The Lawxy Times

Author Image
Lawxy Times Reporter

Irish DPC fines Google €403m for unlawful location tracking

The Irish Data Protection Commission imposed a €403 million penalty on Google Ireland on 21 September 2026 for unlawful processing of users’ location data. The decision clarifies that retroactive technical fixes do not cure past breaches of the Regulation. Google and other data controllers that rely on historical location information now face a substantial monetary sanction and heightened accountability for location‑based services. The ruling limits the effectiveness of post‑hoc compliance measures as a defence against GDPR liability.

Full News Breakdown

The DPC launched a six‑year investigation after receiving complaints that Google continued to collect precise location signals without adequate consent. Google argued that it had altered its practices in 2019 and that the historic data were no longer identifiable. The Commission concluded that the remedial steps could not legitimize the earlier unlawful processing and ordered the fine.

  • Case Name: Google Ireland Ltd v Irish Data Protection Commission

  • Court: Irish Data Protection Commission

  • Date: 21 September 2026

  • EU Instruments / UK Legislation Cited: General Data Protection Regulation (Regulation (EU) 2016/679)

  • Key Provisions: Art 5(1)(f) (storage limitation); Art 6 (lawfulness of processing); Art 7 (conditions for consent); Art 30 (records of processing); Art 24 (responsibility of the controller)

  • Primary Legal Issue: Whether historical location‑data processing violated the Regulation’s requirements on lawfulness, fairness, transparency and storage limitation

  • Applicant/Plaintiff Arguments: The DPC asserted that Google processed location data without valid consent, retained it excessively, and failed to provide clear information to users.

  • Respondent/Defendant Arguments: Google contended that it had remedied the practice after 2019, that the data were anonymised, and that the changes should mitigate liability.

  • Court's Reasoning: The Commission held that accountability demands contemporaneous compliance; retroactive technical measures cannot erase prior breaches; consent must be specific, informed and freely given; and retention periods must be proportionate to the purpose.

  • Holding: The €403 million fine was upheld and Google was ordered to delete the historic location data and implement GDPR‑compliant location‑accuracy controls.

  • Operative Order: Immediate payment of the fine; conduct an independent audit; submit a detailed compliance plan within 90 days.

  • Practical Outcome: Google must overhaul its location‑data handling across all services and absorb a significant financial penalty.

How Does This Affect You?

Before this ruling, practitioners were uncertain whether post‑hoc technical adjustments could shield organisations from liability for earlier GDPR breaches. The Commission now confirms that such remedial steps do not erase past non‑compliance. Consequently, risk assessments must treat historic processing as independently actionable, and compliance programmes must address both current and legacy data practices.

For Lawyers & Advocates

  • Amend privacy policies to obtain explicit, granular consent for location accuracy, referencing the specific purposes required by the Regulation.

  • Review all client data‑processing agreements to include clauses obligating the controller to delete historic location data that lack a valid legal basis.

  • Cite this decision as authority when arguing that retrospective technical fixes cannot mitigate liability in forthcoming enforcement actions.

  • Advise ongoing merger‑related due‑diligence to assess legacy location‑data inventories, as undisclosed historical processing may trigger substantial fines.

  • Highlight the residual risk that the Commission’s order leaves open regarding the adequacy of Google’s post‑2019 safeguards, prompting clients to implement continuous monitoring.

For Law Students

This case demonstrates the Commission’s strict approach to the Regulation’s accountability principle, emphasizing that compliance must be contemporaneous rather than retroactive. The core doctrinal focus is the interplay between the lawful basis for processing (Art 6) and the storage‑limitation obligation (Art 5(1)(f)).

The decision is particularly relevant for the study of:

  • Data‑protection compliance and accountability

  • Consent mechanisms under Art 7

  • Records‑of‑processing obligations (Art 30)

  • Enforcement strategies of EU data‑protection authorities

  • Comparative analysis of GDPR versus UK Data Protection Act 2018

Comparable cases include the French CNIL decision against Uber (2024) and the German BfDI ruling on Facebook (2025), both of which illustrate how supervisory authorities assess historic processing and the limits of remedial actions. Comparing them clarifies the doctrinal question of whether post‑hoc technical measures can ever satisfy the accountability requirement.

For Businesses

  • Companies that process location data must audit historic datasets and document the legal basis for each record; failure to do so may result in fines comparable to the €403 million sanction.

  • Boards should commission an independent GDPR compliance review focusing on legacy data retention policies before the next financial reporting cycle.

  • Marketing teams need to redesign consent flows to capture specific location‑accuracy permissions, ensuring that future data collection meets the Regulation’s consent standards.

  • Cloud‑service providers offering location‑based analytics must update their service‑level agreements to reflect the obligation to delete non‑compliant historic data on client request.

Key Takeaways

  • The Regulation now expressly requires contemporaneous compliance; retroactive technical fixes cannot excuse prior unlawful processing.

  • Data‑protection officers must incorporate legacy‑data assessments into their standard compliance checklists.

  • Supervisory authorities can impose fines for historic breaches even when controllers have subsequently implemented corrective measures.

  • Monitor the European Commission’s upcoming “Location‑Data Governance” proposal, expected to be tabled in early 2027, for further clarification on consent and retention standards.

  • In‑house counsel should initiate a comprehensive location‑data audit before the end of the next quarter to mitigate exposure to similar enforcement actions.

Source: Google says €403m Irish fine was over ‘historical’ location tracking practices

Secure by design. Built for enterprise.

More About Security

Lawxy AI is designed with encrypted infrastructure, access controls, audit visibility, and enterprise-grade security standards.

SOC 2 Type I, II

GDPR

ISO 27001

VAPT Tested

Secure by design. Built for enterprise.

More About Security

Lawxy AI is designed with encrypted infrastructure, access controls, audit visibility, and enterprise-grade security standards.

SOC 2 Type I, II

GDPR

ISO 27001

VAPT Tested

Secure by design. Built for enterprise.

More About Security

Lawxy AI is designed with encrypted infrastructure, access controls, audit visibility, and enterprise-grade security standards.

SOC 2 Type I, II

GDPR

ISO 27001

VAPT Tested