Why is Google being fined by Europe? On 21 September 2026 Ireland's Data Protection Commission, acting as Google's lead regulator for the whole of the European Economic Area, imposed administrative fines totalling €403 million on Google Ireland Limited for the way three features handled users' location data between May 2018 and February 2020. The decision closes a case that began with coordinated consumer complaints in November 2018, and it arrives in the same month that a US court imposed a six-year antitrust monitor on Google's ad-tech business. For general counsel, privacy teams and advisers to any business that collects location signals, the ruling is a practical lesson in consent design, transparency, retention and the mechanics of cross-border GDPR enforcement.
Why is Google being fined by Europe? The short answer
Google is being fined because the DPC found that it processed location data unlawfully, unfairly and without adequate transparency, and kept some of it for too long. The regulator's final decision, taken by the three Commissioners for Data Protection, Dr Des Hogan, Dale Sunderland and Niamh Sweeney, found infringements of the GDPR in four respects, fined Google €403 million in total and ordered it to bring its processing into compliance within six months.
The inquiry covered three features: Web & App Activity, Location History and Location Accuracy. The period under review ran from 25 May 2018, the date the GDPR began to apply, to 4 February 2020. That end date matters: it is historical conduct, which is central to Google's response, but the corrective order looks forward and applies to Google's processing today.
Deputy Commissioner Graham Doyle explained the harm in plain terms. In the DPC's statement he said that, because of Google's failures, "individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data", and that holding location data for longer than necessary "aggravated this loss of control".
In other currencies the penalty is worth about $462 million, according to AFP's report of the decision, or £345 million on the BBC's conversion. It is, as the Irish Times reported, the fourth largest fine the DPC has imposed since the GDPR came into force. Readers following the wider run of technology enforcement can find related coverage across the Corporate INTL newsroom.
What the DPC found: four infringements across three features
The DPC found four distinct GDPR failures, and they do not apply uniformly to all three features. The press release sets them out as follows: the lawfulness and fairness of processing location data in Web & App Activity and Location History; accountability, because Google could not demonstrate compliance with the lawfulness, fairness and transparency principle for Location Accuracy; transparency, across all three features; and retention of location data in Web & App Activity and Location History.
| Feature | What it does (DPC description) | Infringements found |
|---|---|---|
| Web & App Activity | A Google Account setting that, when enabled, processes activity on Google services, which can include browsing history, search history and location data | Lawfulness and fairness; transparency; retention |
| Location History | An opt-in service that tracks a user's location while they carry a compatible device and infers place visits, activities and routes, shown on a private "Timeline" map | Lawfulness and fairness; transparency; retention |
| Location Accuracy | An Android OS feature that pinpoints a device's location more precisely than GPS alone, available whether or not the user has a Google Account | Accountability (could not demonstrate lawful, fair and transparent processing); transparency |
Two points stand out for practitioners. First, the Location History description in the DPC's background note records that the service "saves the private map of where the user goes with their signed-in devices, even when the user is not using a Google service". Passive, continuous collection of this kind raises the stakes on every consent and notice decision.
Second, the Location Accuracy finding is framed as a failure of accountability rather than a positive finding that the processing was unlawful. The GDPR does not only require controllers to comply; it requires them to be able to prove it. According to PPC Land's analysis, the consumer complaints that triggered the case never named Location Accuracy at all, which suggests the DPC widened its own-volition inquiry beyond the original grievances. The DPC has said it will issue the full decision "in due course", so the detailed reasoning on each finding is not yet public.
Which GDPR articles the decision engages
The European Data Protection Board's notice of the decision lists four provisions: Articles 5, 6, 12 and 13 of the GDPR. Each maps onto one of the findings.
- Article 5, the principles. Article 5 requires processing to be lawful, fair and transparent, and requires data to be kept no longer than necessary (the storage limitation principle). Article 5(2) adds the accountability duty: the controller must be able to demonstrate compliance. The retention and Location Accuracy findings sit here.
- Article 6, lawful basis. Article 6 lists the only legal grounds on which personal data may be processed, including consent and legitimate interests. A lawfulness finding means the DPC was not satisfied that a valid ground covered the processing in Web & App Activity and Location History.
