Ireland's DPC Fines Google EUR 403 Million Over Location Data Processing
Independently fact-checked against primary sources (last audited September 21, 2026). · 2 primary sources cited on this page. How we verify our legal content

Ireland's DPC Fines Google Ireland EUR 403 Million Over Location Data Practices
Ireland's Data Protection Commission announced on September 21, 2026 that it fined Google Ireland Limited EUR 403 million for GDPR violations in how it processed users' location data between May 2018 and February 2020.
Information last verified on September 21, 2026.
Jurisdiction scope: This decision was issued by Ireland's Data Protection Commission under the EU General Data Protection Regulation and applies to Google Ireland Limited's processing of personal data across the European Economic Area. It does not address Google's practices outside the EEA or any separate proceedings in other jurisdictions.
What Happened
The DPC announced on September 21, 2026 that it had adopted a final decision imposing administrative fines totaling EUR 403 million on Google Ireland Limited. The decision followed an own-volition inquiry the DPC opened in February 2020, in its capacity as Lead Supervisory Authority for Google under the GDPR's cross-border enforcement rules. The inquiry began after the DPC received complaints from several European consumer rights organizations, including BEUC, the European Consumer Organisation.
The inquiry examined three Google features that process location data: Web & App Activity, Location History, and Location Accuracy. The DPC's scope covered the period from May 25, 2018, the date the GDPR took effect, through February 4, 2020.
According to the DPC, Web & App Activity is a Google Account setting, available only to Google Account holders, that when enabled processes information related to a user's activity on Google services, including sites and apps, and can include browsing history, search history and location data. Location History is an opt-in service that tracks a user's location while they are in possession of a compatible mobile device, inferring place visits, activities and the paths between place visits, and feeding a "Timeline" feature that displays a private map through Google Maps, which is saved even when the user is not actively using a Google service. Location Accuracy is an Android operating system feature that lets a device determine its location more precisely than GPS alone would allow, and it is available to Android users regardless of whether they hold a Google Account.
The decision was made by the Commissioners for Data Protection, Dr Des Hogan, Mr Dale Sunderland and Ms Niamh Sweeney. The DPC found four categories of infringement. First, the lawfulness and fairness of Google's processing of location data in Web & App Activity and Location History. Second, a failure to meet accountability obligations, because Google could not demonstrate compliance with the lawfulness, fairness and transparency principle in connection with Location Accuracy. Third, transparency failures across all three features. Fourth, retention of location data in Web & App Activity and Location History for longer than the DPC found appropriate.
Google Ireland Limited has been ordered to bring its processing into compliance within six months of the decision.
Deputy Commissioner Graham Doyle said: "Location data is a type of personal data which is processed by way of location tracking, and includes data collected or processed by Google, which by itself or in conjunction with other information an individual's location can be inferred. Location data can bring both benefits and harms to individuals. It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private." He added: "The GDPR provides a high level of protection of personal data throughout the EEA, and requires that the processing of personal data must be carried out in a lawful, fair and transparent manner. As a result of Google's failures in this regard, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data. The retention of users' location data for longer than necessary aggravated this loss of control."
The DPC said it "is grateful for the cooperation and assistance of its peer supervisory authorities in this case" and confirmed that it "will issue the full decision in due course." As of this writing, the DPC has released only its announcement, not the full decision text. The detailed legal reasoning and the breakdown of how the EUR 403 million figure was calculated across the four infringement categories are not yet public.
What the Law Actually Says
The GDPR sets out its core data processing principles in Article 5, including that personal data must be processed lawfully, fairly and in a transparent manner, and that it must not be kept in a form permitting identification of data subjects for longer than is necessary for the purposes it was collected for, the storage limitation principle. Article 5(2) adds the accountability principle: the controller is responsible for, and must be able to demonstrate, compliance with those principles, not merely comply with them in fact. A regulator finding that a company cannot demonstrate compliance, as the DPC did here with respect to Location Accuracy, is an accountability finding distinct from a finding that the underlying processing itself was unlawful.
