Our Expert in Ireland
No results available
Ireland’s Data Protection Commission (DPC) has become one of the most significant regulators in Europe for enforcement actions against technology companies handling location and behavioural data under the General Data Protection Regulation (GDPR). Where the DPC finds that a controller has breached core GDPR principles, lawfulness, fairness, transparency, retention and accountability, in relation to location data processed through features such as web and app activity tracking, location history and location accuracy, it can impose substantial administrative fines and issue corrective orders requiring the controller to bring its processing into compliance within a defined period.
For in-house counsel, data protection officers, privacy engineers, product managers and any business processing location or behavioural data across the EU/EEA, understanding how the DPC approaches these cases is a clear signal of regulatory expectations and the direction of enforcement. This article synthesises the DPC’s enforcement approach with the underlying GDPR framework and European Data Protection Board (EDPB) guidance, and delivers a practical remediation roadmap you can act on now.
DPC inquiries into location data frequently arise from the regulator’s own initiative as well as from complaints. Understanding the typical scope of what is examined, the legal provisions engaged, and the remedies available is the starting point for any controller assessing its own exposure.
A self-initiated DPC inquiry into location data will typically focus on how an organisation collects, uses and retains location information generated by its services. The features under scrutiny are commonly the settings and mechanisms through which a provider captures and processes users’ location signals, such as web and app activity records, location history, and location accuracy settings. Where the conduct spans a period beginning on or after 25 May 2018, the date the GDPR became applicable, the DPC assesses that conduct against the full weight of the Regulation.
This chronology matters. The features named above are not obscure back-end systems; they are consumer-facing settings that determine whether and how location trails, search and app interactions, and device telemetry are recorded. The DPC’s attention to these specific mechanisms underscores that regulatory scrutiny is directed at the everyday configurations that shape how much data is collected and for how long it is kept.
DPC findings in location-data cases typically map onto several foundational provisions of the GDPR. At the heart of such decisions are the data processing principles in Article 5, which require that personal data be processed lawfully, fairly and in a transparent manner in relation to the data subject (Article 5(1)(a)), that it be collected only for specified, explicit and legitimate purposes and minimised to what is necessary (Article 5(1)(b) and (c)), and that it be kept in a form permitting identification of data subjects for no longer than is necessary (the storage limitation principle in Article 5(1)(e)).
A finding on lawfulness engages Article 6, which requires a valid legal basis for every processing operation. Transparency findings connect to Articles 12 to 14, which govern the information that must be provided to data subjects and the manner in which it is communicated. An accountability finding, that a controller must be able to demonstrate compliance, flows from Article 5(2) and Article 24, which requires controllers to implement appropriate technical and organisational measures. Where high-risk processing is involved, Article 35 requires a Data Protection Impact Assessment (DPIA), and Article 32 sets the standard for security of processing. Together, these provisions form the legal architecture against which the DPC measures a controller’s conduct.
Under Article 83 of the GDPR, administrative fines must be effective, proportionate and dissuasive, and can reach up to 4% of an undertaking’s total worldwide annual turnover of the preceding financial year for the most serious infringements, or up to 2% for certain other infringements. Beyond a monetary penalty, the DPC can issue corrective orders under Article 58 requiring a controller to bring its processing operations into compliance within a defined window. This dual approach, financial sanction plus a mandated remediation window, is characteristic of GDPR enforcement, where the objective is not only to address past conduct but to compel forward-looking change.
Where a decision is published, controllers should read it carefully to understand the specific deficiencies identified and the paragraph-level reasoning.
The DPC’s approach to location and behavioural data is instructive for every organisation processing such information. Two threads commonly run through these decisions, prolonged retention and inadequate transparency, and both reflect risks that are widespread across the digital economy.
Prolonged retention of location data aggravates the loss of control experienced by individuals. This is a critical point of principle. Location data is among the most revealing categories of personal information: a continuous trail of where a person has been can disclose their home, workplace, place of worship, medical appointments and personal relationships. When such data is retained beyond what is necessary, the individual’s ability to exercise meaningful control over their digital footprint erodes with every passing day.
