The Irish Data Protection Commission fined Google Ireland Limited €403 million for violating multiple GDPR principles through its location tracking features. If your team processes location data through mobile apps, web services, or connected devices, this analysis reveals where Google's controls failed and what the regulation requires.
What Happened
The DPC launched an inquiry in February 2020 after European consumer rights organizations, including BEUC, filed complaints about Google's location data processing. The investigation focused on three features: Web & App Activity, Location History, and Location Accuracy, covering processing from 25 May 2018 (GDPR's application date) to 4 February 2020.
The Commission identified violations in four areas: lawfulness and fairness of processing in Web & App Activity and Location History, accountability failures in Location Accuracy, transparency deficiencies in all three features, and improper retention practices in Web & App Activity and Location History.
Timeline
25 May 2018: GDPR takes effect, subjecting Google's location data processing practices to full GDPR requirements.
May 2018, February 2020: Google operates Web & App Activity, Location History, and Location Accuracy with practices later found to violate transparency, lawfulness, fairness, accountability, and retention obligations.
February 2020: The DPC opens an inquiry following complaints from European consumer rights organizations.
Investigation period: The DPC examines Google's lawful basis documentation, user interface flows, data retention schedules, and internal compliance records for the three features.
Final decision: The Commission imposes a €403 million fine and orders Google to comply within six months.
Which Controls Failed or Were Missing
Lawful basis implementation: Google failed to demonstrate that its processing met the requirements for lawfulness and fairness in Web & App Activity and Location History. This wasn't about choosing the wrong lawful basis but failing to implement the chosen basis properly. If you're relying on consent, your request mechanism must meet Article 7 requirements. If using legitimate interests, document an assessment under Article 6(1)(f) that balances your interests against user rights.
Transparency mechanisms: All three features failed transparency obligations. The information Google provided about location data collection, purposes, and retention didn't meet Article 13 and 14 standards. You can't hide critical details in settings menus or use vague language about "improving services." Users need clear, specific information about what data you collect, why you need it, and how long you keep it.
Accountability documentation: Google couldn't demonstrate compliance with lawfulness, fairness, and transparency principles for Location Accuracy. Article 5(2) requires you to prove compliance, not just claim it. Your documentation must show decision-making processes, risk assessments, and the controls you implemented.
Retention schedules: Web & App Activity and Location History violated retention requirements. Article 5(1)(e) limits storage to what's necessary for your stated purposes. You need documented retention periods tied to specific business or legal requirements, not indefinite storage "in case we need it later."
What the Relevant Standard Requires
Article 5(1)(a), Lawfulness, fairness, and transparency: Your processing must have a valid lawful basis under Article 6, operate fairly, and provide clear information to data subjects. Fairness means users can reasonably expect how you'll use their data based on the context and your communications.
Article 5(2), Accountability: You must demonstrate compliance with all processing principles. This requires written policies, records of processing activities under Article 30, data protection impact assessments where required by Article 35, and evidence that you implemented appropriate technical and organizational measures.
Articles 13 and 14, Transparency obligations: When collecting personal data, you must provide: your identity and contact details, your data protection officer's contact details, processing purposes and lawful basis, legitimate interests if applicable, recipients or categories of recipients, retention periods or criteria for determining them, and data subject rights. This information must be concise, transparent, intelligible, and in clear and plain language.
Article 5(1)(e), Storage limitation: You can only keep personal data for as long as necessary for your stated purposes. This requires defining retention periods before you start processing, documenting the criteria you used to set those periods, and implementing technical controls to delete or anonymize data when the period expires.
Lessons and Action Items for Your Team
Map your location data flows completely: Document every feature or service that collects, infers, or processes location data. Include background collection, derived location from IP addresses or WiFi, and location used for analytics. For each flow, identify the specific purpose, lawful basis, and data subjects affected.
Audit your transparency materials against Article 13/14 checklists: Review your privacy notices, in-app disclosures, and consent flows. Ensure you're providing all required information, not just some of it. If you're collecting location data for multiple purposes, break down each purpose separately rather than grouping them under "service improvement."
Build retention into your data architecture: Implement automated deletion or anonymization based on documented retention periods. Your systems should flag data approaching its retention limit and require affirmative decisions to extend retention with documented justification.
Create compliance evidence as you go: Article 5(2) accountability means contemporaneous documentation. When you conduct a legitimate interests assessment, document it before you start processing. When you update a privacy notice, record why you made specific changes. When you set a retention period, note the business or legal requirement that determined the timeframe.
Test your lawful basis implementation: If you're using consent for location data, verify that your consent mechanism meets Article 7 requirements: freely given, specific, informed, and unambiguous. If you're using legitimate interests, ensure you've documented a legitimate interests assessment that weighs your interests against user rights and freedoms.
The six-month compliance deadline the DPC imposed on Google is the timeline you should give yourself for a full location data audit. Start with your highest-risk processing activities and work systematically through transparency, lawful basis documentation, retention schedules, and accountability records.





