Skip to main content
Category: Data Classification & Identifiers

Location Data

Also known as: Geolocation Data
Simply put

Location data is information that indicates where a device, user, or asset is physically located, often expressed as geographical coordinates. It is commonly generated through technologies such as GPS or through electronic communications networks. Depending on how it is collected and whether it can be linked to an individual, it may be treated as personal data and be subject to data protection rules.

Formal definition

Location data broadly refers to information indicating the geographical position of a device, user, or asset, typically derived from satellite positioning (e.g., GPS), network-based signals, or other geolocation techniques and often expressed as geographical coordinates. In the UK PECR context, the ICO describes location data specifically as data processed in an electronic communications network or by an electronic communications service indicating the geographical position of a user's terminal equipment; this sector-specific meaning is narrower than the general concept and carries its own processing conditions. Where location data relates to an identified or identifiable natural person, it will generally constitute personal data and be subject to applicable data protection law; the precise legal characterisation and lawful basis depend on the collection method, linkability to an individual, and the applicable regime (for example, PECR and the UK GDPR versus the EU framework). Location data that is genuinely anonymised, or that relates solely to inanimate assets without any link to an individual, generally falls outside personal data rules, though whether data is truly anonymised is a fact-specific assessment.

Why it matters

Location data can reveal a great deal about an individual's life beyond a simple point on a map. Patterns of movement can indicate where a person lives and works, which places of worship, clinics, or political venues they visit, and who they associate with. For this reason, location data linked to an identified or identifiable natural person will generally constitute personal data and, in some contexts, may reveal or infer special category information (such as health or religious belief), which would require an additional condition under Article 9. The precise legal characterisation is fact-specific and depends on the collection method, linkability to an individual, and the applicable regime.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs need to determine when location data amounts to personal data, identify the correct lawful basis under Article 6, and consider whether an additional Article 9 condition is required where movement patterns could reveal special category information. Because the position can differ between the PECR/UK GDPR context and the EU framework, mapping which regime applies to a given processing activity is an important early step.
Compliance and Legal Teams
Legal and compliance functions should assess the narrower PECR-specific meaning of location data separately from the general concept, as the sector-specific meaning carries its own processing conditions. They should also treat anonymisation claims cautiously, since whether location data is genuinely anonymised is a fact-specific assessment, and verify positions against the current official text rather than relying on a snapshot interpretation.
Product and Engineering Teams
Teams building products that collect location through GPS, network-based signals, or other geolocation techniques should understand how their collection method affects linkability to an individual, and therefore the legal characterisation of the data. Design decisions about retention, precision, and aggregation can influence whether data remains linked to an individual or moves toward genuine anonymisation, subject to assessment.

Inside Location Data

Geolocation identifier
Data that indicates the geographic position of a device or individual, such as GPS coordinates, cell tower triangulation, Wi-Fi access point data, or IP-based approximations. Where such data relates to an identified or identifiable natural person, it generally constitutes personal data.
Precision and granularity
The accuracy of the location reference, ranging from coarse (country or city level) to precise (exact coordinates). Higher granularity typically increases the risk to individuals and, in most cases, weighs on the assessment of proportionality and necessity.
Temporal dimension
Timestamps and movement patterns over time. A sequence of location points can reveal habits, routines, and inferences (for example, places of worship or health facilities visited), which may bring the data within scope of special category data under Article 9 if it reveals such information.
Source and collection method
The technical means by which location is derived, such as device sensors, network operators, or third-party SDKs. The source affects both accuracy and the identification of the relevant controller or processor.
Link to an identifiable person
Location data falls within the GDPR only where it relates to an identified or identifiable individual. Genuinely anonymous location data is generally outside the material scope, though re-identification risk should be assessed, as location traces can be difficult to anonymise irreversibly.

Common questions

Answers to the questions practitioners most commonly ask about Location Data.

