All articles

Justify, disclose, prove, erase: the four failings behind Google’s €403 million fine

On 21 September 2026 the Irish data protection authority imposed administrative fines totalling €403 million on Google Ireland Limited over its processing of location data, and ordered the company to bring that processing into compliance within six months. The inquiry had been opened on the authority’s own initiative in February 2020, after complaints from several European consumer rights organisations including BEUC. It covered three location features between 25 May 2018, the date the GDPR became applicable, and 4 February 2020.

The figure is what will get attention. The list of findings deserves more of it. There are four, and they describe four things any mobile app that handles a position has to be able to do: justify the processing, disclose it, prove it, erase what no longer has a reason to exist.

Three features, and one of them needs no account

The decision covers three settings. The first, Web & App Activity, is a Google account setting: when it is on, it processes the user’s activity across Google services, sites and apps included, which can include browsing history, search history and location data.

The second, Location History, is a service the user has to opt into. It infers place visits, activities and the paths between those places, then shows them on a private map. The authority notes that it records where the user goes with their signed-in devices, even when the user is not using a Google service.

The third one is a different kind of thing altogether, and it is the one a publisher should read twice. Location Accuracy is a feature of the Android operating system that lets a device work out its position more precisely than the GPS unit alone allows. It is available to Android users whether or not they hold a Google account.

Three layers, then: an account setting, a service you opt into, an operating system feature. Reasoning that stops at the permission the user granted to the app misses all three, although the three bear on the same phone and the same person.

Four failings, and none of them is technical

The authority found four. The lawfulness and fairness of the processing of location data in Web & App Activity and Location History. Accountability, for failing to be able to demonstrate compliance with the lawfulness, fairness and transparency principle in respect of Location Accuracy. Transparency, across all three features. And the retention of location data in Web & App Activity and Location History.

All four are about the basis of the processing, what was said about it, what could be demonstrated about it, and how long the data was kept. Deputy Commissioner Graham Doyle summed up the effect on people: as a result of those failures, individuals could have been unaware that their location was being used, for example, to influence them with ads or to infer their interests, and could lose control over their personal data; retaining it for longer than necessary, he added, aggravated that loss of control.

On the Irish press’ count, it is the fourth largest fine the authority has issued since the GDPR became applicable. The authority says it will publish the full decision in due course. The four findings already work as a checklist.

Fairness, the failing decided on screen

Of the principles the decision names, fairness is the one publishers prepare for least, and it is where the case began. On 27 November 2018 seven consumer organisations coordinated by BEUC filed complaints with their national authorities, an eighth reporting the same practices in Denmark. All of them rested on a report by the Norwegian Consumer Council with an unambiguous title, “Every Step You Take: How deceptive design lets Google track users 24/7”.

That report was about screens. Deceptive design, misleading information and repeated pushing led Android users to leave tracking on. The complaint went to the way the choice was presented, screen by screen, and close to eight years later the decision finds against the fairness of the processing.

For a publisher the consequence is direct. An app’s consent window is a legal object as much as a revenue lever: the order of the buttons, their visual weight, the number of taps a refusal costs, the wording around the request. Those choices get judged, and they get judged years after they were made.

The most instructive failing: not being able to demonstrate

The accountability finding is of a different nature from the other three. The authority does not find the processing unlawful on that point. It finds that the company was not able to demonstrate that it was lawful, fair and transparent. That is the GDPR’s accountability principle in its barest form: the burden of proof sits with the controller, and its absence counts as a failing. Location Accuracy also carries a transparency finding: the accountability one adds to that, it does not replace it.

Carried over to a mobile app, that shifts the question. A record of processing, a privacy policy and a store listing state what the publisher believes the app does. What it actually does is readable on a phone, once installed. Between the two sit third-party SDKs, whose behaviour shows up neither in the publisher’s code nor in their documentation.

Retention, the failing nobody can see from outside

Retention is the easiest finding to overlook, because nothing makes it visible. An app does not show how long a recipient keeps what it was sent. The CNIL offers an example that speaks to any publisher: keeping a detailed history of a user’s movements for years, for a plain weather app, would be hard to justify.

The question comes up once per recipient. Every partner that receives a position keeps it under its own policy, and the publisher stays answerable for what it passed on. Answering therefore starts with the inventory that is almost always missing: where the position leaves the app, to whom, at what precision and at what moment.

