Security3 publishers2 min readPublished
Google gets six months to fix location-data processing after Ireland's 403 million euro fine
Ireland's Data Protection Commission faulted the legal basis, the notice and the retention clock across three Google location features, and the remediation deadline now runs while the full decision stays unpublished.
The Watch · Security desk

What happened
- Ireland's Data Protection Commission fined Google 403 million euros over its processing of user location data and ordered the company to bring that processing into compliance within six months.
- The DPC opened the inquiry on its own initiative in February 2020 after complaints from European consumer-rights organizations including BEUC.
- POLITICO reports the penalty is the fourth largest the Irish regulator has issued and its first major fine against Google.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure The enforcement reached Google through product settings, so any controller running location or activity logging is exposed on consent copy and retention limits feature by feature, with each surface judged on its own.
- constraint Six months constrains engineering more than legal: consent flows, notice text and deletion jobs for three separate features have to change inside two quarters.
- decision Teams setting default log lifetimes now have a regulator's stated position that keeping data longer than necessary aggravates the harm.
- precedent Complaints from consumer organizations triggered this inquiry. No incident did. Every EU supervisory authority has the same standing to start one against a telemetry pipeline.
The findings split along three product features. Google's processing of location data through Web & App Activity and Location History breached the GDPR's lawfulness and fairness requirements, the DPC found [2]. Transparency failures covered those two features and Location Accuracy [3]. Retention was faulted for Web & App Activity and Location History [3].
On Location Accuracy, Google violated its accountability obligations by failing to demonstrate compliance with the principle of lawfulness, fairness and transparency in that processing, the regulator said [4].
"As a result of Google's failures in this regard, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data. The retention of users' location data for longer than necessary aggravated this loss of control," Graham Doyle, the DPC's Deputy Commissioner, said [7].
The inquiry opened in February 2020 [6] and ended with Monday's decision [11][12], about 79 months later [13]. Google's compliance window is six months [1], which puts the deadline around March 21, 2027 [14] and makes it roughly a thirteenth of the time the regulator took [16]. The conduct examined ran from May 25, 2018 to February 4, 2020, about 20 months of processing [5][15].
So the penalty attaches to behaviour that stopped more than six and a half years before the decision [18]. The order to bring the processing into compliance applies to what those features do now [1].
403 million euros is the fourth largest fine the Irish regulator has issued and its first major penalty against Google, according to Politico [9]. Ireland enforces the EU's privacy rules against many of the tech companies that base their European headquarters there [10]. The DPC said the full decision would be published later [8]; the retention periods it examined will be in that document.
What to watch
- The full DPC decision, when published, and the retention periods it treats as longer than necessary.
- Any statement from Google on whether it accepts the six-month order or challenges the fine.
- Whether other EU supervisory authorities open retention inquiries into comparable activity-logging features.