European regulators fined Google €403 million in September 2026 for unlawfully tracking users' location data without valid consent. The ruling affects Android users and advertisers across the EU and signals stricter GDPR enforcement for data-driven business models.
European data protection authorities announced a €403 million fine against Google on September 22, 2026, concluding a multi-year investigation into the company's location tracking practices. Regulators determined that Google continued collecting and processing precise location data from Android devices even after users disabled location history settings.
The investigation found that Google's "Web & App Activity" setting remained active by default on Android devices. Even when users proactively turned off "Location History," Google continued to record location data through other service settings without adequately informing users or obtaining valid consent. This practice violated core GDPR principles including transparency, purpose limitation, and data minimization.
Regulators specifically cited that Google's consent mechanism did not provide users with genuine choice. The multiple layers of settings, pre-ticked boxes, and opaque privacy controls made it effectively impossible for users to understand and control how their location data was being processed.
The ruling directly affects Android users across the European Economic Area (EEA) whose location data was collected without lawful basis. Estimates suggest hundreds of millions of users may have had location data processed improperly between 2018 and 2025.
Advertisers and businesses relying on Google's location-based advertising products also face indirect impacts. The enforcement action may force Google to modify its ad targeting infrastructure in the EU, reducing available location-based audience segmentation and bidding signals.
The decision also affects the broader technology sector by setting a clear precedent: default-enabled tracking features that require users to navigate complex settings to opt out will not satisfy GDPR consent requirements.
The magnitude of this fine—the second-largest GDPR penalty ever imposed—demonstrates that European regulators are intensifying enforcement against systemic privacy violations by large technology platforms. Key compliance takeaways include:
Google's use of a single "I agree" action covering multiple data processing purposes violated GDPR Article 7. Organizations must obtain separate, granular consent for distinct processing activities, particularly location tracking.
GDPR Article 25 requires data protection by design and by default. Default-on tracking settings that require user action to disable are fundamentally incompatible with this requirement. Location services must be opt-in by default.
Vague privacy policies that bury location tracking disclosures across multiple documents do not meet GDPR transparency standards. Users must be clearly informed what data is collected, why, and how to control it.
The fine resulted from coordinated action by multiple EU supervisory authorities, signaling that the GDPR's one-stop-shop mechanism is now functioning effectively for large-scale cases.
Review all data collection features that are enabled by default, especially location services, analytics, and advertising identifiers. Document the legal basis for each processing activity and verify that default settings align with privacy-by-default requirements.
Implement granular consent mechanisms that separate location tracking from other data processing purposes. Remove pre-ticked boxes and require affirmative, unambiguous opt-in action for location data.
Identify all settings and features that may collect location data indirectly. Google's violation stemmed from one setting capturing data even when another was disabled. Conduct a comprehensive data flow mapping exercise.
Rewrite privacy policies in plain language that specifically explains location data practices. Users should understand exactly when their location is collected, how long it is retained, and who it is shared with.
Data protection authorities across the EU are likely to apply similar standards to other mobile operating systems, apps, and platforms. Organizations should proactively close compliance gaps before facing enforcement.
The €403 million fine against Google represents a watershed moment for location data compliance under GDPR. It establishes that complex, multi-layered privacy settings cannot substitute for genuine consent, and that default-enabled tracking is categorically unacceptable. Organizations processing location data—whether through mobile apps, IoT devices, or advertising platforms—must prioritize transparent consent mechanisms and privacy-by-default design to mitigate regulatory risk.
Google was fined €403 million because Android devices continued collecting precise location data through 'Web & App Activity' even after users disabled 'Location History,' without valid GDPR consent or adequate transparency.
Yes. GDPR requires privacy by default under Article 25. Location tracking must be opt-in by default, with specific, granular, and freely given consent obtained before any location data is collected.
Companies should disable location tracking by default, implement granular consent flows, map all data collection points, rewrite privacy notices in plain language, and regularly audit settings to prevent indirect data collection.
The largest GDPR fine issued to date is €1.2 billion against Meta in 2023 for unlawful transfers of EU user data to the United States, with Google's €403 million location tracking fine among the top penalties.
Yes. Under GDPR Article 82, individuals who suffered material or non-material damage from unlawful data processing have the right to seek compensation through EU courts or representative actions by non-profit organizations.
PoliWriter creates all the policies and documentation you need for compliance, customized to your organization. AI-powered, audit-ready, hours not months.
Get Started Free