Six years and seven months

The period examined stops on 4 February 2020, the day the authority announced it was opening the inquiry. The decision lands on 21 September 2026, six years and seven months later. Google’s answer is that the case concerns historical policies that have since been updated, and that its practices have evolved significantly since 2019. The Irish press reports that it intends to appeal.

BEUC, whose members lodged the complaints, welcomed the decision the same day while calling the time taken “disproportionate with the seriousness of the infringement”, its Director General Agustín Reyna adding that “late enforcement can be as harmful as no enforcement at all”.

That answer can be accurate and still change nothing about the period being judged. Compliance is not a current state, it is a dated one. What holds up years later comes down to a dated record of how each published version actually behaved, kept version after version.

The French framework already says the same thing

None of this is specific to Ireland or to very large platforms. All four requirements have their counterpart in French doctrine, which is written for app publishers. Justify: the CNIL requires consent as soon as the position is not strictly necessary to run the service, and states that an authorisation granted at operating system level does not amount to consent on its own. Disclose: the information given must name the recipients and the retention period. Prove: those duties bind the whole chain, the publisher as much as the partners receiving the data. Erase: the period must be defined and defensible against the purpose.

The French timetable has been running for two years: the recommendation on mobile apps published on 24 September 2024, an amended version on 8 April 2025, an inspection campaign launched in spring 2025, then the page of 7 July 2026 devoted to location data. What the authority expects on the position itself is covered in another article; what matters here is that a French publisher already sits inside the perimeter this decision has just drawn.

The four questions, asked of your app

Justify: on what basis does the position leave the phone, and does that basis hold for every recipient or only for the feature the user can see? Disclose: does what the privacy policy and the store listing announce match the actual recipients? Prove: what would you produce today if an inspector asked for the demonstration? Erase: what retention period applies, at your end and at the end of everyone who receives the data?

None of these four questions is settled by reading code, and none is settled without knowing what actually leaves the phone. You cannot check a declaration without observing it, you cannot produce a demonstration without a record, and you cannot apply a retention period to recipients you have not identified. That is the whole point of a mobile app analysis: it does not state the law, it supplies the dated evidence the law is applied to.

Sources

Every finding in this article traces back to one of these documents.

  1. DPC ’26Data Protection Commission fines Google €403 million following inquiry into its processing of location dataData Protection Commission (Ireland), 21 September 2026
  2. BEUC ’26Google fined for invasive location tracking after BEUC complaintBEUC, 21 September 2026
  3. BEUC ’18Every Step You Take: the coordinated complaints on Google location trackingBEUC and national consumer organisations, 27 November 2018
  4. BEUC ’18Model complaint filed with data protection authoritiesBEUC, November 2018
  5. CNIL ’26Location data and mobile apps: which rules protect usersCNIL, 7 July 2026
  6. CNIL ’25Recommendation on mobile apps, amended versionCNIL, 8 April 2025
  7. CNIL ’24Mobile apps: recommendations to better protect privacyCNIL, 24 September 2024
  8. Irish Times ’26Irish data protection watchdog fines Google €403m over GDPR breachesThe Irish Times, 21 September 2026
  9. TechCrunch ’20The Irish authority announces its statutory inquiryTechCrunch, 4 February 2020

Common questions

Why was Google fined by Ireland’s data protection authority?
Because the Irish authority is Google’s lead supervisory authority in the European Union, the group’s main European establishment being in Dublin. It ran the inquiry in that capacity, on cross-border processing, and says in its statement that it had the cooperation and assistance of its peer authorities under the European cooperation mechanism.
What was Google fined €403 million for?
Four failings, across three location features examined between 25 May 2018 and 4 February 2020: the lawfulness and fairness of the processing in Web & App Activity and Location History, a breach of the accountability principle for failing to be able to demonstrate compliance in respect of Location Accuracy, a transparency failing across all three features, and a retention failing in Web & App Activity and Location History. The fines total €403 million, with an order to bring the processing into compliance within six months.
How long can location data be kept in a mobile app?
The GDPR sets no figure: data must not be kept longer than is necessary for the purpose it was collected for, and that period has to be defined, documented and disclosed to users. The French authority illustrates the limit with a simple case: keeping a detailed movement history for years, for a plain weather app, would be hard to justify. The period also has to be assessed at each recipient of the data.
How do you prove what a mobile app does with location data?
By observing it run. Launch the app on a phone, record the recipients actually contacted, the data sent and the moment of each transmission relative to the user’s choice, then date that record. That record is what you put in front of an inspector; the register and the privacy policy are only declarations.

And the app you audit, what does it actually embed?