Articles 12 through 14 impose transparency obligations, requiring controllers to give data subjects information about how their data is processed in a concise, transparent and easily accessible form, using clear and plain language. The DPC's finding of transparency failures across all three features maps onto this framework, though the announcement does not say which disclosures fell short; that detail should appear in the full decision.
Fines under the GDPR are set under Article 83, which creates a two-tier structure. Lower-tier infringements, largely procedural and organizational failures, can draw fines up to EUR 10 million or 2 percent of global annual turnover, whichever is higher. Higher-tier infringements, including breaches of the core processing principles in Articles 5, 6, 7 and 9 and of data subject rights, can draw fines up to EUR 20 million or 4 percent of global annual turnover, whichever is higher. Article 83 also requires that fines be effective, proportionate and dissuasive, weighed against factors including the nature, gravity and duration of the infringement, the degree of cooperation with the regulator, and any mitigating action taken.
Ireland's Data Protection Commission served as Lead Supervisory Authority in this matter because Google's main EU establishment sits in Ireland. Under the GDPR's one-stop-shop mechanism, set out in Article 56, the supervisory authority where a controller has its main establishment takes the lead on cross-border processing, coordinating with the other EU data protection authorities whose residents are affected before a final decision issues. That is a large part of why the DPC's announcement specifically thanks its "peer supervisory authorities" for their cooperation and assistance in the case. For readers wanting the fuller national picture, how Irish law generally treats data protection and recording and how the DPC handles a complaint someone files with it are covered separately.
Analysis: Why This Matters
The following is analysis from the Recording Law Editorial Team.
This decision is significant less for its dollar figure than for what it targets. Many of the largest GDPR fines to date have concerned the legal basis for behavioral advertising or unlawful data transfers to the United States. Here, the DPC went after the mechanics of location tracking itself, three specific product features and how they were disclosed, consented to, and retained. That is a more granular, feature-level enforcement approach than some earlier headline fines, and it signals regulators are willing to dissect a single product area rather than a company's data practices as a whole.
The four infringement categories the DPC identified, lawfulness and fairness, accountability, transparency, and retention, together read like a checklist of the obligations sitting underneath Article 5. That breadth, spanning both the substance of the processing and the company's ability to document its own compliance, suggests the inquiry looked comprehensively at the full lifecycle of the location data these features touched.
It is worth being precise about what is and is not yet known. The DPC has published an announcement, not the underlying decision. It states the findings and the total fine but does not walk through the legal reasoning or how the EUR 403 million figure was apportioned across the four categories. Readers should treat that reasoning as pending until the DPC releases the full text.
By the Recording Law Editorial Team's own tally of confirmed major GDPR enforcement actions, this fine trails Meta's EUR 1.2 billion fine from the Irish DPC in 2023, Uber's EUR 824,990,000 fine from the Dutch Data Protection Authority in 2026, Amazon's EUR 746 million fine from Luxembourg's CNPD in 2021, TikTok's EUR 530 million fine from the Irish DPC in 2025, and Meta/Instagram's EUR 405 million fine from the Irish DPC in 2022. That places it sixth on the list, not a record, but still among a small handful of GDPR fines that have crossed EUR 400 million. One caveat on that ranking: Amazon's EUR 746 million fine no longer stands as imposed. Luxembourg's Administrative Court annulled it on March 12, 2026, and the CNPD's own statement the following day gives the ground: a later development in Court of Justice case law required an assessment of whether Amazon had acted with a degree of negligence, and the original decision contained none. The CNPD also noted that the court endorsed its approach almost in its entirety, including its findings that Amazon's reliance on legitimate interests was not justified and that its information procedures did not comply with the GDPR. That fine is ranked here by the amount originally imposed, not as a currently enforceable penalty. Our tracker of major GDPR fines and penalties has more on how these enforcement actions compare over time, and our page on Ireland's broader data privacy framework covers the DPC's role in EU-wide enforcement in more depth.
How This Affects You
This decision does not create a new claims process, and it does not require Google to pay individual users. It is a regulatory enforcement action, not a class settlement. That said, there are a few general points worth understanding if you use Google services and are located in the EEA.
