The €403 million fine Ireland's Data Protection Commission imposed on Google on Monday is, by one reading, a penalty for something that no longer happens. The conduct window the regulator examined runs from May 25, 2018, the day the GDPR took effect, to February 4, 2020. The location-data practices at issue were redesigned years ago. Google's own response says the case "centres around historical policies that have since been updated," and the company is right about the timeline.

The mistake would be to read the fine as a stale receipt. The decision's most instructive finding is not that Google processed location data unlawfully. It is that Google, on one of the three features under review, could not demonstrate that its processing complied with the law. That is the accountability finding, and it is the part of the GDPR that most companies still have not internalized. Under the regulation, it is not enough to be compliant. You must be able to prove it, years later, on a regulator's timetable.

The conduct window closed before the penalties began

The timeline of this case is the first lesson. The complaints that seeded it were filed in November 2018 by consumer organizations in seven countries, coordinated by the European consumer group BEUC and built on research by the Norwegian Consumer Council into how Google's interface design steered users into leaving location tracking switched on. The DPC, as Google's lead European supervisor, opened its inquiry in February 2020 and closed the examined period at that point. The decision arrived in September 2026.

That is a six-year enforcement clock, and it runs in both directions. For the company, it means conduct from a previous product era is judged by a regulator that has had years to build the record. For consumers, it means the remedy for a 2018 complaint arrives after most of the affected behavior has already stopped. The DPC's finding that users "could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests" describes an experience that Google's subsequent product changes were explicitly designed to change. The penalty and the fix have different dates on them.

The retention finding carries the same double-edged quality. The DPC concluded that holding location data longer than necessary compounded users' loss of control, which means part of the fine attaches to a storage policy that Google has since shortened through auto-delete defaults. A regulator that punishes yesterday's retention with today's standards is saying that data practices are judged by the law as it stood when the data was held, not by the company's current settings. That is legally orthodox and practically awkward: the company paying the fine has already, by its own account, become the company that would not have earned it.

The accountability finding is the new terrain

The decision covers three features: Web & App Activity, Location History, and Location Accuracy, an Android setting. For the first two, the DPC found breaches of lawfulness, fairness, transparency, and retention obligations. For Location Accuracy, the finding was different in kind: Google failed its accountability obligations by not demonstrating compliance with lawfulness, fairness, and transparency.

The distinction matters because it shifts what a company is fined for. A transparency breach means a setting was unclear. An accountability breach means the company could not show the regulator what it did, on what basis, with what safeguards. The GDPR's accountability principle requires organizations to be able to demonstrate compliance, and the Location Accuracy finding is the DPC telling the market that a compliance program which cannot produce evidence is itself a violation. That is a much harder standard for any company whose data practices span products, teams, and years, and it is the standard the remaining Google inquiries will be judged against.

For every privacy team reading the decision, the practical instruction is uncomfortable: keep the receipts. A company that changed a product in 2021 needs the documentation of what it did in 2019, who approved it, and what lawful basis was recorded at the time. Evidence that lives in a departed engineer's memory or a decommissioned wiki is not evidence, and a six-year regulatory clock outlasts most of the artifacts companies actually keep. The fine is a warning that the duty to demonstrate compliance begins the day the processing begins, not the day the inquiry opens.

The design research that started it

The case's origin is worth recovering because it explains why the fine is as much about design as about data. The Norwegian Consumer Council's 2018 research documented how Google's choices of wording, defaults, and click paths made leaving location tracking on the path of least resistance, with the appearance of user consent layered on top. The same summer, an Associated Press investigation found that Google recorded location data even when users had switched Location History off, because the separate Web & App Activity setting continued feeding location into the advertising system. The distinction between the two switches, invisible to most users, became the public face of the problem: the settings did not mean what they appeared to mean. The consumer complaints that followed were never primarily about Google collecting location data in secret. They were about a consent architecture that made genuine choice difficult and the company's later claims of user control ring hollow.

That framing survives in the DPC's language about loss of control and retention. The regulator's conclusion that holding location data longer than necessary "aggravated" users' loss of control over personal data treats retention not as an efficiency choice but as a design decision with consequences. The fine's size, the fourth largest the DPC has issued, reflects the breadth of the conduct across features and years rather than any single egregious act, and the six-month compliance order attached to it gives the decision teeth beyond the cash.

Google's defense is that it already fixed the problem

Google's response is substantive, and it deserves to be stated fairly. Since 2019, the company points out, it has introduced auto-delete controls with three-month, eighteen-month, and thirty-six-month options, built the My Ad Center for controlling personalized advertising, moved Timeline data onto users' devices, and changed Web & App Activity to store an estimated general area rather than precise location. The company says it will appeal, and the appeal will presumably argue that penalizing abandoned practices, under standards clarified after the fact, is not what the GDPR was for.

The counterargument is equally plain: the practices ran for years while they were current, the complaints were filed in real time, and the fact that a company eventually fixed a problem does not erase the period when the problem existed. The DPC also imposed fines and a compliance order, not merely a reprimand, which signals the regulator does not accept reform as full absolution. Whatever the appeal decides, the six-month clock on the compliance order starts now, and the three other large-scale Google inquiries the DPC says are at advanced stages will be argued on the accountability standard this decision just sharpened.

Late enforcement costs both sides

BEUC welcomed the fine and aimed its criticism at the calendar: its director general said "late enforcement can be as harmful as no enforcement at all." The critique cuts to the structural problem of the GDPR's one-stop-shop system, where a lead regulator in one member state carries cases of global scale, and years of procedure sit between complaint and decision. For a company of Google's size, €403 million is a manageable cost, and a penalty that lands years late has limited power to change behavior that has already changed itself.

The scale economics deserve one honest sentence each. €403 million is roughly a rounding error against Alphabet's quarterly results, and if that were the whole story, the fine would be a toll booth, not a deterrent. What raises the price is aggregation: the DPC's four largest fines have now hit the same small set of platforms repeatedly, each decision adds a compliance order with a six-month clock, and the still-open inquiries mean the meter is running. A company can absorb any one fine and still notice the pattern. The regulator's bet is that the pattern, not the penalty, does the deterring.

The counterweight is that the GDPR's fines are not its only output. The compliance order, the published findings, the articulation of the accountability standard, and the signal to every other company's privacy team travel faster than any single penalty. The question the next three Google decisions will answer is whether the system has learned to move faster, because the most repeated criticism of European data enforcement is not that it is too strict. It is that it arrives too late to matter, and every six-year case makes that criticism harder to answer.

Primary sources

  1. Ireland's Data Protection Commission, whose decision and findings are the basis of this piece, as reported by Irish outlets.
  2. RTÉ, for the details of the decision, the compliance order, and the timeline of the inquiry.
  3. The Next Web, for the parties' responses, including BEUC's enforcement-timing critique and Google's account of its post-2019 changes.
  4. The Norwegian Consumer Council's 2018 research, the origin of the complaints that led to the inquiry.