The Challenge
Google processed location data across three features, Web & App Activity, Location History, and Location Accuracy, from May 25, 2018, to February 4, 2020. During this period, Ireland's Data Protection Commission found the company failed to comply with Article 5's core principles: lawfulness, fairness, and transparency.
The violations weren't due to a single catastrophic breach. They were about everyday processing decisions that revealed systemic gaps under regulatory scrutiny. Users couldn't see how their location data influenced ad targeting or interest profiling. More critically, Google retained this data longer than necessary, compounding the control users had already lost through unclear consent mechanisms.
The DPC's investigation began in February 2020, triggered by complaints from European consumer organizations, including BEUC. This timing is significant: consumer advocacy groups spotted patterns that Google's accountability frameworks should have caught.
Operational Realities and Constraints
Google operated as a controller processing location data at massive scale across the EU. The company faced several operational realities that complicated compliance:
Cross-feature data flows. Location signals collected through one feature could inform processing in another, such as ad targeting. Each feature required its own lawful basis, transparency layer, and retention schedule. The DPC found Google's accountability measures couldn't clearly demonstrate these distinctions.
Legacy retention practices. When GDPR took effect on May 25, 2018, Google inherited data retention policies from a different regulatory regime. Aligning those policies with Article 5(1)(e)'s storage limitation principle required more than technical changes, it demanded a fundamental reassessment of what "necessary" meant for each processing purpose.
Transparency at scale. Explaining location processing to hundreds of millions of users across multiple touchpoints created tension between comprehensiveness and clarity. The DPC's findings suggest Google prioritized feature functionality over user understanding.
The regulatory constraint was clear: Article 5(2) places the burden of proof on the controller. Google couldn't demonstrate compliance, which meant it wasn't compliant.
Google's Approach and Shortcomings
The source material doesn't detail Google's internal compliance decisions during the examined period. What we know from the DPC's findings: Google's approach failed on three fronts.
Lawful basis documentation. The company couldn't show which lawful basis applied to location processing across its features, or why that basis satisfied Article 6's requirements. For location data used in ad targeting or interest inference, this gap was particularly damaging, users couldn't have provided meaningful consent if they didn't understand the processing.
Transparency implementation. Google's privacy notices and settings interfaces didn't clearly explain how location data moved between features or how retention periods varied by purpose. The DPC specifically cited failures across all three features, suggesting the transparency problem was structural, not isolated.
Retention policy alignment. Google kept location data beyond what its stated purposes required. This violated Article 5(1)(e) directly and aggravated the transparency failures: users who couldn't understand the processing also couldn't know their data was being retained unnecessarily.
The DPC ordered Google to bring its processing into compliance within six months, reflecting the supervisory authority's view that these weren't edge cases requiring novel technical solutions. They were accountability failures.
Results and Implications
The €403 million fine is one outcome. The compliance order matters more for your risk assessment.
Ireland's DPC found violations spanning May 25, 2018, to February 4, 2020, a 21-month period beginning the day GDPR took effect. This timing tells you something: supervisory authorities expect controllers to demonstrate compliance from day one, not to phase it in gradually.
The DPC's Deputy Commissioner, Graham Doyle, emphasized the consequence: "Individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data."
That loss of control, amplified by unnecessary retention, became the regulatory harm the DPC penalized. Not a data breach. Not a security incident. Ordinary processing that failed to meet GDPR's baseline standards.
Corrective Actions
The source material doesn't include Google's retrospective, but the DPC's findings point to clear corrective actions:
Purpose-specific retention schedules. Each processing purpose needs its own documented retention period tied to that purpose's business justification. When location data serves ad targeting, how long does that targeting purpose persist? When it infers interests, how long are those inferences relevant? These questions require answers before you collect the data, not after a supervisory authority asks.
Layered transparency that follows data flows. If location data from Feature A influences processing in Feature B, your privacy notice for Feature A must explain that connection. Users don't need a technical architecture diagram, but they need enough information to understand the stakes of their consent.
Proactive accountability documentation. Article 5(2) doesn't say "be compliant." It says "be able to demonstrate compliance." That's a documentation standard. Google's failures suggest its internal records couldn't reconstruct the lawful basis logic, retention justifications, or transparency decisions for each feature, even though those decisions were made.
Takeaways for Your Team
Consumer complaints trigger formal inquiries. The DPC launched this investigation after receiving complaints from BEUC and other consumer organizations. Your privacy team can't assume that individual DSARs represent the full scope of user concern. Organized advocacy groups are monitoring processing patterns and escalating them to supervisory authorities.
Retention is an accountability test. Article 5(1)(e) requires you to keep data only as long as necessary for your stated purposes. If you can't articulate why you need 18 months instead of 12, or two years instead of one, you're holding data without a lawful basis. The DPC treated Google's retention failures as evidence of broader accountability gaps, retention policy became a proxy for governance maturity.
Transparency obligations extend beyond privacy policies. The violations covered "transparency across all three features," which suggests Google's settings interfaces, consent flows, and in-app notices all fell short. Your Article 13 and 14 obligations don't end with a compliant privacy policy. Every touchpoint where users make decisions about their data must meet the transparency standard.
Six-month compliance orders are realistic timelines. The DPC gave Google six months to fix processing that spanned 21 months of non-compliance. That timeline implies these weren't technically impossible fixes, they were governance and documentation gaps. If your retention policies don't align with your stated purposes, or your transparency layers don't explain cross-feature data flows, you don't need a multi-year roadmap. You need decisions.
The €403 million penalty will get budget attention. The compliance order should get operational attention. Google's failures weren't exotic, they were everyday processing decisions that couldn't withstand regulatory scrutiny. Your location data practices, your retention schedules, and your transparency implementations face the same test.



