Ireland's Data Protection Commission (DPC) has fined Google 403 million euros after finding the company infringed the EU's General Data Protection Regulation through its handling of location data. The penalty, one of the largest GDPR enforcement actions to date, closes an inquiry that began in February 2020 and covers Google's conduct between May 2018 and February 2020. For anyone who relies on privacy tools like a VPN to protect their whereabouts online, the case is a useful reminder that a VPN and your phone's location settings are solving two very different problems.
What the Irish Data Protection Commission Found
According to the DPC's final decision, Google infringed GDPR "in respect of the lawfulness and fairness of its processing of location" data. The regulator opened its inquiry in February 2020 and spent years examining how Google collected, stored, and used location information tied to user accounts and devices during the period in question. The 403 million euro penalty reflects the DPC's conclusion that Google's practices did not meet GDPR's core requirements around lawful and fair data processing, which generally means users must be given clear, meaningful choices about whether and how their location is tracked, not buried defaults or confusing settings.
As the primary EU regulator for Google under GDPR's "one-stop-shop" mechanism (Google's European headquarters are in Ireland), the DPC has jurisdiction over the company's data practices across the entire bloc. That makes this decision binding EU-wide, not just for Irish users.
A Pattern of Location-Privacy Penalties Under GDPR
This is not the first time a large tech company has been penalized over how it handles location data, and location tracking has repeatedly proven to be one of the thorniest areas of GDPR enforcement. Location history is uniquely sensitive: it can reveal where someone lives, works, worships, seeks medical care, or spends time with specific people. Regulators have consistently scrutinized whether companies obtain genuine, informed consent before collecting this kind of data, rather than relying on default settings users may never realize they agreed to.
It's worth putting the size of this fine in context. GDPR's theoretical maximum penalty is 20 million euros or 4 percent of a company's global annual turnover, whichever is higher. For a company the size of Google, that ceiling is enormous, and most fines issued under GDPR fall well short of it. Our explainer on why the GDPR fine cap rarely applies breaks down how regulators actually calculate penalties in practice, which helps explain why a 403 million euro fine, while headline-grabbing, still represents a fraction of what GDPR technically allows.
What a VPN Does and Doesn't Hide About Your Location
Cases like this one often prompt readers to ask whether a VPN would have prevented this kind of tracking. The honest answer is no, and understanding why matters. A VPN encrypts your internet traffic and masks your IP address, which can obscure your general geographic location from your internet provider, network snoopers, and some websites that rely on IP-based location estimates.
But a VPN has no effect on location data collected through other channels, including GPS signals, Wi-Fi and Bluetooth scanning, cell tower triangulation, or account-level settings baked into an operating system or app. If a phone's location services are switched on and an app or account has permission to access them, that data can still be collected and processed regardless of whether a VPN is running in the background. In other words, a VPN protects your network-level location from external observers, but it does not touch the location data your device and its apps generate and share directly.
Locking Down Location Tracking on Android and Google Accounts
Because GDPR enforcement targets how companies configure defaults and consent flows, the most effective protection for individual users is reviewing those settings directly rather than assuming a VPN covers the gap. A few practical steps:
- Open your device's location settings and check which apps have "always allow" location access versus "only while using the app," and revoke access for anything that doesn't need it.
- Review your Google Account's activity controls to see whether location history is enabled, and turn it off or set it to auto-delete after a shorter period.
- Periodically audit app permissions, since apps sometimes request location access for features you no longer use.
- Consider disabling Wi-Fi and Bluetooth scanning when not actively connecting to devices, since these can be used to estimate location even with GPS off.
What This Means For You
This fine is a regulatory outcome, not a data breach, but it underscores a broader point: location privacy is largely determined by account and device settings, not by network-level tools. If you use a VPN because you care about who can see your location, that's a reasonable instinct, but it should be paired with a regular check of the permissions and history settings tied to your phone and accounts. The two approaches address different threats, and neither substitutes for the other.
The 403 million euro figure is significant, but as with most GDPR cases, it falls short of the regulation's maximum possible penalty, a gap worth understanding before assuming any fine reflects the full scale of enforcement power regulators actually hold.
Actionable takeaways:
- Audit which apps on your phone have location permissions and remove access you don't recognize or need.
- Check your Google Account's location history and activity controls, and adjust auto-delete settings if you haven't already.
- Remember that a VPN protects your network location, not GPS or account-based location data, so use both tools deliberately rather than relying on one alone.
- Revisit these settings periodically, since app updates and new installs can quietly re-request location access.




