The Irish regulator has closed an inquiry it opened in February 2020 after complaints from consumer organisations. Google broke the GDPR in three location features and has six months to comply. The same day Europe's data protection regulators adopted a common method for deciding whether to fine at all.
- The fines total 403 million euros, and the infringements cover the period from 25 May 2018 to 4 February 2020.
- The features concerned are Web & App Activity, Location History and Location Accuracy on Android.
- The European Data Protection Board adopted five steps regulators follow when deciding whether to fine.
The inquiry opened in February 2020. The decision came out on 21 September 2026.
Six and a half years between the start of an inquiry and the fine sounds like forever, and it is. Why it took so long, the DPC's announcement does not say.
The uncomfortable part
The description of Location History in the DPC's announcement. The feature keeps a private map of where you go with your signed-in devices, even when you are not using a Google service. You switch it on yourself, and then it tracks where you are while the phone is with you.
Deputy Commissioner Graham Doyle puts it plainly: people may not have known their location was being used to influence them with ads or to infer their interests. And keeping the data longer than necessary made the loss of control worse.
The EDPB method is the other half of the day, duller and more important for anyone holding personal data in Europe. Five steps, the last of which asks whether a fine would be effective, proportionate and dissuasive. A minor infringement generally brings no fine and may end in a reprimand, while anything beyond minor creates a strong presumption of a fine.
The decision covers a past period. Open your Google account and phone settings and see which of the three are on for you, and for how long the history is kept.