Skip to main content
The state of ai impact assessment
Location Data Compliance Myths That Cost €403 MillionSupervisory Authorities & Enforcement
5 min readFor Privacy Officers

Location Data Compliance Myths That Cost €403 Million

Google's €403 million fine from Ireland's Data Protection Commission (DPC) highlights how easily organizations can misunderstand their GDPR obligations regarding location data. The decision, which scrutinized Google's Web & App Activity, Location History, and Location Accuracy features between May 2018 and February 2020, exposes misconceptions that persist across privacy teams.

These myths endure because location data intersects with multiple GDPR obligations: lawful basis, transparency, data minimization, and accountability. Processing millions of data points across different features and jurisdictions can lead to reliance on simplified assumptions. However, as this enforcement action shows, those shortcuts create liability.

Myth 1: If Users Can Turn Off Location Features, You've Met Transparency Requirements

Reality: Articles 13 and 14 require you to explain what you're doing with location data, not just provide an on/off switch.

The DPC found Google violated transparency rules even though users could disable these features. The issue wasn't access to controls; it was that people couldn't understand what enabling those controls meant for their data. Were they consenting to location processing for navigation only, for ad targeting, or for inferring interests based on visited locations?

Your transparency documentation must specify each processing purpose, the categories of location data you'll collect, and how long you'll keep it. If Location History means storing precise GPS coordinates to build a movement profile that influences ad delivery for 18 months, say that. Generic statements about "improving your experience" don't satisfy Article 5(1)(a)'s fairness requirement.

Myth 2: Auto-Delete Features Automatically Fix Data Minimization Issues

Reality: Retention periods must be justified from the start; retroactive fixes don't erase past violations.

Google introduced auto-delete controls in May 2019 and made 18-month deletion the default for new accounts in June 2020. These changes occurred during the period the DPC examined, yet the supervisory authority still found violations for retaining location data longer than necessary.

Article 5(1)(e) requires you to keep personal data only as long as necessary for your stated purposes. That determination must happen before you start processing, not after a supervisory authority opens an inquiry. If you can demonstrate that ad personalization requires 18 months of location history, document that analysis. If you can't, you're processing unlawfully from day one.

Adding deletion controls later shows good faith but doesn't prove your original retention period was proportionate. The DPC hasn't publicly confirmed whether Google's current auto-delete defaults satisfy the compliance order issued alongside the fine.

Myth 3: Opt-In Mechanisms Automatically Establish a Valid Lawful Basis

Reality: Requiring opt-in doesn't mean you've secured valid consent or proven another lawful basis applies.

Location History required users to opt in, yet the DPC still found lawful processing violations. The distinction matters: opt-in is a mechanism, consent is a lawful basis with specific validity conditions under Article 7.

For consent to be valid, it must be freely given, specific, informed, and unambiguous. If your opt-in flow bundles location processing with other services users need, it's not freely given. If the explanation doesn't specify what location data you'll collect and why, it's not informed. If enabling Location History triggers multiple processing operations with different purposes, a single toggle isn't specific enough.

The DPC's finding that Google breached accountability rules means the company couldn't demonstrate its processing was lawful, fair, and transparent. You need documentation showing which lawful basis applies to each processing operation, why it's appropriate, and how you've met that basis's conditions.

Myth 4: Processing Without a Google Account Reduces GDPR Risk

Reality: Anonymous or pseudonymous processing still falls under GDPR if data relates to an identifiable person, and you still need a lawful basis.

Location Accuracy works on Android devices regardless of whether users have a Google account. The DPC's findings for this feature focused on transparency and accountability violations, specifically, Google couldn't demonstrate the processing was lawful, fair, and transparent.

This matters because privacy teams often assume device-level processing without direct account linkage creates less regulatory exposure. It doesn't. Article 4(1) defines personal data as information relating to an identified or identifiable natural person. If Location Accuracy data can be linked to a device that can be linked to a person, it's personal data.

You need the same lawful basis, transparency documentation, and appropriate technical and organizational measures whether users authenticate or not. The accountability obligation under Article 5(2) requires you to demonstrate compliance in both scenarios.

Myth 5: Lengthy Enforcement Timelines Mean Low Regulatory Priority

Reality: The DPC opened its inquiry in February 2020 and issued the decision more than 6.5 years later. That delay doesn't signal low priority, it signals complexity and cross-border coordination that you can't predict or control.

BEUC's director general called the timeline harmful: "Late enforcement can be as harmful as no enforcement at all." For your organization, this creates planning risk. You might implement location features today that seem compliant, only to face an inquiry announcement in 2025 and a final decision in 2031.

The enforcement delay also means you can't rely on the absence of regulatory action as evidence of compliance. Google's violations occurred between May 2018 and February 2020, but the company received the decision in September 2026. That's eight years of potential liability accumulation before formal resolution.

What to Do Instead

Start with purpose specification. For each location processing operation, document exactly why you need that data, which lawful basis applies, and how long you'll keep it. If you're relying on legitimate interests, complete a legitimate interests assessment that addresses the specific risks of location tracking.

Build transparency documentation that explains your processing in concrete terms. "We collect your precise GPS coordinates when you use navigation features and retain them for 90 days to improve route accuracy" is better than "We process location data to enhance services."

Implement technical controls that enforce your documented retention periods automatically. Don't wait for users to discover deletion settings, make data minimization the default.

Finally, recognize that the six-month compliance deadline the DPC imposed on Google applies to you too. If a supervisory authority identifies violations in your location processing, you'll need to remediate quickly across potentially millions of data subjects and multiple processing systems. Build that capability now while you control the timeline.

GDPR Articles

Application Security Isn’t Optional Anymore.

You Might Also Like