There is no duplicate content penalty. That is a persistent myth, and Google has said so repeatedly. What actually happens is more mundane and, for a local business, more damaging: Google picks one version to index and ignores the rest.
Where local businesses hit this
The classic case is city pages. A business serving eight Phoenix metro suburbs builds eight pages that are the same 600 words with the city name swapped. Every one of them is competing for the same intent with nearly the same content, and the usual outcome is that Google indexes one or two and marks the rest “Discovered — currently not indexed.”
Nothing was penalized. The pages simply were not worth indexing separately, which is a fair assessment of pages that are not separately worth reading.
The test that matters
Take two of your city pages and ask what a real resident of the second city learns from theirs that they would not learn from the first. If the honest answer is “the city name,” you have one page, not two.
Pages that survive this test contain things only true of that market: named neighborhoods, actual local competitors, permitting or code specifics, seasonal patterns, jobs you have done there, travel and service radius realities. That is genuinely harder to write than swapping a token, which is exactly why it works.
The practical rule
Fewer, deeper location pages beat more, thinner ones — every time. Three cities you can write substantively about will outperform twelve you cannot. Add the fourth when you have something real to say about it.
For genuine technical duplication — parameters, print versions, HTTP and HTTPS both resolving, trailing-slash variants — use canonical tags and pick one version. That housekeeping is worth doing and takes an afternoon.
The duplicate content guide covers the canonical patterns and the diagnostic steps.