Phone us
Location data can reveal far more than where someone happens to be. This article looks at what Google’s €403 million GDPR fine means for organisations, and the practical lessons around data minimisation, retention, transparency and privacy governance.

Location data can appear deceptively simple. A latitude, longitude, postcode or device location may seem relatively innocuous in isolation. But when those data points are collected repeatedly and combined over time, they can reveal considerably more.

Location information can indicate where a person lives and works, which businesses they visit, where they spend their time, which healthcare facilities they attend and where they travel. Repeated location data can therefore build a detailed picture of an individual’s movements and routines.

That sensitivity is at the centre of a major European data protection decision. On 21 September 2026, Ireland’s Data Protection Commission (DPC) announced that it had fined Google Ireland Limited €403 million following an investigation into the company’s processing of location data.

The inquiry examined three Google features, Web & App Activity, Location History and Location Accuracy, covering processing between 25 May 2018 and 4 February 2020. The regulator found infringements relating to lawfulness and fairness, accountability, transparency and the retention of location information. Google has also been ordered to bring the relevant processing into compliance with the GDPR within six months.

Google has said the decision concerns policies and systems that are now more than six years old and that it has since introduced significant changes, including enhanced controls, automatic deletion options and reduced use of precise location information. The company has indicated that it disagrees with aspects of the decision.

The case concerns one of the world’s largest technology companies, but the lessons apply much more widely. Organisations need to understand what location information they hold, what it can reveal when combined, why it is being collected and how long it genuinely needs to be retained.

What Did the Irish Data Protection Commission Find?

The DPC launched its inquiry in February 2020 following complaints from several European consumer organisations, including BEUC. The inquiry examined location processing associated with three Google services:

  • Web & App Activity can record activity across Google services, including browsing history, search activity and certain location information.
  • Location History records a user’s location over time and can infer information such as places visited, activities and routes travelled.
  • Location Accuracy is an Android feature designed to improve the precision with which a device determines its location beyond relying purely on GPS.

The DPC concluded that Google infringed GDPR requirements relating to the lawfulness and fairness of location processing associated with Web & App Activity and Location History.

It also found failures relating to transparency across all three features, accountability in relation to Location Accuracy and the length of time certain location information was retained.

The regulator has not yet published its full decision, so further detail about its reasoning is still expected. However, the DPC’s announcement already highlights several important governance issues for organisations handling location and behavioural data.

Location Data Is More Than a Point on a Map

A single record showing that a person was in central London at midday may reveal very little. A dataset showing their location repeatedly over several months can reveal a clear pattern.

An organisation may be able to infer where someone lives because a device remains at the same location overnight, or where they work because they regularly attend the same location during working hours. Repeated visits to a hospital, fertility clinic, addiction treatment service, place of worship, political event or trade union office may reveal considerably more.

Those conclusions do not necessarily need to exist explicitly in the original dataset. They can emerge when information is combined and analysed over time.

For organisations, the important point is that privacy risk does not always sit within an individual data field. Context and patterns matter.

Ordinary Data Can Produce Sensitive Inferences

Location data is not automatically classed as special category data simply because it records where somebody has been.

However, analysis of location information can potentially reveal or enable inferences about sensitive matters such as health, religious belief or political activity.

The same principle applies beyond geolocation. Browsing history can indicate health concerns. Purchase records can suggest religious practice. Workforce access logs can reveal employee behaviour. Customer analytics can provide insight into financial circumstances or vulnerability.

The important question for leadership is therefore not simply:

What information do we collect?

It is also:

What could somebody reasonably learn about a person by combining the information we hold?

Data Minimisation Starts With Purpose

Under the UK GDPR, organisations must ensure that personal information is adequate, relevant and limited to what is necessary for the purpose for which it is processed.

Modern technology makes it increasingly easy to collect more information than is actually required. Mobile applications can request location access. Websites can collect device information. Company systems can record user activity. Vehicles and physical devices can generate telemetry. Employee systems can record logins and access locations.

Just because information can be collected does not mean it should be.

A useful governance question is:

What would stop working if we stopped collecting this information?

If nobody can provide a clear answer, the organisation should reconsider why the collection exists.

There may be a legitimate purpose. Location information can be essential for delivery services, workforce safety, fraud detection, navigation, asset management or location-based functionality.

The issue is whether the amount and precision of information being collected are proportionate to that purpose.

Precision Matters

There is a considerable difference between knowing that somebody is in the United Kingdom and knowing that they are standing within a few metres of a particular address.

The more precise the information becomes, the more useful it may be, but it can also become more intrusive.

An organisation attempting to determine whether a service is available within a particular region may not require exact GPS coordinates. A website personalising content based on country may not need street-level location. A fraud-detection system may need geographic information without retaining a complete historical trail.

Organisations should therefore consider not only whether location data is necessary, but also whether the level of precision is proportionate to the purpose.

If approximate location can achieve the same outcome, collecting precise coordinates may create unnecessary privacy risk.

Retention Was a Central Part of the Google Decision

The DPC specifically identified Google’s retention of location data associated with Web & App Activity and Location History as an infringement. The regulator said that retaining location information for longer than necessary aggravated the loss of control experienced by individuals.

