
Ireland’s privacy regulator says Google unlawfully and unfairly processed location data, failed to give users sufficient information and kept some of the data for longer than necessary.
Google has been fined €403 million following a major European privacy investigation into how the company collected, used and retained people’s location data.
The Irish Data Protection Commission (DPC), which acts as Google’s lead privacy regulator in the European Union, launched the inquiry in February 2020 after receiving complaints from several European consumer-rights organizations, including the European Consumer Organisation (BEUC).
The investigation covers Google’s processing of location data from May 25, 2018—the date the General Data Protection Regulation took effect—until Feb. 4, 2020.
The regulator examined three features: Web & App Activity, Location History and Location Accuracy.
It concludes that Google violated the GDPR through:
Besides the €403 million in administrative fines, the regulator has ordered Google to bring the processing covered by the decision into compliance within six months. The DPC says it will publish the full decision later.
Location information can make digital services more useful. It helps people navigate unfamiliar places, find nearby businesses, receive local recommendations and recover missing devices.
But a detailed location trail can also expose deeply personal aspects of someone’s life: where they live and work, which medical facilities they visit, where their children go to school, the religious services they attend and the people they meet regularly.
Deputy Commissioner, Graham Doyle commented:
Location data is a type of personal data which is processed by way of location tracking, and includes data collected or processed by Google, which by itself or in conjunction with other information an individual’s location can be inferred. Location data can bring both benefits and harms to individuals. It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private.
According to the regulator, Google’s failures meant that people could have been unaware their location was being used to influence advertising or infer their interests.
Keeping the information longer than necessary further reduced users’ control over their personal data, Doyle added.
Web & App Activity is a Google Account setting that can save information about a person’s activity across Google services. Depending on the configuration, the information can include searches, browsing activity and location-related data.
Location History—now presented to users as Google Maps Timeline—records places visited and routes traveled. The feature can build a private map of someone’s movements, including when they are carrying a compatible device but are not actively using a Google service.
Location Accuracy is an Android feature that combines signals such as GPS, nearby Wi-Fi networks, mobile towers and device sensors to estimate a device’s position more precisely. Unlike the other two features examined by the DPC, it can be available to Android users without a Google Account.
The inquiry addresses Google’s practices during a specific historical period. Google’s current documentation says Timeline is off by default and stores location history on individual devices, with an optional encrypted cloud backup. However, the company also warns that turning off Timeline does not necessarily prevent location information from being saved through other settings, including Web & App Activity.
People depend heavily on major technology platforms, but often have limited visibility into what happens behind the settings screens.
The latest Bitdefender Consumer Cybersecurity Survey, covering more than 7,000 internet users in seven countries, finds that Google is one of the most trusted technology companies. Some 88% of respondents say they trust it to some extent, placing it alongside Microsoft (85%) and ahead of Apple (77%).

Yet that confidence does not equal unconditional permission. Nearly one in five respondents—19%—say they want to keep their location information away from major technology platforms.

Concern is even greater in some European countries.

Consumers may trust a familiar brand while still feeling uneasy about individual data practices. Trust can also be based on convenience, habit or a lack of practical alternatives rather than a clear understanding of how information is processed.
But overall, consumers deserve to know (and understand) what information is collected, why it is needed, how different controls interact and how long the company keeps the data.
Turning off a single setting may not be enough because location data can come from several sources. Google notes that even after users disable or delete Timeline, other services may retain approximate location information derived from activity or an IP address.
Consumers should consider the following steps:
1. Review Google Account activity controls
Check both Timeline and Web & App Activity. Disable anything you do not need and review previously saved information.
2. Delete old activity
Use Google’s My Activity and Maps Timeline tools to remove historical data. Where available, configure automatic deletion.
3. Check app permissions
On Android and iOS, restrict location access to apps that genuinely need it. Prefer “While using the app” and approximate location where appropriate.
4. Review Android Location Accuracy
Android users can find this under Settings > Location > Location Services > Location Accuracy on many current devices. Note that disabling it can reduce accuracy and affect services such as navigation or device finding.
5. Inspect location sharing separately
Timeline, app permissions and live location sharing are different controls. Check Google Maps to ensure you are not sharing your position with people who no longer need it.
6. Revisit the settings periodically
Services, menus and defaults change. A privacy checkup every few months can reveal permissions or saved activity you have forgotten about.
7. Pay attention to breach notifications
If a service you use reports a breach, act quickly: update passwords, monitor credit reports where relevant, and consider identity theft protections.
8. Know your GDPR rights
Under GDPR, you have rights to access, correct, delete, and restrict processing of your personal data. Contact the company or your local data protection authority if these rights are not respected.
On topic:
Europe slaps tech sector with €1.2 billion in fines under GDPR in 2025
tags
Filip has 17 years of experience in technology journalism. In recent years, he has focused on cybersecurity in his role as a Security Analyst at Bitdefender.
View all posts