys General Announce Historic Settlement with Google over Location Tracking Practices - New Jersey Office of the Attorney General
• Google LLC to pay $60 million for misleading representations - ACCC
• Google fined €403m by Ireland's Data Protection Commission for GDPR breaches - Irish Examiner
• GDPR Enforcement Tracker, largest fines - CMS