Retention remains an area where organisations can struggle with data protection.

Information may be collected for a legitimate purpose but remain long after that purpose has ended. Cheap storage and the possibility that historic information might be useful in future can encourage organisations to retain data without actively reconsidering whether it is still needed.

Data that remains indefinitely simply because nobody has made an active decision to remove it is not a retention strategy.

“We Might Need It One Day” Is Not a Retention Period

The ICO’s storage limitation guidance states that personal information should not be kept for longer than it is needed.

The UK GDPR does not prescribe one universal retention period. An organisation may legitimately need one type of record for seven years and another for seven days.

What matters is being able to explain why.

A useful retention rationale should connect directly to the purpose:

  • Why do we need this information?
  • For how long does that need continue?
  • Is there a legal or contractual requirement?
  • Would aggregated or anonymised information meet the purpose once identifiable data is no longer necessary?
  • When should the information be deleted?

If the answer is simply that storage is inexpensive or somebody may find the data useful in future, the organisation should reconsider whether continued retention is appropriate.

Retention Is Also a Cyber Security Control

Retention is also a cyber security issue.

Information that no longer exists cannot be stolen in a future breach.

Two organisations may suffer the same technical compromise, but the consequences can be very different if one holds years of unnecessary historical data while the other routinely removes information it no longer needs.

Data minimisation and appropriate retention can therefore reduce both privacy risk and the amount of information potentially exposed during a cyber incident.

Where data no longer provides a legitimate business benefit and there is no legal reason to retain it, keeping it creates additional risk.

Retention Schedules Need to Work in Practice

Many organisations already have retention policies.

That does not necessarily mean their information is actually being deleted.

Organisations should understand what happens inside their systems:

  • Does deletion occur automatically?
  • Are backups and archives included?
  • Does the CRM system follow the schedule?
  • What happens to exported spreadsheets or data warehouses?
  • Do third-party processors retain their own copies?
  • Could copies remain within email inboxes or shared folders?

The ICO specifically recommends having mechanisms to ensure retention periods are actually followed, rather than simply documenting them.

Retention therefore needs to be treated as a practical systems-governance issue, not simply a policy exercise.

Transparency Is About Understanding, Not Just Disclosure

The DPC also found transparency infringements relating to all three Google features examined by its inquiry.

Transparency requires more than publishing a privacy notice.

Under UK data protection rules, individuals should be told why their information is being processed, how long it will be retained, who it may be shared with and other relevant details. That information needs to be concise, intelligible, accessible and written in clear language.

If location information is being used for several purposes, describing the processing simply as “improving our services” may not give people a meaningful understanding of what is actually happening.

Individuals should be able to understand what information is being collected, why it is needed, how it will be used and how long it will be retained.

A privacy notice may be technically accurate but still fail to provide meaningful transparency if people cannot easily understand what the organisation is doing with their information.

Complex Processing Needs Better Communication, Not More Legal Language

A lengthy privacy policy may contain all the required information but still fail to give individuals a clear understanding of how their data is being used.

The ICO recommends approaches including layered privacy information, dashboards and just-in-time notices to present relevant information at appropriate points in the user journey.

For location data, organisations could explain why access is required at the point the user is asked to enable it.

For example:

  • What information will be collected?
  • Is the location precise or approximate?
  • Will collection continue in the background?
  • What will the information be used for?
  • How long will it be retained?
  • Can the user later disable it?

Good transparency provides individuals with relevant information at the point when it is most useful.

Accountability Means Being Able to Prove the Decision

The DPC decision also highlights the importance of accountability.

Organisations must not only comply with data protection requirements, but be able to demonstrate how and why key decisions were made.

A regulator may ask:

  • Why was this lawful basis selected?
  • Who approved it?
  • How was necessity assessed?
  • What alternatives were considered?
  • Where is the Data Protection Impact Assessment?
  • What did you tell individuals?
  • Why was a particular retention period selected?
  • When was the arrangement last reviewed?

If those decisions exist only in someone’s head, the organisation has an accountability problem.

This is particularly important for processing that could be intrusive or difficult for individuals to understand.

A DPIA Should Challenge the Business Case

Location tracking is the type of processing that may require careful privacy-risk assessment.

A Data Protection Impact Assessment should not simply document a decision that has already been made. It should test whether the proposed processing is genuinely necessary and proportionate.

Questions might include:

  • Do we actually need location information?
  • Does it need to be precise?
  • Does collection need to be continuous?
  • Could the service work with less data?
  • What could somebody infer from it?
  • What happens if the dataset is breached?
  • How long should the information remain identifiable?
  • Can individuals reasonably expect this processing?

Used properly, a DPIA can help organisations achieve their business objectives while identifying ways to reduce unnecessary privacy risks.

Location Data Is Relevant to More Organisations Than They May Think

It would be easy to view the Google decision as relevant mainly to technology companies and mobile-app developers.

In reality, location information appears across numerous sectors.

