You're collecting location data. The question isn't whether you need a retention policy, it's which retention model fits your processing purposes and risk profile.
Ireland's Data Protection Commission (DPC) fined Google €403 million for transparency failures and retaining location data longer than necessary through Web & App Activity and Location History features. The violation period ran from May 25, 2018, through February 4, 2020. The authority found users "could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests," creating a loss of control that extended retention periods aggravated.
If you're processing location data, you're facing the same retention choice Google misjudged. Here's how to decide.
The Decision You're Facing
Your retention policy determines how long you hold location data after collection. Three factors drive this choice:
Your processing purpose under Article 6. If you're using location for fraud detection (legitimate interests), your retention timeline differs from location used for direct marketing (consent). The lawful basis shapes the necessity test.
Your data minimization obligations under Article 5(1)(c). Location data is precise personal data. The longer you hold it, the broader your exposure if a personal data breach occurs or a data subject access request (DSAR) reveals processing the individual didn't expect.
Your transparency obligations under Articles 13 and 14. Whatever retention period you choose, you must specify it in your privacy notice. "We keep your data as long as necessary" fails the transparency test the DPC applied to Google.
Key Factors That Affect Your Choice
Before you set a retention schedule, map these elements:
Granularity of the location data. GPS coordinates down to a few meters carry different risk than city-level location. Google now stores only "an estimated general area" in Web & App Activity rather than precise device location. If your processing purpose permits coarser data, aggregate before you store.
Frequency of collection. Continuous tracking creates a movement profile. One-time location checks for delivery verification do not. Frequency affects both necessity and the severity of transparency failures.
Secondary processing. The DPC noted users could have been unaware their location was used to "influence them with ads or to infer their interests." If you're conducting a compatibility assessment under Article 6(4), your retention period must account for the new processing, and you must update your transparency disclosures.
Supervisory authority guidance in your jurisdiction. Some authorities have issued sector-specific retention guidance. Review it before you finalize your policy.
Path A: Short-Term Deletion (Immediate to 90 Days)
Choose short-term deletion when your processing purpose is transactional and time-bound.
When this fits:
- Delivery or ride-sharing services where location confirms a completed transaction
- Fraud detection that requires recent location patterns, not historical movement
- Session-based services where location improves the immediate user experience but has no ongoing value
Implementation steps: Set automated deletion at the shortest interval that serves your purpose. Google now automatically removes Maps Timeline data older than three months and stores it on-device rather than centrally. If 30 days meets your fraud detection needs, delete at 31 days.
Document your necessity assessment. When a supervisory authority or DSAR challenges your retention period, you must demonstrate why you chose 90 days instead of 30, or 30 instead of seven.
Update your Article 13/14 notice with the specific period: "We delete your location data 30 days after collection."
Compliance advantage: Short retention limits your exposure if you suffer a personal data breach. It also simplifies DSAR responses, if you delete data within 30 days, most DSARs won't reach data that's already gone.
Path B: Purpose-Linked Retention (6 Months to 3 Years)
Choose purpose-linked retention when you have a documented business or legal need that extends beyond immediate transactions.
When this fits:
- Analytics that require longitudinal data to identify patterns
- Regulatory obligations that specify retention periods
- Warranty or product liability where location data evidences usage patterns relevant to claims
Implementation steps: Tie your retention period to the specific purpose in your lawful basis documentation. If you're relying on legitimate interests for location-based analytics, your legitimate interests assessment must explain why you need 12 months of data rather than six.
Build purpose-specific deletion triggers. When the purpose ends, the retention clock stops.
Separate retention schedules by processing purpose. If you're using location for both service delivery and marketing, you need two deletion timelines.
Compliance advantage: Purpose-linked retention demonstrates you've applied the necessity principle to your specific processing activities. It also gives you a defensible answer when a supervisory authority asks why you're still holding data.
Path C: User-Controlled Deletion
Choose user-controlled deletion when your processing relies on consent or when you want to exceed your minimum legal obligations.
When this fits:
- Marketing or personalization based on consent
- Competitive differentiation where privacy controls are a product feature
- High-risk processing where you want to give users maximum control
Implementation steps: Provide an interface where users set their own retention period or trigger immediate deletion. Google implemented controls that "let users define a specific timeline for automatically deleting data in their account."
Set a default deletion period that applies if the user doesn't choose. Make it the shortest period that serves your purpose.
Document that you offered the control and what the user selected.
Compliance advantage: User-controlled deletion reduces the risk that a supervisory authority will second-guess your necessity assessment. It also creates a record of user choice that supports your transparency obligations.
Summary Matrix
| Retention Model | Best For | Key Requirement | Main Risk If Misapplied |
|---|---|---|---|
| Short-Term (≤90 days) | Transactional, session-based services | Automated deletion at fixed interval | Over-retention if purpose actually requires longer period |
| Purpose-Linked (6mo, 3yr) | Analytics, regulatory obligations, warranty | Documented necessity tied to specific purpose | Retention beyond purpose completion; transparency failures |
| User-Controlled | Consent-based processing, competitive differentiation | Default backstop + user interface for choice | Treating "no user action" as consent to indefinite retention |
Your retention policy is not a one-time decision. Review it when you add new processing purposes, when supervisory authorities issue guidance, and when you receive DSARs that reveal users didn't understand how long you're keeping their data. The DPC found Google's practices from 2018-2020 failed these tests. Your 2024 policy needs to account for what enforcement has taught us since.