The storage limitation principle in Article 5(1)(e) is not a technicality. EU jurisprudence has long treated retention and proportionality as matters of fundamental-rights significance. In Digital Rights Ireland (Joined Cases C-293/12 and C-594/12), the Court of Justice of the European Union invalidated the Data Retention Directive precisely because indiscriminate, long-term retention of communications data was disproportionate to the objectives pursued. The principle that retention must be limited, justified and proportionate is deeply embedded in EU data protection law, and where the DPC treats retention as an aggravating factor it sits squarely within that tradition.
The transparency requirements address a persistent challenge for digital services: telling users, in plain and accessible language, what is being collected, why, and for how long. Articles 12 to 14 require that information be concise, transparent, intelligible and easily accessible, using clear and plain language. Where settings such as web and app activity, location history and location accuracy interact in complex ways, the risk is that individuals cannot readily understand the true extent of processing or how to control it.
For businesses, the lesson is that transparency is measured by the user’s actual comprehension, not by the mere existence of a privacy policy. Burying material information in lengthy documents, using ambiguous toggle labels, or presenting settings in a way that obscures the consequences of enabling them are all practices likely to attract regulatory concern.
DPC and EDPB guidance highlights categories of conduct that controllers should scrutinise in their own operations. These include:
To understand why Ireland’s Data Protection Commission leads so many cases involving major technology companies, it is necessary to understand the one-stop-shop mechanism at the heart of the GDPR’s cross-border enforcement architecture.
The GDPR establishes a one-stop-shop system for cross-border processing. Where a controller has its main establishment in one EU Member State but processes the data of individuals across the EU/EEA, the supervisory authority of the Member State where that main establishment is located acts as the lead supervisory authority. Because many of the world’s largest technology companies locate their European headquarters in Ireland, the DPC frequently serves as the lead authority for cases with pan-European reach. This is why enforcement against global platforms so often originates in Dublin.
The lead authority does not act in isolation. Under the cooperation and consistency mechanism (Articles 60 to 65), the DPC must work with concerned supervisory authorities in other Member States whose residents are affected by the processing. Where those authorities raise a relevant and reasoned objection to the lead authority’s draft decision and the disagreement cannot be resolved, the matter can be escalated to the European Data Protection Board for a binding decision under the dispute-resolution mechanism in Article 65. This structure ensures that a decision taken by Ireland’s Data Protection Commission carries weight across the entire EU/EEA, and that the outcome reflects a genuinely European consensus rather than a single national view.
For organisations without an Irish establishment, the practical implication is that a DPC decision can set an influential interpretive standard for the single market. A controller headquartered in another Member State, or outside the EU but offering goods or services to EU residents, may find that the reasoning applied by the DPC informs how supervisory authorities approach location and behavioural data. The one-stop-shop does not shield companies elsewhere from the effect of a leading decision; it can amplify it.
The most valuable response to DPC enforcement in this area is a structured remediation programme. A defined compliance window, of the kind the DPC typically imposes in corrective orders, is a useful benchmark for any controller wishing to demonstrate good faith. The following playbook is organised into immediate, near-term and medium-term phases.
In the first thirty days, the priority is to establish visibility and stop the highest-risk practices:
The second phase moves from triage to structural change:
The final phase embeds durable compliance:
The table below sets out illustrative guidance. It is not legal advice for any specific product; the correct legal basis and retention period always depend on the particular processing and its context.
| Scenario / data type | Typical lawful basis | Retention guidance (illustrative) | Key controls |
|---|---|---|---|
| Passive location collected for a core service (e.g. navigation) | Contract (Art. 6(1)(b)) where strictly necessary; otherwise consent | Keep only while necessary for the service; aggregate or pseudonymise for analytics; delete raw traces once the service-necessity period has passed | Purpose limitation, minimisation, deletion workflow |
| Background tracking for ad targeting | Consent (Art. 6(1)(a)), a high bar; must be specific and granular | Minimise retention; anonymise for any longer-term analytics | Consent UX, easy withdrawal, DPIA, opt-out mechanisms |
| Location accuracy and telemetry for product improvement | Legitimate interests (Art. 6(1)(f)) possible after a balancing test, subject to context | Limit to the minimal retention needed; keep only aggregated or anonymised data for product metrics | Documented balancing test, pseudonymisation, access controls |
| Historical location trails used for profiling or advertising | Consent (preferred) or a distinct, explicit legal ground | Avoid long-term raw retention; keep only aggregated profiles under strict controls | Record of processing, DPIA, technical deletion workflows |
A workable sample retention schedule might read: “Raw device location traces are retained for a defined, documented period for service delivery and troubleshooting, after which they are automatically deleted; aggregated, non-identifiable location metrics are retained for a limited period for capacity planning and are subject to periodic review.” Adapt the periods to your own documented justifications and note that where the ePrivacy regime applies to storage of, or access to, information on a user’s device, additional consent requirements under the ePrivacy Regulations may be engaged.
