Ireland’s Data Protection Commission has fined Google €403 million for violations of the EU General Data Protection Regulation related to the processing of users’ location information.
The investigation concerned three features: Web & App Activity, Location History and Location Accuracy. The regulator examined how these tools operated between May 25, 2018, and February 4, 2020.
Google was also ordered to bring its processing of location data into compliance with the GDPR within six months.
Why Google was fined
The decision was announced on September 21, 2026, by Ireland’s Data Protection Commission, or DPC. It acts as Google’s lead European regulator because the company’s European headquarters are located in Ireland.
The DPC opened the investigation on its own initiative in February 2020 after receiving complaints from several European consumer rights organizations.
The regulator found GDPR violations in several areas:
the processing of location data through Web & App Activity and Location History did not meet the requirements of lawfulness and fairness;
Google failed to adequately demonstrate GDPR compliance in the operation of Location Accuracy;
information about data processing across all three features did not meet transparency requirements;
location data collected through Web & App Activity and Location History was kept longer than necessary.
According to the DPC, users may not have understood that their location information could be used for purposes such as personalizing advertising or determining their interests.
The regulator imposed administrative fines totaling €403 million. The full text of the decision has not yet been published, but the DPC said it would be released at a later date.
The decision covers the period from 2018 to 2020
It is important to note that the regulator’s findings cover a specific historical period — from the GDPR’s entry into force on May 25, 2018, until the investigation began on February 4, 2020.
The decision does not mean that all of Google’s current location settings have automatically been declared unlawful. Over the following years, the company changed how users manage location data, redesigned its settings and revised the way location history is stored.
A Google representative told Reuters that the investigation concerned historical policies and that the company had significantly updated its location controls since 2019.
At the same time, the DPC ordered Google to bring its data processing into compliance with the GDPR within six months. The specific additional changes required from the company should become clearer once the regulator publishes its full decision.
Which Google features did the DPC investigate?
The investigation covered three separate mechanisms. Each can use location information, but they operate in different ways.
Web & App Activity
Web & App Activity saves a user’s actions across selected Google services to their Google Account.
The saved information may include search queries, activity in apps and services, device information, interactions with advertisements and other related data. According to Google, these records may also contain an approximate location based on the general area where the device was used or its IP address.
To review this setting on Android:
Open Settings.
Select Google.
Tap Manage your Google Account.
Open Data & privacy.
Find the History settings section.
Select Web & App Activity.
The feature can be turned off, or users can choose to turn it off and delete previously saved activity at the same time. Individual records are also available on the My Activity page.
Location History is now called Timeline
The feature previously known as Location History is now presented in Google Maps as Timeline. It creates a private map of the places, routes and trips associated with a user.
According to Google’s current information, Timeline is turned off by default and begins working only after the user enables it. When activated, the device’s precise location may be saved regularly, even when Google apps are not being used.
The current version of Timeline stores information separately on each device. Users may also voluntarily enable encrypted cloud backup to Google’s servers.
To review Timeline settings:
Open Google Maps.
Tap the profile picture.
Select Your Timeline.
Open the settings menu.
Go to the location and privacy settings.
Users can delete all Timeline data, a selected period, a particular day or an individual visit. Automatic deletion is also available for data older than 3, 18 or 36 months.
Turning off Timeline does not guarantee that all location-related information will be removed from a Google Account. Google warns that an approximate location may still be stored through Web & App Activity or the history of individual search services.
What Location Accuracy does
Location Accuracy, also known as Google Location Services, is an Android system feature. It is available even to people who do not use a Google Account.
The feature helps a device determine its location more quickly and accurately. It may use:
GPS;
Wi-Fi access points;
mobile networks;
the accelerometer;
the gyroscope;
the barometer and other device sensors.
Google says that when the feature is enabled, the system may periodically collect information about nearby wireless signals and device sensors. Random temporary identifiers are used for this purpose. According to the company, they change regularly and are not associated with a particular person or Google Account.
On Android 12 and newer versions, the setting can usually be found under:
Settings → Location → Location services → Location Accuracy.
If enhanced accuracy is turned off, the device will rely mainly on GPS and its own sensors. This may reduce the quality of navigation, indoor positioning and lost-device detection.
Check location permissions for individual apps
In addition to Google Account settings, Android separately controls each app’s access to the device’s location.
The list of permissions can usually be found under:
Settings → Location → App location permissions.
For each app, users may be able to choose one of the following options:
allow access all the time;
allow only while using the app;
ask every time;
do not allow.
Modern versions of Android also allow users to share only an approximate location instead of precise coordinates. Permanent access is best disabled for apps that do not need location information for their core functions.
What users should do
The fine does not mean that users need to urgently disable every location feature. Navigation, lost-device tracking, local weather forecasts and nearby recommendations all depend on access to location information.
However, it is worth checking:
whether Google Maps Timeline is enabled;
what information is stored in My Activity;
whether Web & App Activity is needed;
which apps have access to precise location;
which apps can access location in the background;
whether automatic history deletion is enabled;
whether Timeline cloud backup is active.
The central point of the DPC’s decision is not that every use of location data is unlawful. Companies must clearly explain what information they collect, why they collect it, how long it is retained and how users can control it.