- Article 12, transparent communication. Article 12 requires information to be concise, transparent, intelligible and easily accessible, in clear and plain language.
- Article 13, information at collection. Article 13 specifies what a controller must tell people when it collects their data, including the purposes and legal basis for each processing operation and how long data will be kept.
All four sit in the band of provisions that attract the GDPR's higher fine ceiling under Article 83(5), which covers "the basic principles for processing, including conditions for consent" and the data subject rights in Articles 12 to 22. That is the first reason the Google GDPR fine is measured in hundreds of millions rather than millions.
From a 2018 complaint to a 2026 decision
The Google location case took almost eight years from complaint to decision, a delay the consumer groups behind it have openly criticised. The complaints rested on a Norwegian Consumer Council report titled Every Step You Take, published on 27 November 2018. According to BEUC, the European Consumer Organisation, seven national consumer groups filed complaints with their data protection authorities that day, and a Danish group reported the practices to its regulator.
| Date | Event |
|---|---|
| 25 May 2018 | GDPR applies; start of the period examined by the DPC |
| 27 November 2018 | Forbrukerrådet publishes Every Step You Take; seven consumer groups file complaints coordinated by BEUC |
| 22 January 2019 | Google Ireland Limited becomes the data controller for EEA users, according to PPC Land |
| February 2020 | DPC opens an own-volition inquiry as lead supervisory authority; the period examined ends on 4 February 2020 |
| 21 September 2026 | DPC announces its final decision: €403m in fines and a six-month compliance order |
| By about 21 March 2027 | Six-month deadline for Google to bring processing into compliance |
The complainant groups came from Norway, the Netherlands, Greece, the Czech Republic, Slovenia, Poland and Sweden, with Denmark reporting separately. BEUC's director general, Agustín Reyna, told the Irish Times that the decision "confirms the illegality of the way the tech giant obtained consent", but added that "late enforcement can be as harmful as no enforcement at all".
Why Ireland decides: the one-stop-shop and the lead supervisory authority
Ireland decided the case because the GDPR's one-stop-shop gives the regulator of a company's main EU establishment the lead role in cross-border cases. Under Article 56, the supervisory authority of the main establishment acts as lead supervisory authority for cross-border processing. Google, like most large US technology groups, has its European headquarters in Dublin, which is why, as AFP put it, the DPC is responsible for overseeing Google "at the European level". GDPR enforcement is therefore decentralised, in contrast with the Digital Markets Act, which the European Commission enforces directly, as the recent DMA gatekeeper ruling involving Apple illustrates.
The complaints were filed in seven countries, but that did not give seven regulators seven decisions. Article 60 requires the lead authority to cooperate with the other "concerned" authorities, share a draft decision with them and take account of their views. If a concerned authority lodges a relevant and reasoned objection that cannot be resolved, Article 65 sends the dispute to the European Data Protection Board for a binding decision.
On the public record, this case did not go that far. The DPC's statement thanks "its peer supervisory authorities" for their cooperation and assistance, and neither the DPC nor the EDPB announcement refers to an Article 65 dispute resolution. The EDPB's role here, so far as it has been published, was to record the decision in its news register.
Timing mattered too. The original complaints named Google LLC in the United States; PPC Land reports that Google Ireland Limited became the EEA controller on 22 January 2019. Before that change, national authorities could act alone, which is how France's CNIL was able to fine Google LLC €50 million in January 2019 over transparency and consent for ads personalisation. The one-stop-shop also has limits: in its September 2025 decision fining Google €325 million over Gmail ads and account-creation cookies, the CNIL explained that the mechanism does not apply to cookies and electronic marketing, which fall under the ePrivacy rules rather than the GDPR. Businesses mapping their own regulatory exposure should therefore expect national authorities to remain active alongside any lead regulator. Advisers with local enforcement experience are listed among Corporate INTL's experts in Ireland.
