LiMP VPN
← All news

Google Fined €403M Over Location Tracking in EU

Google Fined €403M Over Location Tracking in EU

In short: On September 21, 2026, Ireland's Data Protection Commission (DPC) — Google's lead GDPR regulator in the EU — fined Google Ireland Limited €403 million following a six-year inquiry into how it processes location data across Web & App Activity, Location History, and Location Accuracy. The DPC found four separate GDPR violations: unlawful processing, a failure of accountability, insufficient transparency, and excessive data retention. Google must bring its practices into compliance within six months.

What Irish regulators found

The DPC's inquiry began in February 2020, prompted by complaints from consumer organizations including the European consumer group BEUC about how Google collects and retains location data across Android and its other services. Over the six-year investigation, the regulator examined how three interconnected mechanisms actually work: Web & App Activity logging, Location History, and the location-accuracy feature.

The final decision documents four distinct GDPR breaches. First, Google lacked a lawful basis for part of its location-data processing. Second, the company failed to demonstrate accountability to the regulator — it could not show that its own data-processing systems were built to comply with the law. Third, users weren't given sufficient transparency about exactly what data was being collected and for what purpose. Fourth, the data was retained longer than the processing purposes justified.

Why €403 million specifically

The figure makes this the fourth-largest fine in the DPC's history — the agency is the EU's lead regulator for Google, Meta, and other tech giants headquartered in Ireland. The European Data Protection Board (EDPB), which coordinates GDPR enforcement across EU member states, confirmed the DPC's decision and issued its own statement on the inquiry's outcome.

Google isn't just required to pay the fine — it must also bring its location-data processing into compliance with GDPR within six months, meaning it has to change the actual mechanisms for collecting, storing, and disclosing users' location information, not merely issue compensation.

What this means for an ordinary user

For anyone using an Android phone, Google Maps, Search, or other Google services, the fine doesn't automatically change anything or delete data already collected. But the decision establishes an officially recognized fact: for years, some location data was retained longer than necessary and without sufficient transparency about what was actually happening with it. Location history is one of the most sensitive categories of personal data — it can reveal where someone lives, works, who they meet, and where they travel privately.

The fine doesn't remove the need to check and limit what location data you hand over to services yourself. For more on how advertising identifiers track you and why to disable them, see our piece on how ad tracking IDs follow you across apps.

How to limit location data collection in practice

  • Turn off Location History in your Google Account settings (myactivity.google.com) if you don't rely on it for specific features like trip history in Maps.
  • Restrict app location permissions on your phone to "only while using the app" instead of "always."
  • Periodically review and delete your activity history — Google lets you export and erase accumulated data manually; our guide on deleting your data from the internet walks through the process.
  • Encrypt your network traffic separately from your account privacy settings. LiMP VPN hides your device's real IP address from websites and network observers, but it cannot change what Google's own services learn about your location through GPS and Wi-Fi when those permissions and features are enabled by the user — these are different, complementary layers of privacy protection.

Sources