Employers may collect location information from corporate mobile devices, vehicles, access-control systems or remote-working tools. Retailers may use location-based marketing. Financial institutions can use geographic signals to detect suspicious transactions. Delivery and logistics companies track drivers, vehicles and packages. Security systems may record the geographic origin of authentication attempts.

Even ordinary website analytics can potentially provide information about visitors’ approximate locations.

The precise legal and operational risks will differ considerably between these uses, but every organisation should know whether location data exists within its information environment.

Employee Location Tracking Requires Particular Care

Workplace technologies deserve particular consideration because the relationship between employer and employee can affect how intrusive monitoring is perceived.

Tracking a lone worker for safety purposes may be justified. Continuously recording the precise location of every employee throughout the working day simply because the technology allows it raises very different questions.

Employers should distinguish clearly between legitimate operational needs and monitoring that has expanded beyond its original purpose.

Questions to consider include:

  • Could approximate location achieve the same outcome?
  • Does tracking need to continue outside working hours?
  • Who can access the information?
  • How long is it retained?
  • Can employees see what is collected?
  • What happens if location information is later used for disciplinary or performance purposes?

The more uses that are added after collection begins, the more complex the governance becomes.

Purpose Creep Is Easy When Data Is Valuable

Location information can become increasingly valuable once an organisation possesses it.

Information originally collected to provide a service may later appear useful for marketing, profiling, analytics or other business activities.

This is commonly described as purpose creep.

UK data protection rules require organisations to be clear about their purposes from the beginning and to consider whether reuse for a different purpose is compatible with the original purpose.

Commercial value alone does not make a new use appropriate.

Organisations therefore need change-control processes around the use of personal information, just as they have change-control processes around technology.

What Should Boards and Senior Leaders Be Asking?

Senior leadership does not need to understand how GPS triangulation works or review every line of a privacy notice.

It should, however, have assurance that higher-risk data processing is being governed appropriately.

Following the Google decision, useful questions include:

  • What location information do we collect about customers, employees, visitors or devices?
  • Why do we collect it?
  • Is the level of precision genuinely necessary?
  • What can be inferred when datasets are combined?
  • How long do we retain the information?
  • Is deletion actually taking place?
  • Are individuals clearly informed about its use?
  • Have appropriate DPIAs been completed?
  • Who owns decisions about new uses of existing data?

The aim is not for boards to manage day-to-day privacy activity, but to ensure that appropriate governance, ownership and assurance are in place.

The Question Is Not Just What Data You Have

Google has stressed that the DPC investigation concerns historical practices and that its systems and controls have since changed. The regulator’s full decision is also still to be published, and Google may challenge aspects of the outcome.

The wider lesson for organisations is that collecting data creates an ongoing responsibility.

Personal information needs to be protected. Its use needs to remain consistent with the purpose for which it was collected. Access needs to be controlled. Individuals need appropriate information. Retention needs to be reviewed and new uses need to be governed.

Location data demonstrates this particularly clearly.

A single location record may reveal very little, but repeated location data can build a detailed picture of an individual’s movements and routines.

For leadership teams, the broader principle is straightforward:

Do not assess personal information solely by looking at the individual fields you collect. Consider what the dataset as a whole can reveal.

Where information no longer serves a legitimate business or legal purpose, organisations should consider whether it should be deleted.

How AJC Can Help

AJC supports organisations with data protection, privacy governance and information risk.

Our team can assist with GDPR compliance reviews, Data Protection Impact Assessments, retention and deletion practices, privacy notices and the governance of higher-risk processing.

We can also help businesses understand what personal information they hold, identify potential privacy risks and ensure appropriate controls and oversight are in place.

Please contact us on 020 7101 4861 or email info@ajollyconsulting.co.uk if you think we can help.

 

Sources:

https://www.dataprotection.ie/en/news-media/latest-news/data-protection-commission-fines-google-eu403-million-following-inquiry-googles-processing-location

https://www.reuters.com/business/media-telecom/irish-regulator-fines-google-403-million-over-location-data-processing-2026-09-21/

https://www.bbc.co.uk/news/articles/ck1e52v16ngxo

https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/

https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/data-minimisation/

https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/storage-limitation/

https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/lawfulness-fairness-and-transparency/

https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/the-right-to-be-informed/

https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/purpose-limitation

Image accreditation: Googleplex Headquarters (2016) from Wikimedia Commons. Last accessed on 1 October 2026. Available at: https://commons.wikimedia.org/wiki/File:Googleplex_HQ_(cropped).jpg

In case you missed it...

AJC Achieves ISO 27001 Certification

AJC is pleased to announce that it has achieved ISO 27001 certification, recognising the robust information security processes and controls...

Read More
prepare cyber resilience act
Why Businesses Need to Prepare for...

The main requirements of the EU Cyber Resilience Act come into effect in December 2027. While that may still sound...

Read More
revolut data breach
Revolut Data Breach: Why Official Email...

A recent Revolut data breach has highlighted the risks of relying on apparently legitimate email requests for sensitive information. This...

Read More

Get in touch

    By submitting this form you are consenting that your data be handled in accordance with our Privacy Notice and we will be in touch regarding your enquiry.