Location-related settings, including Web & App Activity, Location History and Location Accuracy, are generally accessible and adjustable in a Google Account's privacy settings or in an Android device's location settings. Reviewing which are enabled, and understanding what each one does based on the DPC's own descriptions above, is something any user can do regardless of this decision. Under the GDPR generally, EEA residents have rights to access, correct, and in some circumstances delete personal data companies hold about them, and to lodge a complaint with their national data protection authority, or with the DPC directly if the matter concerns an Irish-regulated company.
Google has been given six months from the decision to bring its processing into compliance, so any product changes would be expected on that general timeline, though the DPC's announcement does not specify what changes it is requiring beyond the finding itself.
This article provides general legal information about a regulatory decision and is not legal advice. It does not address any individual's specific circumstances. Information verified against Ireland's Data Protection Commission's published announcement as of September 21, 2026.
Last updated: 2026-09-21. This is a developing story; details verified as of 2026-09-21.
Frequently Asked Questions
How much was Google Ireland Limited fined by Ireland's Data Protection Commission?
The DPC announced a total of EUR 403 million in administrative fines against Google Ireland Limited on September 21, 2026, following an inquiry into its processing of location data.
What Google features did the DPC investigate?
The inquiry covered three features: Web & App Activity, Location History, and Location Accuracy, examining how each processed users' location data between May 25, 2018 and February 4, 2020.
What violations did the DPC find?
The DPC found four categories of infringement: unlawful and unfair processing of location data in Web & App Activity and Location History, a failure to demonstrate accountability for Location Accuracy, transparency failures across all three features, and excessive retention of location data in Web & App Activity and Location History.
Why did Ireland's DPC handle this case rather than another EU country's regulator?
Google's main EU establishment is in Ireland, so under the GDPR's one-stop-shop mechanism the DPC acts as Lead Supervisory Authority for Google's cross-border processing, coordinating with other EU data protection authorities before issuing a final decision.
Is this the largest GDPR fine ever issued?
No. By Recording Law's own tally of major GDPR fines ranked by the amount originally imposed, EUR 403 million ranks sixth, behind Meta's EUR 1.2 billion fine (Irish DPC, 2023), Uber's EUR 824,990,000 fine (Dutch AP, 2026), Amazon's EUR 746 million fine (Luxembourg's CNPD, 2021), TikTok's EUR 530 million fine (Irish DPC, 2025), and Meta/Instagram's EUR 405 million fine (Irish DPC, 2022). One caveat: Amazon's fine no longer stands as imposed, because Luxembourg's Administrative Court annulled it on March 12, 2026, though the court left the CNPD's underlying findings largely intact.
Has the DPC published the full decision?
Not yet as of September 21, 2026. The DPC has published only its announcement summarizing the findings and the fine amount; it has stated it will issue the full decision in due course.
What is Google required to do now?
The DPC ordered Google Ireland Limited to bring its processing of location data in the affected features into compliance with the GDPR within six months of the decision.
Can I file a complaint with the DPC if I think my location data was mishandled?
Yes, generally. EEA residents can lodge a complaint with their national data protection authority, or with the DPC if the matter concerns an Irish-regulated company like Google. The DPC's general complaint process is a separate matter from this enforcement decision.
Updates
Independently fact-checked against the cited primary sources
Sources and References
- Data Protection Commission fines Google EUR403 million following Inquiry into Google's processing of location data, DPC announcement, September 21, 2026(dataprotection.ie).gov
- Article 5 GDPR, Principles relating to processing of personal data(gdpr-info.eu)
- Article 12 GDPR, Transparent information, communication and modalities for the exercise of the rights of the data subject(gdpr-info.eu)
- Article 56 GDPR, Competence of the lead supervisory authority(gdpr-info.eu)
- Article 83 GDPR, General conditions for imposing administrative fines(gdpr-info.eu)
- CNPD statement on the Administrative Court judgment concerning Amazon (13 March 2026)(cnpd.public.lu).gov