How big is €403m? The GDPR fine ceiling and how fines are calculated
The maximum GDPR fine for the infringements found is €20 million or 4% of total worldwide annual turnover of the preceding financial year, whichever is higher. That ceiling, set by Article 83(5), is why fines against groups the size of Alphabet can reach nine or ten figures.
Regulators do not simply pick a percentage. The EDPB's Guidelines 04/2022 on the calculation of administrative fines, adopted in final form on 24 May 2023, set out a common methodology for authorities across the EEA. In broad terms, an authority identifies the processing operations and infringements involved, sets a starting point that reflects the seriousness of each infringement and the size of the undertaking, adjusts for aggravating and mitigating factors under Article 83(2), checks the result against the legal maximum, and then tests whether the final figure is effective, proportionate and dissuasive.
Several Article 83(2) factors are visible on the face of this case: the nature, gravity and duration of the infringements (a period of almost two years); the number of people affected across the EEA; the sensitivity of location data; and the fact that retention "aggravated" the loss of control, in the Deputy Commissioner's own word. The DPC has not yet published how it weighted each factor, nor how the €403 million total divides between the four infringements. PPC Land notes that no per-infringement breakdown has been released and calculates the fine at roughly 0.1% of Alphabet's 2025 revenue, far below the 4% cap.
There is also a fault threshold. As Secure Privacy's review of the Amazon appeal explains, the Court of Justice ruled on 5 December 2023 in Deutsche Wohnen that GDPR fines cannot be imposed on a strict-liability basis: the authority must establish intent or negligence. That requirement has already undone one landmark fine, and it is likely to feature in any challenge Google brings.
How the Google GDPR fine compares with other large fines
At €403 million, the Google location fine is the fourth largest imposed by the DPC and sits among the largest GDPR penalties anywhere. The table below draws on the DPC's own published fines register (last updated 10 August 2026) and other sources as marked.
| Company | Authority | Date | Fine | Subject / status |
|---|---|---|---|---|
| Meta Platforms Ireland | DPC (Ireland) | 12 May 2023 | €1.2bn | EU to US data transfers; pending appeal |
| Amazon Europe Core | CNPD (Luxembourg) | July 2021 | €746m | Advertising and legitimate interest; fine annulled by the Administrative Court on 12 March 2026 and sent back to the CNPD |
| TikTok Technology | DPC | 30 April 2025 | €530m | Transfers of EEA data to China; pending appeal |
| Meta (Instagram) | DPC | 2 September 2022 | €405m | Pending appeal |
| Google Ireland | DPC | 21 September 2026 | €403m | Location data; six-month compliance order |
| Meta (Facebook and Instagram) | DPC | 31 December 2022 | €390m | Two decisions; pending appeal |
| TikTok Technology | DPC | 1 September 2023 | €345m | Pending appeal |
| DPC | 22 October 2024 | €310m | Pending appeal | |
| Google LLC | CNIL (France) | January 2019 | €50m | Transparency and consent for ads personalisation |
Two patterns emerge. The largest penalties concentrate on a small number of Dublin-based groups, a direct consequence of the one-stop-shop. And the DPC's register marks almost every nine-figure fine as "pending appeal", which means the headline figure is rarely the final word. The EU's other digital rulebooks are producing similar numbers: the Commission recently imposed a record €550m DSA fine on AliExpress.
Location tracking has also cost Google outside Europe. In November 2022 it agreed a $391.5m settlement with 40 US states, which the attorneys general called the largest multistate privacy settlement in US history, after investigators alleged it had misled users about location tracking since at least 2014.
Google's response, the appeal route and the six-month order
Google says the case concerns historical policies that it has since changed. A spokesperson told the Guardian and other outlets: "This case centres around historical policies that have since been updated. From 2019 onwards, we've significantly evolved our practices and launched robust tools that make managing location data simple."
The changes Google points to are real and documented. The Irish Times reports that users can now have data deleted automatically after a period of between three and 36 months, that Timeline data is stored on users' devices, and that ad personalisation controls have been simplified. Google announced in December 2023 that Timeline would be saved on the device rather than in the cloud. Whether those changes satisfy the DPC's six-month order has not been stated publicly.