Beyond a fine itself, the practical question for controllers is what happens next and what the enforcement mechanics reveal about regulatory expectations.
Companies subject to a GDPR decision of significant scale typically have recourse to appeal the decision before the national courts of the lead supervisory authority. Where the DPC issues a final decision, the affected company may challenge both the findings and the penalty through the Irish courts. Where a decision is published, its full text should be consulted for the precise findings and for any statements the DPC records regarding the company’s representations during the inquiry. Controllers should treat the availability of appeal as a procedural feature of the regime rather than as a reason to defer their own remediation.
A corrective order requiring a controller to bring its processing into compliance within a defined window is enforceable in its own right: it requires demonstrable operational change, not merely payment of any fine. Supervisory authorities routinely monitor compliance with such orders and may require evidence that the specified changes have been implemented. A short compliance window is a compressed timeframe for structural change to complex systems, which is why the phased remediation approach above front-loads mapping and high-risk mitigation.
Decisions of significant magnitude tend to shape how supervisory authorities across the EU/EEA scrutinise location and behavioural data. The likely practical effect is heightened attention to retention periods, the clarity of transparency notices, and the validity of the legal basis relied upon for each processing activity. Failure to comply with a corrective order can expose an organisation to further enforcement measures, including additional fines and orders to limit or suspend processing under Article 58, alongside the reputational consequences of a public finding of non-compliance.
Because the DPC frequently acts in its capacity as lead supervisory authority under the one-stop-shop, the reach of its leading decisions extends far beyond Irish borders. Multinational controllers should treat this enforcement trend as a benchmark for their own compliance.
The GDPR applies to controllers established outside Ireland, and indeed outside the EU, where they offer goods or services to individuals in the EU/EEA or monitor their behaviour within the EU/EEA (Article 3). A business headquartered elsewhere that collects location or behavioural data from EU residents cannot assume DPC enforcement is irrelevant to it. The interpretive standards the DPC applies to lawfulness, transparency and retention can inform the expectations of other supervisory authorities whose residents are affected.
Cross-border processing chains multiply compliance obligations. Controllers should revisit their Article 28 processor agreements to confirm that each processor handling location data is contractually bound to appropriate security, retention and deletion obligations, and that sub-processing is authorised and controlled. Where data is transferred outside the EU/EEA, appropriate transfer mechanisms under Chapter V, such as an adequacy decision, standard contractual clauses, or binding corporate rules, supported where necessary by a transfer impact assessment, must be in place. The location-data context makes these obligations particularly acute given the sensitivity of the information involved.
While the GDPR harmonises the core rules, national implementing legislation, in Ireland, the Data Protection Act 2018, supplies procedural and supplementary provisions. Controllers operating across multiple Member States should be alert to areas where national law adds requirements or where enforcement postures differ. The one-stop-shop reduces but does not eliminate divergence, and organisations should design their compliance to meet the most demanding standard applicable to their operations rather than the most permissive.
The DPC’s enforcement approach to location and behavioural data is a defining feature of how such data must be handled under the GDPR. The following six priority actions distil the remediation programme into a roadmap any controller can begin immediately:
The overarching message from DPC enforcement in this area is that data minimisation, disciplined retention and honest transparency are not optional refinements but enforceable legal duties. Organisations that audit and remediate their location-data practices proactively will be far better placed than those who wait for a supervisory authority to make the case for them.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Dean Cunningham at Cunningham Solicitors, a member of the Global Law Experts network.
posted 20 minutes ago
posted 39 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message