Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
GDPR Location Data Disclosure TemplateGovernance & Controls
5 min readFor GRC Leaders

GDPR Location Data Disclosure Template

When the Irish Data Protection Commission fined Google €403 million for unlawful location data processing, the violation centered on three failures: insufficient transparency about how location data influenced ad targeting, inadequate accountability for cross-service data flows, and retention periods that exceeded legitimate purposes. Your organization faces the same scrutiny if you process location data under the General Data Protection Regulation.

This template provides a disclosure framework to address the transparency and accountability requirements the Irish DPC found lacking in Google's implementation.

Purpose of This Template

Use this template to document how your organization processes location data across multiple services or features. It's designed for:

  • Mobile apps that collect precise or approximate location
  • Web services that infer location from IP addresses or user inputs
  • Platforms that combine location data with behavioral tracking
  • Any service where location data influences automated decision-making, including ad targeting or content personalization

The template addresses Articles 5(1)(a) (lawfulness, fairness, transparency), 5(1)(c) (data minimisation), 5(1)(e) (storage limitation), and Article 24 (accountability) of the General Data Protection Regulation.

Prerequisites

Before customizing this template, gather:

  1. Service inventory: List every feature, API, or function that collects, infers, or processes location data.
  2. Data flow maps: Document how location data moves between services. The Google case highlighted failures when Web & App Activity and Location History operated without clear boundaries.
  3. Retention schedules: Specify how long location data persists in each system, tied to specific processing purposes.
  4. Decision logic: Identify where location data influences automated outputs, such as ad targeting or content recommendations.
  5. Legal basis per purpose: Match each processing activity to consent, legitimate interest, contract performance, or another Article 6 basis.

The Template

LOCATION DATA PROCESSING DISCLOSURE

Effective Date: [Date]
Last Updated: [Date]
Controller: [Your organization's legal entity name and contact details]


1. LOCATION DATA WE COLLECT

We process the following categories of location data:

  • Precise location (GPS coordinates accurate to [specify radius]): [List specific features]
  • Approximate location (city/region level from IP address): [List specific features]
  • Inferred location (derived from search queries, content preferences, or other behavioral data): [List specific features]

For each category, we collect this data when you [describe the specific user action or setting that triggers collection].


2. HOW LOCATION DATA INFLUENCES WHAT YOU SEE

Your location data directly affects:

  • Advertising: We use [precise/approximate/inferred] location to [specific mechanism: show ads from nearby businesses, target regional campaigns, measure ad effectiveness in geographic segments].
  • Content personalization: We use location to [specific mechanism: prioritize local news, adjust language settings, filter search results].
  • Service functionality: We use location to [specific mechanism: calculate delivery estimates, show nearby store inventory, enable location-based reminders].

What we infer from your location: Location data combined with [list other data categories] allows us to infer [specific attributes: shopping preferences, commute patterns, interest categories]. These inferences [do/do not] create profiles used for automated decision-making.


3. HOW LONG WE KEEP LOCATION DATA

Data Type Retention Period Justification
Precise GPS coordinates [Specify period or "until you delete"] [Tie to specific purpose: trip history functionality, fraud detection window]
Approximate location logs [Specify period] [Tie to specific purpose: service improvement analytics, compliance with legal obligations]
Location-based inferences [Specify period] [Tie to specific purpose: ad targeting profile validity period]

Automated deletion: We automatically delete [specify which categories] after [period] unless you actively use the feature during that window.


4. SERVICES THAT SHARE YOUR LOCATION DATA

Location data collected through [Feature A] is accessible to:

  • [Feature B] for [specific purpose]
  • [Feature C] for [specific purpose]
  • [Third-party service name] for [specific purpose under data processing agreement]

Cross-service visibility: When you enable [Feature A], your location data [is/is not] visible to [other services]. To restrict cross-service access, [specific steps].


5. YOUR CONTROLS

To stop location collection:

  • For [Feature A]: [Specific steps, including navigation path]
  • For [Feature B]: [Specific steps]
  • System-level: [OS-specific instructions]

To delete existing location data:

  • [Navigation path to deletion interface]
  • Bulk deletion: [Steps to delete all location data at once]
  • Selective deletion: [Steps to delete specific date ranges or service-specific data]

To limit how we use location data:

  • Restrict ad targeting: [Specific toggle or setting]
  • Disable location-based inferences: [Specific toggle or setting]
  • Pause collection without deleting history: [Specific toggle or setting]

Export your location data: [Link to data portability interface] provides [format] files containing [specific data elements].


6. LEGAL BASIS FOR PROCESSING

Processing Activity Legal Basis Your Rights
[Specific use case] Consent (Article 6(1)(a)) Withdraw consent at any time without affecting service access
[Specific use case] Legitimate interest (Article 6(1)(f)) Object to processing; we'll stop unless we demonstrate compelling grounds
[Specific use case] Contract performance (Article 6(1)(b)) This processing is necessary to deliver the service you requested

7. ACCOUNTABILITY MEASURES

We maintain:

  • Data Protection Impact Assessments for [list location-processing features that underwent DPIA]
  • Processing records under Article 30 documenting location data flows
  • Data processing agreements with [number] third parties who access location data
  • Regular audits of retention schedules and deletion automation

Data Protection Officer contact: [Email and postal address]


How to Customize It

Section 1 (Data We Collect): The Irish DPC found Google failed to clarify that Web & App Activity included location data. Don't bury location collection in a general "usage data" category. List it explicitly with accuracy specifications.

Section 2 (Influences): This section addresses the transparency gap the regulator identified. Google users "could have been unaware that their location was being used to, for example, influence them with ads." State the causal relationship clearly: "We use your city-level location to show ads from businesses within 25 miles."

Section 3 (Retention): The Irish DPC found Google retained location data "longer than necessary." Tie every retention period to a specific purpose. If you can't articulate why you need 18 months of location history, you probably don't need it.

Section 4 (Cross-service sharing): Google's case involved multiple features accessing the same location data pool. Map these connections explicitly. If enabling Feature A means Feature B and Feature C also get location access, say so upfront.

Section 5 (Controls): Provide navigation paths, not vague statements like "manage your settings." The Irish DPC requires "detailed communication" about data practices, which includes actionable instructions.

Section 7 (Accountability): Article 24 requires you to "implement appropriate technical and organisational measures" and "be able to demonstrate compliance." This section documents those measures for regulators and users.

Validation Steps

  1. Cross-reference with privacy policy: Every location processing activity in this disclosure must appear in your Article 13/14 privacy notice with consistent language.
  2. Test user paths: Follow your own instructions in Section 5. Can a non-technical user actually find and use these controls?
  3. Audit retention automation: Verify that the deletion periods in Section 3 match your actual data lifecycle policies and that automated deletion works.
  4. Map to processing records: Confirm that your Article 30 register includes every processing activity described in this disclosure.
  5. Review with DPO: Your Data Protection Officer should validate that legal bases in Section 6 match your internal assessments and that accountability measures in Section 7 are current.

Google had six months from the Irish DPC's decision to bring its processing into compliance. You don't have to wait for an enforcement action to get this right.

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide

You Might Also Like