An appeal looks likely. RTÉ reported that "it is understood that Google will appeal the ruling focused on legal issues that require clarification beyond this case", and the Irish Times said Google "may appeal elements of the decision". The route is set by the Data Protection Act 2018:
- Appeal within 28 days. Section 142 allows a controller to appeal a fine within 28 days of formal notice. For fines above €75,000 the appeal goes to the High Court, which may confirm the decision, substitute a different fine or no fine, or annul it, acting in accordance with Article 83.
- Court confirmation if there is no appeal. Under section 143, the DPC must apply to the Circuit Court to confirm an unappealed fine, and the court will confirm it "unless the Court sees good reason not to do so". Until then the fine is not collectable.
- Further inquiries. The DPC has three other large-scale inquiries into Google at an advanced stage, including one opened in September 2024 into whether Google should have carried out a data protection impact assessment before using Europeans' data to train its AI models, according to AFP.
For companies facing their own regulatory proceedings, the procedural lesson is that the decision is the start of a second phase, not the end. Experienced dispute resolution and litigation counsel are typically involved from the draft-decision stage onwards.
Is location data personal data under GDPR?
Yes. Location data is expressly named in the GDPR's definition of personal data. Article 4(1) defines an identifiable person as one who can be identified "by reference to an identifier such as a name, an identification number, location data, an online identifier" or other factors.
Location data is not listed among the special categories in Article 9, but regulators treat it as high risk because of what it reveals. BEUC's complaint materials put it bluntly: location data can reveal religious beliefs (visits to places of worship), political leanings (attending demonstrations), health conditions (regular hospital visits) and sexual orientation (visiting certain bars). The DPC's Deputy Commissioner made the same point in more measured language, saying location data "can reveal a significant amount of information about an individual, including information that is inherently private".
For businesses, the practical consequence is that raw coordinates, derived place visits, inferred routines and advertising segments built from them are all personal data if they can be linked to a person, directly or indirectly. That includes data held against device identifiers or account IDs rather than names. Questions about who may access such data, and under what legal compulsion, are also live in the UK, as the tribunal fight over Apple's encrypted data shows.
Consent, dark patterns and lawful basis: the core lessons
The central lesson is that consent obtained through repeated nudging, pre-selected settings or bundled choices is unlikely to be valid, and a controller that cannot rely on consent will struggle to find another lawful basis for intrusive tracking. The Forbrukerrådet report accused Google of using "deceptive design, misleading information and repeated pushing", in BEUC's words, to steer Android users into enabling tracking. PPC Land records the complaint's allegation that users had to decline Location History "at least four times" across different preinstalled apps, and that Web & App Activity was pre-selected during account set-up.
The DPC's published findings speak of lawfulness, fairness and transparency rather than dark patterns as such, and the full reasoning is awaited. But the legal standards the complaint relied on are clear:
- Consent must be freely given, specific, informed and unambiguous, and under Article 7(3) "it shall be as easy to withdraw as to give consent".
- Legitimate interests is not a fallback for invasive tracking. BEUC argued that Google could not invoke legitimate interest "due to the significant and intrusive impact that this tracking has". The Luxembourg court reviewing Amazon's fine likewise left intact the finding that Amazon could not rely on legitimate interests for behavioural advertising.
- Interface design is a compliance issue. The EDPB's Guidelines 03/2022 on deceptive design patterns give concrete examples of patterns in sign-up flows, privacy settings and account management that can breach the GDPR's fairness and transparency principles.
- Data protection by design and default. Article 25 requires that, by default, only personal data necessary for each specific purpose is processed, which cuts against settings that are switched on unless the user objects.
Scrutiny of platform design is not limited to data protection law. Consumer groups have also used the Digital Services Act to press regulators on scam advertising on Google, Meta and TikTok, and the regulatory overlap is only growing.
What the ruling means for companies processing location data
Any organisation that collects, infers or monetises location signals should treat the Google decision as a benchmark for how EU regulators will assess its own practices. That includes app publishers, mobility and delivery platforms, retailers using footfall analytics, insurers pricing on driving behaviour, advertising technology intermediaries and employers tracking vehicles or devices.
