AJC Achieves ISO 27001 Certification
AJC is pleased to announce that it has achieved ISO 27001 certification, recognising the robust information security processes and controls...
Read MoreLocation data can appear deceptively simple. A latitude, longitude, postcode or device location may seem relatively innocuous in isolation. But when those data points are collected repeatedly and combined over time, they can reveal considerably more.
Location information can indicate where a person lives and works, which businesses they visit, where they spend their time, which healthcare facilities they attend and where they travel. Repeated location data can therefore build a detailed picture of an individual’s movements and routines.
That sensitivity is at the centre of a major European data protection decision. On 21 September 2026, Ireland’s Data Protection Commission (DPC) announced that it had fined Google Ireland Limited €403 million following an investigation into the company’s processing of location data.
The inquiry examined three Google features, Web & App Activity, Location History and Location Accuracy, covering processing between 25 May 2018 and 4 February 2020. The regulator found infringements relating to lawfulness and fairness, accountability, transparency and the retention of location information. Google has also been ordered to bring the relevant processing into compliance with the GDPR within six months.
Google has said the decision concerns policies and systems that are now more than six years old and that it has since introduced significant changes, including enhanced controls, automatic deletion options and reduced use of precise location information. The company has indicated that it disagrees with aspects of the decision.
The case concerns one of the world’s largest technology companies, but the lessons apply much more widely. Organisations need to understand what location information they hold, what it can reveal when combined, why it is being collected and how long it genuinely needs to be retained.
The DPC launched its inquiry in February 2020 following complaints from several European consumer organisations, including BEUC. The inquiry examined location processing associated with three Google services:
The DPC concluded that Google infringed GDPR requirements relating to the lawfulness and fairness of location processing associated with Web & App Activity and Location History.
It also found failures relating to transparency across all three features, accountability in relation to Location Accuracy and the length of time certain location information was retained.
The regulator has not yet published its full decision, so further detail about its reasoning is still expected. However, the DPC’s announcement already highlights several important governance issues for organisations handling location and behavioural data.
A single record showing that a person was in central London at midday may reveal very little. A dataset showing their location repeatedly over several months can reveal a clear pattern.
An organisation may be able to infer where someone lives because a device remains at the same location overnight, or where they work because they regularly attend the same location during working hours. Repeated visits to a hospital, fertility clinic, addiction treatment service, place of worship, political event or trade union office may reveal considerably more.
Those conclusions do not necessarily need to exist explicitly in the original dataset. They can emerge when information is combined and analysed over time.
For organisations, the important point is that privacy risk does not always sit within an individual data field. Context and patterns matter.
Location data is not automatically classed as special category data simply because it records where somebody has been.
However, analysis of location information can potentially reveal or enable inferences about sensitive matters such as health, religious belief or political activity.
The same principle applies beyond geolocation. Browsing history can indicate health concerns. Purchase records can suggest religious practice. Workforce access logs can reveal employee behaviour. Customer analytics can provide insight into financial circumstances or vulnerability.
The important question for leadership is therefore not simply:
What information do we collect?
It is also:
What could somebody reasonably learn about a person by combining the information we hold?
Under the UK GDPR, organisations must ensure that personal information is adequate, relevant and limited to what is necessary for the purpose for which it is processed.
Modern technology makes it increasingly easy to collect more information than is actually required. Mobile applications can request location access. Websites can collect device information. Company systems can record user activity. Vehicles and physical devices can generate telemetry. Employee systems can record logins and access locations.
Just because information can be collected does not mean it should be.
A useful governance question is:
What would stop working if we stopped collecting this information?
If nobody can provide a clear answer, the organisation should reconsider why the collection exists.
There may be a legitimate purpose. Location information can be essential for delivery services, workforce safety, fraud detection, navigation, asset management or location-based functionality.
The issue is whether the amount and precision of information being collected are proportionate to that purpose.
There is a considerable difference between knowing that somebody is in the United Kingdom and knowing that they are standing within a few metres of a particular address.
The more precise the information becomes, the more useful it may be, but it can also become more intrusive.
An organisation attempting to determine whether a service is available within a particular region may not require exact GPS coordinates. A website personalising content based on country may not need street-level location. A fraud-detection system may need geographic information without retaining a complete historical trail.
Organisations should therefore consider not only whether location data is necessary, but also whether the level of precision is proportionate to the purpose.
If approximate location can achieve the same outcome, collecting precise coordinates may create unnecessary privacy risk.
The DPC specifically identified Google’s retention of location data associated with Web & App Activity and Location History as an infringement. The regulator said that retaining location information for longer than necessary aggravated the loss of control experienced by individuals.
Retention remains an area where organisations can struggle with data protection.
Information may be collected for a legitimate purpose but remain long after that purpose has ended. Cheap storage and the possibility that historic information might be useful in future can encourage organisations to retain data without actively reconsidering whether it is still needed.
Data that remains indefinitely simply because nobody has made an active decision to remove it is not a retention strategy.
The ICO’s storage limitation guidance states that personal information should not be kept for longer than it is needed.
The UK GDPR does not prescribe one universal retention period. An organisation may legitimately need one type of record for seven years and another for seven days.
What matters is being able to explain why.
A useful retention rationale should connect directly to the purpose:
If the answer is simply that storage is inexpensive or somebody may find the data useful in future, the organisation should reconsider whether continued retention is appropriate.
Retention is also a cyber security issue.
Information that no longer exists cannot be stolen in a future breach.
Two organisations may suffer the same technical compromise, but the consequences can be very different if one holds years of unnecessary historical data while the other routinely removes information it no longer needs.
Data minimisation and appropriate retention can therefore reduce both privacy risk and the amount of information potentially exposed during a cyber incident.
