Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Location Data Processing Under GDPRLawful Basis for Processing
5 min readFor Legal & Compliance Teams

Location Data Processing Under GDPR

Scope of This Guide

This guide covers the lawful basis, transparency, and retention requirements for processing location data under the GDPR. It focuses on the violations identified in Google's €403m fine by the Irish Data Protection Commission: lawfulness and fairness failures, accountability gaps, transparency deficiencies, and excessive retention periods. If your organization collects precise location, inferred location, or movement patterns, you need to demonstrate compliance with these obligations.

The guide emphasizes Articles 5, 6, 13, 14, and 30. It doesn't cover cross-border transfer mechanisms or personal data breach notification procedures.

Key Concepts and Definitions

Location data: Data that reveals or can infer an individual's physical position, such as GPS coordinates, Wi-Fi triangulation, cell tower proximity, and IP-based geolocation. Under GDPR, this is personal data. When it reveals patterns about places of worship, medical facilities, or political venues, it may require Article 9 protections as special category data.

Lawfulness vs. fairness: Article 5(1)(a) requires both. Lawfulness means having a valid lawful basis under Article 6. Fairness means not using data in ways that surprise or disadvantage the data subject. The Irish DPC found Google's processing unlawful and unfair because users didn't understand their location data would be used for ad targeting and profiling.

Accountability principle: Article 5(2) requires you to demonstrate compliance, not just claim it. You must maintain documentation proving your processing meets GDPR requirements. The Irish DPC cited Google's failure to demonstrate compliance with lawfulness, fairness, and transparency for its Location Accuracy feature.

Requirements Breakdown

Lawful Basis (Article 6)

You need one of six lawful bases. For location processing, you'll typically rely on:

  • Consent (Article 6(1)(a)): Must be freely given, specific, informed, and unambiguous. If using location for multiple purposes (service delivery, analytics, advertising), you need separate consent for each. Pre-ticked boxes aren't valid.

  • Contract performance (Article 6(1)(b)): Applies when location is objectively necessary for the requested service. Navigation apps can use this for directions. It can't cover analytics or ad targeting.

  • Legitimate interests (Article 6(1)(f)): Requires a legitimate interests assessment balancing your interests against the data subject's rights. Given location data's sensitivity, this basis is hard to justify for advertising or profiling.

Transparency Obligations (Articles 13-14)

You must inform users at the point of collection:

  • Your identity and contact details
  • Specific purposes for processing their location data
  • The lawful basis you're relying on
  • How long you'll retain the data
  • Whether you'll share it with third parties
  • Their rights (access, erasure, restriction, objection)

The Irish DPC found Google's transparency failures across all three features it examined. Your privacy notice can't be vague about what "improving services" means if you're actually building ad profiles.

Data Minimization and Retention (Article 5(1)(c) and (e))

You can only keep location data as long as necessary for your stated purpose. The Irish DPC found Google retained location data longer than necessary, which "aggravated the loss of control" users experienced.

Define specific retention periods tied to purpose. If you need location for fraud detection, determine how long historical patterns remain relevant. If you need it for a delivery, delete it when the delivery's complete.

Accountability Measures (Article 5(2))

Document your decisions:

  • Records of processing activities (Article 30) specifying location data categories, purposes, retention periods, and recipients
  • Data protection impact assessments for high-risk processing (Article 35)
  • Legitimate interests assessments if relying on Article 6(1)(f)
  • Evidence of implemented technical and organizational measures

Implementation Guidance

Establishing Your Lawful Basis

Map every use of location data. For each use, ask: what's the purpose, and which lawful basis applies?

If using consent, implement granular controls. A user consenting to location-based service delivery hasn't consented to location-based advertising. Your consent mechanism must allow users to say yes to one and no to the other.

If considering legitimate interests, run a proper assessment. Document your legitimate interest, evaluate necessity, and conduct a legitimate interests assessment. For location data, the legitimate interests assessment rarely favors the controller when the purpose is advertising or profiling.

Building Transparent Disclosures

Write your privacy notice in plain language without sacrificing specificity. Instead of "we use your location to improve our services," write "we use your precise GPS location to show you nearby restaurants and measure how often you visit retail locations for our advertising partners."

Present location-specific information at the point where you request location permissions, not buried in a general privacy policy. Mobile apps should use the system permission dialogue plus a just-in-time explanation.

Implementing Retention Controls

Set automated deletion schedules. If location data is necessary for 90 days, configure your systems to delete it at 91 days. Don't rely on manual review.

Distinguish between aggregated, anonymized data and personal data. Once you've extracted the insights you need, delete the individual-level location records.

Demonstrating Accountability

Your Article 30 records should list location data as a distinct category with its own purpose, lawful basis, and retention period. Don't lump it under "usage data" or "analytics data."

If processing location at scale or for profiling, complete a data protection impact assessment. Document the necessity of location processing, alternatives considered, and safeguards implemented.

Common Pitfalls

Bundling consent: Requiring users to accept location tracking as a condition of using your service when location isn't objectively necessary. This makes consent invalid under Article 7(4).

Vague purpose statements: Describing processing as "personalization" or "service improvement" when actually building advertising profiles. The Irish DPC specifically called out this practice in Google's case.

Passive retention: Keeping location data indefinitely because you haven't implemented deletion processes. Article 5(1)(e) requires active retention management.

Inadequate documentation: Claiming you've assessed the necessity of location processing but having no written record of that assessment. Accountability means evidence, not assertions.

Treating all location data the same: GPS coordinates revealing someone's home address carry different risks than city-level location. Your safeguards should reflect the precision and sensitivity of the data you're collecting.

Quick Reference Table

Requirement Article What You Must Do Evidence Required
Lawful basis 6(1) Identify valid basis for each purpose Consent records, contract terms, or legitimate interests assessment
Fairness 5(1)(a) Don't use location in ways that surprise users Privacy notice, consent language, user testing results
Transparency 13-14 Disclose purposes, basis, retention, recipients at collection Privacy notice, in-app disclosures, consent flows
Data minimization 5(1)(c) Collect only location data necessary for purpose Purpose documentation, technical specifications
Retention limits 5(1)(e) Delete location data when no longer necessary Retention schedule, deletion logs, automated deletion configs
Accountability 5(2) Maintain documentation proving compliance Article 30 records, DPIAs, legitimate interests assessments
Appropriate measures 32 Implement appropriate technical and organisational measures for location data Access controls, encryption specs, pseudonymization procedures

The Irish DPC's investigation covered the period from May 25, 2018, to February 4, 2020, but your obligations haven't changed. If you're processing location data today, supervisory authorities expect you to demonstrate compliance with these same requirements.

Application Security Isn’t Optional Anymore.

You Might Also Like