Three features of the decision deserve attention in boardrooms. The first is retention: the DPC found a separate infringement for keeping location data too long, and described over-retention as aggravating. Default retention periods and deletion that actually happens are now enforcement issues in their own right. The second is accountability: the Location Accuracy finding shows that a controller can be sanctioned for failing to evidence compliance, even where the regulator does not go on to find the processing itself unlawful. The third is transparency across the stack: operating-system features, account settings and consumer apps were each assessed, so a notice that is clear in one place does not cure silence in another.
Surveys of senior technology leaders already rank data governance and security as top priorities. The Google fine gives that priority a price. It also illustrates timing risk: conduct from 2018 to 2020 produced a fine in 2026, so today's product decisions may be judged years from now against standards that have tightened in the meantime.
A compliance checklist for in-house counsel
In-house teams can use the findings to test their own location data practices now, before a regulator does. The following steps track the four infringements.
- Map every location signal. Record each source (GPS, Wi-Fi, Bluetooth, IP address, cell data, inferred place visits), each system that stores it and each purpose it serves, including advertising and profiling.
- Assign a lawful basis per purpose. Document which Article 6 ground covers each purpose. Where consent is the basis, make sure it is separate for each purpose, not bundled with service access, and as easy to withdraw as to give.
- Audit the interfaces. Review sign-up flows, settings screens and in-app prompts against the EDPB deceptive design guidelines. Remove pre-ticked options, repeated prompts after refusal and asymmetric "accept" and "decline" choices.
- Rewrite notices at the point of collection. Explain in plain language what location data is collected, why, on what basis, for how long, and whether it is used for advertising or to infer interests, as Articles 12 and 13 require.
- Set and enforce retention periods. Fix a period for each dataset that is justified by purpose, make short retention the default, and test that deletion actually runs.
- Build the accountability file. Keep records of processing, data protection impact assessments for high-risk location processing, legitimate interest assessments where relied on, and design decisions, so compliance can be demonstrated on request.
- Prepare for access and deletion requests. Location histories are often the most revealing data a person can request; our explainer on the GDPR right of access sets out what individuals are entitled to see.
- Secure the data. Precise location data is attractive to attackers and to anyone seeking to track individuals; involve cyber security specialists in access controls and breach planning.
- Check the ePrivacy layer. Where location is read from a device or combined with cookies or similar technologies, national ePrivacy rules can apply in parallel and outside the one-stop-shop, as the CNIL's 2025 Google decision illustrates.
Two questions are worth putting to product and marketing teams directly: would a user who declined tracking once be asked again, and could the company show a regulator, today, why each dataset is still held? If either answer is uncertain, the Google decision suggests that is where review should begin.
When to bring in specialist advisers
Most organisations can run the checklist above internally, but outside help is worth considering when location data feeds advertising or profiling, when processing spans several EU jurisdictions, or when a complaint or regulatory inquiry has already begun. Specialist technology, media and telecoms advisers can review product design and lawful basis, while regulatory and public law specialists handle engagement with supervisory authorities. Groups operating across several markets may also want cross-border advisers who can coordinate lead-authority and national-level exposure. Profiles of recognised practitioners also appear in Corporate INTL's Who's Who handbooks.
The answer to why is Google being fined by Europe is, in the end, straightforward: it failed to process location data lawfully, fairly and transparently, and kept it too long. The harder question for every other company is whether its own location practices would survive the same scrutiny.
Frequently asked questions
Why is Google being fined by Europe?
Ireland's Data Protection Commission, acting as Google's lead EU regulator, fined Google €403 million on 21 September 2026. It found that Web & App Activity, Location History and Location Accuracy breached GDPR rules on lawfulness, fairness, transparency, accountability and retention of location data between May 2018 and February 2020.
Which GDPR articles did Google breach?
The EDPB's notice lists Articles 5, 6, 12 and 13. Article 5 sets the core principles, including storage limitation and accountability; Article 6 governs lawful basis; Articles 12 and 13 require clear information to users about how their data is processed, why, on what legal basis and for how long.
