On 21 September 2026, the Data Protection Commission (DPC) announced a €403 million fine against Google Ireland Limited following its inquiry into how Google processed users' location data, and ordered the company to bring that processing into compliance within six months. The inquiry, opened in February 2020, covered the period from 25 May 2018 to 4 February 2020 and examined three account features: Web & App Activity, Location History and Location Accuracy.
The DPC found that Google infringed the GDPR in four respects: the lawfulness and fairness of its processing of location data through Web & App Activity and Location History; its accountability obligation, in demonstrating compliance for Location Accuracy; its transparency obligations across all three features; and the retention of location data in Web & App Activity and Location History. The decision was made by Commissioners Dr Des Hogan, Dale Sunderland and Niamh Sweeney. Deputy Commissioner Graham Doyle noted that location data can make online services more useful but can also reveal significant private information about individuals.
The breadth of the findings is as significant as the figure. A single processing context produced a lawful-basis problem, a transparency problem, an accountability problem and a retention problem at once. Each corresponds to something an organisation is expected to be able to show on request: the purpose and lawful basis behind the processing, the information given to the people concerned, evidence that compliance can be demonstrated rather than asserted, and a retention period that is actually applied to the data.
Location data is also a recurring theme in European enforcement because of what it can reveal: patterns of movement point to home and work addresses, health appointments, religious practice and associations. That sensitivity is why regulators expect the justification for collecting and keeping it to be specific, documented and proportionate.
Acompli perspective: The Google decision is a reminder that accountability is a records problem as much as a policy one. Organisations processing location or other revealing data should be able to point to a record of processing that states the purpose, lawful basis and retention period for that data; a data map that shows where it is collected, where it flows and how long it is kept; and an assessment that weighed the risk before the processing began. Keeping those records connected, and approved by a named reviewer, is what turns "we are compliant" into something a regulator can check.
