A Nine-Figure Wake-Up Call for Data Governance
On September 21, 2026, Ireland's Data Protection Commission (DPC) issued a €403m fine against Google Ireland Limited for the unlawful processing of location data. This is the fourth-largest penalty ever handed down by the DPC since GDPR came into force in May 2018 — trailing only the record €1.2bn fine imposed on Meta in 2023.
The investigation, opened in February 2020 following complaints filed by the European Bureau of Consumer Unions (BEUC), covered the period from May 25, 2018 to February 4, 2020. Three widely used features within Google's ecosystem came under scrutiny: Location History, Web & App Activity, and Location Accuracy. In each case, the regulator concluded that users were not adequately informed about how their location data was being used — including for advertising purposes and interest-based profiling.
Lawfulness, Transparency, Retention: Three Pillars Under Pressure
The DPC's decision identifies failures across several core GDPR obligations. First, lawfulness and fairness of processing: Google failed to demonstrate a sufficiently clear legal basis for collecting and exploiting location data. Second, transparency obligations: users should have been able to understand, without undue effort, that their geographic location was feeding advertising targeting logic. Third, retention rules: storing location data beyond what is strictly necessary for the stated purpose is itself a violation.
What's at stake is not the technical sophistication of the processing — it's the consent and disclosure architecture, or rather the absence of a sufficiently rigorous one at the point these features were deployed.
The One-Stop-Shop Mechanism Under the Microscope
The Irish DPC acts as lead supervisory authority for Google, Meta, TikTok, and LinkedIn — all of which maintain their European headquarters in Dublin. This one-stop-shop mechanism, designed to streamline compliance for pan-European operators, effectively concentrates enormous regulatory pressure on a single authority. Every DPC ruling sets precedent across all EU member states, which is why corporate legal and IT teams track each decision so closely.
Google now has six months to bring its practices into compliance or face further sanctions. The clock is running until spring 2027.
What IT Teams Need to Take Away
This case extends well beyond a single large platform. It sets clear markers for any organization that collects, stores, or processes location data — whether through a mobile app, a fleet management tool, a marketing automation platform, or a physical access control system.
For CIOs and compliance officers, the operational takeaway is unambiguous: location data is not a benign metadata category. It triggers enhanced transparency obligations, demands an explicitly documented legal basis, and requires retention periods strictly limited to the declared purpose. A formalized retention policy — regularly audited and legible to end users — is no longer an optional best practice. It is a non-negotiable compliance requirement.
As European regulations continue to stack up — GDPR, the AI Act, the Data Act, ePrivacy currently under revision — location data governance has become a priority workstream for any organization that wants to stay out of the regulator's next decision.