What is the maximum fine for a GDPR violation?
For breaches of the core principles, lawful basis, consent conditions or data subject rights, Article 83(5) allows fines of up to €20 million or 4% of total worldwide annual turnover for the preceding financial year, whichever is higher. Lesser infringements carry a lower ceiling of €10 million or 2%.
Why is Google's EU regulator in Ireland?
Under the GDPR one-stop-shop, the authority where a company has its main EU establishment leads cross-border cases. Google's European headquarters is in Dublin, so the Data Protection Commission acts as lead supervisory authority, cooperating with regulators in other member states under Article 60.
Is location data personal data under GDPR?
Yes. Article 4(1) of the GDPR names location data as an identifier that can make a person identifiable. It is not a special category under Article 9, but regulators treat it as high risk because it can reveal religion, health, political views and sexual orientation.
Will Google appeal the €403m fine?
Google says the case concerns historical policies that it has since updated. RTÉ reported it is understood Google will appeal on legal issues. Under section 142 of Ireland's Data Protection Act 2018, an appeal must be lodged within 28 days of formal notice, and fines above €75,000 go to the High Court.
What are the penalties for GDPR violations in Ireland?
The DPC can impose administrative fines up to the Article 83 caps and order corrective measures, such as Google's six-month compliance order. Fines are not collectable until confirmed: if no appeal is made, the DPC must ask the Circuit Court to confirm the fine under section 143.
How does the Google fine compare with other GDPR fines?
It is the fourth largest DPC fine. Meta's €1.2 billion fine in 2023 remains the largest, followed by TikTok's €530 million and Instagram's €405 million. Amazon's €746 million fine from Luxembourg was annulled on procedural grounds in March 2026 and sent back to the regulator.
What should companies using location data do now?
Map every location signal and purpose, document a lawful basis for each, remove pre-selected settings and repeated prompts, rewrite notices in plain language, set short default retention periods and verify deletion, and keep an accountability file that shows how each decision complies with the GDPR.
Sources
- Data Protection Commission: DPC fines Google €403 million following Inquiry into Google's processing of location data (21 September 2026)
- European Data Protection Board: The Irish Data Protection Commission fines Google 403 000 000 EUR
- Data Protection Commission: Fines register
- The Irish Times: Irish data protection watchdog fines Google €403m over GDPR breaches
- The Guardian: Google fined more than €400m by Irish regulator over its use of location data
- RTÉ: Google fined €403m by Irish data watchdog over location data
- AFP via Yahoo Finance: EU fines Google 403 mn euros for location data breach
- PPC Land: Google faces €403m fine over location tracking flagged in 2018
- BEUC: Every Step You Take
- Forbrukerrådet: Every Step You Take (November 2018)
- Irish Statute Book: Data Protection Act 2018, section 142
- Irish Statute Book: Data Protection Act 2018, section 143
- GDPR Article 83: General conditions for imposing administrative fines
- GDPR Article 56: Competence of the lead supervisory authority
- EDPB Guidelines 04/2022 on the calculation of administrative fines under the GDPR
- EDPB Guidelines 03/2022 on deceptive design patterns in social media platform interfaces
- Secure Privacy: Amazon's €746M GDPR fine annulled in 2026
- CNIL: Google fined 325 million euros (September 2025)
- BBC News: Google hit with £44m GDPR fine over ads (January 2019)
- The Guardian: Google will pay $392m to 40 states in largest ever US privacy settlement
- Google: Updates to Location History and new controls coming soon to Maps (December 2023)
About this article
This analysis was researched and written by The Corporate INTL Newsroom, which covers cross-border legal, regulatory and business developments for lawyers, professional advisers and financiers in over 150 jurisdictions. It has been checked against the Data Protection Commission's announcement, the EDPB's notice, the text of the GDPR and the Irish Data Protection Act 2018, and primary reporting. The DPC's full decision had not been published at the time of writing. This article is general information, not legal advice; for advice on a specific matter, consult a qualified adviser. Last reviewed 24 September 2026. To receive analysis like this, subscribe to Corporate INTL.