Is location data always considered personal data under the GDPR?
Not automatically, but frequently. Location data is personal data where it relates to an identified or identifiable individual, which is often the case when it is tied to a device, account, or other identifier that can be linked back to a person. Where location information has been genuinely and irreversibly anonymised so that no individual can be identified, it generally falls outside the GDPR's scope. However, apparent aggregation or pseudonymisation is not the same as anonymisation, and location patterns can be highly re-identifying even when direct identifiers are removed. Each case should be assessed on whether re-identification remains reasonably possible.
Does processing location data always require the individual's consent?
No. Consent is one of the Article 6 legal bases, but it is not a universal requirement. Depending on the context, other bases such as performance of a contract, legitimate interests, or a legal obligation may apply. That said, consent often becomes relevant where separate rules apply, for example national laws implementing the ePrivacy framework, which can require consent for storing or accessing information on a user's device or for certain uses of location data by electronic communications providers. The interaction between the GDPR and ePrivacy-derived national rules should be checked, as it can vary by member state, and any assessment should confirm which instrument governs the specific processing.
How should we identify the appropriate legal basis for processing location data?
Begin by defining each distinct purpose for which location data is processed, then map each purpose to an Article 6 basis and document the reasoning. Where the data reveals special category information, an additional Article 9 condition would also be needed. Consider whether national ePrivacy-derived rules impose a consent requirement for the collection step, which is separate from the GDPR basis for subsequent processing. Where legitimate interests is relied upon, carrying out and recording a balancing assessment is generally expected. The chosen basis, and any layered requirements, should be verified against the current official text and applicable national law.
What should a privacy notice say about location data?
Transparency obligations generally require informing individuals about the categories of location data collected, the specific purposes, the legal basis relied upon, retention periods or the criteria used to set them, any recipients or transfers, and how individuals can exercise their rights. Because location data can be sensitive and revealing, plain-language explanations of precision, frequency of collection, and any inferences drawn are typically helpful for meaningful transparency. Notices should be reviewed to reflect the actual processing carried out rather than generic templates.
When might a Data Protection Impact Assessment be needed for location data?
A DPIA under Article 35 is generally required where processing is likely to result in a high risk to individuals, and systematic or large-scale tracking of location can fall within that category, particularly where it enables monitoring of movement or behaviour. Supervisory authorities may publish lists of processing operations that require a DPIA, and these can differ between member states. Assessing the need for a DPIA at the design stage, and documenting the outcome, is the prudent approach; the relevant regulator's current guidance should be checked.
How should retention and minimisation be handled for location data?
The data minimisation principle generally means collecting only the location data necessary for the defined purpose, at the lowest precision and frequency that meets that need, and retaining it no longer than necessary. Practical measures often include setting purpose-specific retention periods, deleting or aggregating raw location traces once the purpose is served, and considering privacy-enhancing techniques where appropriate. Because retention expectations can be shaped by sector-specific rules and regulator guidance, retention schedules should be justified against the stated purposes and reviewed periodically.

Common misconceptions

Consent is always required to process location data.
Consent is one of several Article 6 legal bases; contract, legitimate interests, legal obligation, vital interests, or public task may apply depending on context. Separately, where location data is collected via information stored on or read from a device, national ePrivacy rules implementing the ePrivacy Directive may impose their own consent requirements, which can differ from the GDPR position and vary by member state.
Aggregated or 'anonymised' location data is automatically outside the GDPR.
Data is only outside scope if it is genuinely anonymous, meaning individuals are not identifiable by any means reasonably likely to be used. Location traces are frequently distinctive and can be re-identified, so an anonymisation claim should be tested through assessment rather than assumed.
Location data is ordinary personal data and never triggers Article 9 conditions.
Location data can reveal special category information (for example, visits that indicate health, religious belief, or trade union membership). Where it reveals such data, an additional Article 9 condition is generally required alongside the Article 6 basis. Whether Article 9 is engaged depends on the specific data and inferences involved.

Best practices

Identify the applicable legal basis under Article 6 before processing, and assess separately whether the data reveals special category information requiring an Article 9 condition; do not default to consent without confirming it is the appropriate basis.
Check whether national ePrivacy rules apply to the collection of location information from a device, as these may impose distinct consent obligations that operate alongside the GDPR and can vary between member states.
Collect location data at the lowest granularity and shortest retention period necessary for the stated purpose, applying data minimisation and proportionality to reduce risk.
Where high-risk processing is likely, such as systematic tracking or large-scale monitoring, conduct a Data Protection Impact Assessment under Article 35 and document the necessity and proportionality assessment.
Test any anonymisation or aggregation claim against re-identification risk rather than assuming location traces are anonymous, and treat residual re-identification risk as bringing the data back within scope.
Map controllers, processors, and any third-party SDKs or network sources involved in collection, and put in place appropriate Article 28 arrangements with processors, verifying against the current official text where specific obligations apply.