The Irish Data Protection Commission's €403 million fine against Google for location data processing violations between May 2018 and February 2020 offers a clear view into how supervisory authorities evaluate transparency and accountability. More importantly, it provides your team with a practical compliance blueprint.
If your organization processes location data through mobile apps, web services, or connected devices, the DPC's findings highlight where regulatory scrutiny is most intense. This checklist translates those findings into actionable steps your team can take now.
Prerequisites
Before using this checklist, ensure you have:
- Documentation of all systems and services that collect, process, or store location data
- Current privacy notices and consent mechanisms for location-enabled features
- Access to your data retention schedules and deletion procedures
- Authority to review and update data processing practices across product teams
If you're missing any of these, gather them first. This checklist requires you to verify actual practices, not intended ones.
Location Data Compliance Checklist
1. Map every location data touchpoint across your services
Document where location data enters your systems: GPS coordinates, IP-derived location, Wi-Fi positioning, cell tower triangulation, or inferred location from user behavior. Include all features, not just those obviously labeled "location services."
✓ Good looks like: A complete inventory showing data type, collection method, processing purpose, and retention period for each service or feature. Your DPO can trace any location data point from collection to deletion.
2. Verify your lawful basis for each processing activity
For every location data touchpoint identified, confirm which Article 6 lawful basis applies. If you're relying on consent (Article 6(1)(a)), verify it's specific, informed, and freely given. If you're relying on legitimate interests (Article 6(1)(f)), confirm you've completed a legitimate interests assessment that accounts for location data's sensitivity.
✓ Good looks like: Written documentation of the lawful basis for each processing activity, with supporting assessments where required. No gaps, no assumptions.
3. Audit your transparency obligations for location processing
Review every privacy notice, in-app disclosure, and settings interface where users encounter location features. The DPC emphasized that individuals "could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests." Your notices must explain not just that you collect location data, but how you use it to make decisions that affect the user.
✓ Good looks like: Privacy notices that explicitly state when location data influences advertising, content personalization, or behavioral inference. Users can read your notice and understand the actual processing, not just the category.
4. Separate location features with distinct consent mechanisms
If your organization offers multiple location-enabled features, each must have its own consent control. You cannot bundle them into a single "allow location services" toggle if they serve different purposes.
✓ Good looks like: Granular consent controls where users can enable location accuracy for navigation while declining location history for advertising. Each control clearly explains what that specific feature does.
5. Implement purpose-specific retention periods
The DPC noted that "retention of users' location data for longer than necessary aggravated this loss of control." Review your retention schedules. Location data collected for real-time navigation doesn't justify indefinite storage. Location data used for advertising analytics requires a defensible retention period tied to that specific purpose.
✓ Good looks like: Documented retention periods for each location processing purpose, with automated deletion procedures. If you retain location data for more than 90 days, you can articulate the specific business requirement and lawful basis.
6. Build accountability into product development
The DPC's inquiry examined whether Google complied with accountability requirements under Article 5(2). This means demonstrating compliance, not just claiming it. When your product teams launch location-enabled features, they must document the data protection assessment before launch.
✓ Good looks like: A mandatory data protection impact assessment (DPIA) workflow for any feature processing location data. Product launches are blocked until the DPO signs off on the DPIA and confirms appropriate technical and organizational measures are in place.
7. Review historical policies against current practices
Google's response noted the inquiry focused on "historical policies that have since been updated." This is not a defense. Your current practices must match your current policies, and you must update both as processing evolves. If your privacy notice references practices from 2019, audit whether those descriptions still reflect reality.
✓ Good looks like: A quarterly review cycle where your DPO and product teams verify that privacy notices, consent flows, and actual data processing remain aligned. Any discrepancies trigger immediate updates or processing changes.
8. Test user control mechanisms
Users must be able to disable location processing and delete stored location data. The DPC's concern about individuals losing "control over their personal data" suggests these controls must be accessible and effective, not buried in settings menus.
✓ Good looks like: Users can disable location features and request deletion of historical location data within three clicks from your main settings interface. Deletion requests complete within 30 days with confirmation sent to the user.
Common Mistakes
Treating location as low-risk data. The DPC explicitly called out location data's sensitivity, noting it can "reveal a significant amount of information about an individual, including information that is inherently private." Your risk assessments must reflect this.
Assuming implied consent. If users enable a location feature for one purpose (navigation), you cannot process that data for another purpose (advertising) without separate, specific consent.
Relying on outdated documentation. The six-month remediation order Google received shows supervisory authorities expect prompt updates. If your last DPIA for location processing is over a year old, it's likely inadequate.
Bundling unrelated processing activities. Each distinct use of location data requires its own lawful basis, transparency disclosure, and retention justification. You cannot use a single consent to cover navigation, analytics, and advertising.
Next Steps
Complete this checklist within 30 days. If you identify gaps, prioritize transparency obligations and user control mechanisms first. These were central to the DPC's findings and are most visible to users and supervisory authorities.
If your organization processes location data at scale, consider whether your current practices would withstand a multi-year inquiry. The DPC examined Google's practices from May 2018 through February 2020. Your documentation and technical measures must demonstrate continuous compliance, not point-in-time fixes.
Finally, brief your product and engineering teams on these requirements. The €403 million fine and six-month remediation order show that supervisory authorities will mandate operational changes, not just policy updates. Your teams need to understand that location data processing carries specific, enforceable obligations under Articles 5, 6, and 13 of the GDPR.