Where data no longer provides a legitimate business benefit and there is no legal reason to retain it, keeping it creates additional risk.
Many organisations already have retention policies.
That does not necessarily mean their information is actually being deleted.
Organisations should understand what happens inside their systems:
The ICO specifically recommends having mechanisms to ensure retention periods are actually followed, rather than simply documenting them.
Retention therefore needs to be treated as a practical systems-governance issue, not simply a policy exercise.
The DPC also found transparency infringements relating to all three Google features examined by its inquiry.
Transparency requires more than publishing a privacy notice.
Under UK data protection rules, individuals should be told why their information is being processed, how long it will be retained, who it may be shared with and other relevant details. That information needs to be concise, intelligible, accessible and written in clear language.
If location information is being used for several purposes, describing the processing simply as “improving our services” may not give people a meaningful understanding of what is actually happening.
Individuals should be able to understand what information is being collected, why it is needed, how it will be used and how long it will be retained.
A privacy notice may be technically accurate but still fail to provide meaningful transparency if people cannot easily understand what the organisation is doing with their information.
A lengthy privacy policy may contain all the required information but still fail to give individuals a clear understanding of how their data is being used.
The ICO recommends approaches including layered privacy information, dashboards and just-in-time notices to present relevant information at appropriate points in the user journey.
For location data, organisations could explain why access is required at the point the user is asked to enable it.
For example:
Good transparency provides individuals with relevant information at the point when it is most useful.
The DPC decision also highlights the importance of accountability.
Organisations must not only comply with data protection requirements, but be able to demonstrate how and why key decisions were made.
A regulator may ask:
If those decisions exist only in someone’s head, the organisation has an accountability problem.
This is particularly important for processing that could be intrusive or difficult for individuals to understand.
Location tracking is the type of processing that may require careful privacy-risk assessment.
A Data Protection Impact Assessment should not simply document a decision that has already been made. It should test whether the proposed processing is genuinely necessary and proportionate.
Questions might include:
Used properly, a DPIA can help organisations achieve their business objectives while identifying ways to reduce unnecessary privacy risks.
It would be easy to view the Google decision as relevant mainly to technology companies and mobile-app developers.
In reality, location information appears across numerous sectors.
Employers may collect location information from corporate mobile devices, vehicles, access-control systems or remote-working tools. Retailers may use location-based marketing. Financial institutions can use geographic signals to detect suspicious transactions. Delivery and logistics companies track drivers, vehicles and packages. Security systems may record the geographic origin of authentication attempts.
Even ordinary website analytics can potentially provide information about visitors’ approximate locations.
The precise legal and operational risks will differ considerably between these uses, but every organisation should know whether location data exists within its information environment.
Workplace technologies deserve particular consideration because the relationship between employer and employee can affect how intrusive monitoring is perceived.
Tracking a lone worker for safety purposes may be justified. Continuously recording the precise location of every employee throughout the working day simply because the technology allows it raises very different questions.
Employers should distinguish clearly between legitimate operational needs and monitoring that has expanded beyond its original purpose.
Questions to consider include:
The more uses that are added after collection begins, the more complex the governance becomes.
Location information can become increasingly valuable once an organisation possesses it.
Information originally collected to provide a service may later appear useful for marketing, profiling, analytics or other business activities.
This is commonly described as purpose creep.
UK data protection rules require organisations to be clear about their purposes from the beginning and to consider whether reuse for a different purpose is compatible with the original purpose.
Commercial value alone does not make a new use appropriate.
Organisations therefore need change-control processes around the use of personal information, just as they have change-control processes around technology.
Senior leadership does not need to understand how GPS triangulation works or review every line of a privacy notice.
It should, however, have assurance that higher-risk data processing is being governed appropriately.
Following the Google decision, useful questions include:
The aim is not for boards to manage day-to-day privacy activity, but to ensure that appropriate governance, ownership and assurance are in place.
Google has stressed that the DPC investigation concerns historical practices and that its systems and controls have since changed. The regulator’s full decision is also still to be published, and Google may challenge aspects of the outcome.
The wider lesson for organisations is that collecting data creates an ongoing responsibility.
Personal information needs to be protected. Its use needs to remain consistent with the purpose for which it was collected. Access needs to be controlled. Individuals need appropriate information. Retention needs to be reviewed and new uses need to be governed.
Location data demonstrates this particularly clearly.
A single location record may reveal very little, but repeated location data can build a detailed picture of an individual’s movements and routines.
For leadership teams, the broader principle is straightforward:
Do not assess personal information solely by looking at the individual fields you collect. Consider what the dataset as a whole can reveal.
Where information no longer serves a legitimate business or legal purpose, organisations should consider whether it should be deleted.
AJC supports organisations with data protection, privacy governance and information risk.
Our team can assist with GDPR compliance reviews, Data Protection Impact Assessments, retention and deletion practices, privacy notices and the governance of higher-risk processing.
We can also help businesses understand what personal information they hold, identify potential privacy risks and ensure appropriate controls and oversight are in place.
Please contact us on 020 7101 4861 or email info@ajollyconsulting.co.uk if you think we can help.
Sources:
https://www.bbc.co.uk/news/articles/ck1e52v16ngxo
Image accreditation: Googleplex Headquarters (2016) from Wikimedia Commons. Last accessed on 1 October 2026. Available at: https://commons.wikimedia.org/wiki/File:Googleplex_HQ_(cropped).jpg
AJC is pleased to announce that it has achieved ISO 27001 certification, recognising the robust information security processes and controls...
Read MoreThe main requirements of the EU Cyber Resilience Act come into effect in December 2027. While that may still sound...
Read MoreA recent Revolut data breach has highlighted the risks of relying on apparently legitimate email requests for sensitive information. This...
Read More