we_are_coded.by CODE · The world, decoded
БГ
Data protection

Ireland fines Google 403 million euros over location data collected more than six years ago

Data Protection Commission (Ireland) · event date: 21 September 2026Control

The Irish regulator has closed an inquiry it opened in February 2020 after complaints from consumer organisations. Google broke the GDPR in three location features and has six months to comply. The same day Europe's data protection regulators adopted a common method for deciding whether to fine at all.

In short
  • The fines total 403 million euros, and the infringements cover the period from 25 May 2018 to 4 February 2020.
  • The features concerned are Web & App Activity, Location History and Location Accuracy on Android.
  • The European Data Protection Board adopted five steps regulators follow when deciding whether to fine.
Checked on1 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

The inquiry opened in February 2020. The decision came out on 21 September 2026.

Six and a half years between the start of an inquiry and the fine sounds like forever, and it is. Why it took so long, the DPC's announcement does not say.

The facts: on 21 September 2026 Ireland's Data Protection Commission (DPC), the lead supervisory authority for Google in the EU, announced its final decision in an own-volition inquiry into Google Ireland Limited, launched in February 2020 after complaints from several European consumer organisations, including BEUC. The inquiry covered the processing of location data in three features - Web & App Activity, Location History and Location Accuracy - between 25 May 2018 and 4 February 2020. According to the DPC, Google infringed the GDPR in respect of the lawfulness and fairness of processing in Web & App Activity and Location History, its accountability obligation regarding Location Accuracy, transparency across all three features, and the retention of the data. The administrative fines total 403 million euros, and Google has six months to bring its processing into compliance. The full decision will be published later. The same day the European Data Protection Board (EDPB) adopted guidelines with a five-step method for deciding when regulators impose a fine, open for public consultation until 13 November 2026, along with its final guidelines on the interplay between the DSA and the GDPR.

The uncomfortable part

The description of Location History in the DPC's announcement. The feature keeps a private map of where you go with your signed-in devices, even when you are not using a Google service. You switch it on yourself, and then it tracks where you are while the phone is with you.

Deputy Commissioner Graham Doyle puts it plainly: people may not have known their location was being used to influence them with ads or to infer their interests. And keeping the data longer than necessary made the loss of control worse.

Nobody is afraid of a map they have never seen.

The EDPB method is the other half of the day, duller and more important for anyone holding personal data in Europe. Five steps, the last of which asks whether a fine would be effective, proportionate and dissuasive. A minor infringement generally brings no fine and may end in a reprimand, while anything beyond minor creates a strong presumption of a fine.

The decision covers a past period. Open your Google account and phone settings and see which of the three are on for you, and for how long the history is kept.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→Data Protection Commission (Ireland) - DPC fines Google €403 million following Inquiry into Google's processing of location data, 21.09.2026→EDPB - EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines, 21.09.2026
Original: https://wearecoded.com/en/articles/irlandiya-globi-google-403-mln-lokaciya.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news