Google's €403 Million Fine Tests the Speed of GDPR
Ireland fined Google €403 million over location data. The six-year inquiry shows how GDPR enforcement can arrive after products and policies already change.
Written by AI. Samira Barnes

Ireland’s Data Protection Commission fined Google €403 million on September 21 over location-data practices examined in an inquiry that opened in February 2020.
The number is large. The calendar is more revealing.
The DPC’s announcement covers Google’s processing through three features from May 25, 2018, when the General Data Protection Regulation took effect, through February 4, 2020. More than six years passed between the end of that period and the decision. Google says it began changing the relevant practices in 2019.
That chronology creates the central policy question in this case: what can privacy enforcement accomplish when it reaches the company after the product and its controls have changed?
The fine still imposes a financial consequence, establishes the regulator’s interpretation of the law and may shape Google’s future decisions. The DPC also ordered the company to bring its processing into compliance within six months. Yet delayed enforcement gives a company years to operate under contested practices, redesign them on its own terms and describe the eventual ruling as a judgment on history.
What the Regulator Actually Found
The case concerns three systems with different functions and, importantly, different groups of users.
Web & App Activity is an account setting through which Google can process activity across its services, including browsing, searches and location information. Location History, an opt-in service, recorded where users carrying compatible devices had been and displayed that information through a private Google Maps Timeline. Location Accuracy helps Android devices determine their position more precisely than GPS alone, and it can apply even when someone does not have a Google account.
The DPC found failures across several GDPR duties. It concluded that Google’s processing of location data through Web & App Activity and Location History did not meet lawfulness and fairness requirements. For Location Accuracy, Google failed to demonstrate compliance with the principles of lawfulness, fairness and transparency, an accountability failure under the GDPR. The company also breached transparency obligations across all three features and retained location data from Web & App Activity and Location History longer than necessary.
These distinctions matter. The decision reaches beyond whether a user tapped an opt-in button. GDPR compliance also requires a company to explain processing clearly, establish a lawful basis, treat people fairly, limit retention and produce evidence that it has done those things. A settings screen cannot carry that entire legal load, however neatly designed.
The regulator said users could have been unaware that location information was influencing advertising or being used to infer their interests. It added that keeping the information longer than necessary aggravated users’ loss of control. Location records can reveal routines and associations even when no individual coordinate appears remarkable.
The full decision has not yet been published, so the announcement does not disclose the regulator’s complete legal reasoning, the precise retention periods it rejected or how the €403 million total was allocated among infringements. Those omissions limit any firm assessment of how broadly the ruling will apply to other products.
Google’s Strongest Answer is a Changed Product
Google says the case concerns “historical policies” and that its practices have evolved since 2019. That response has substance because current product architecture affects whether the conduct can recur.
The company told BleepingComputer that Google Maps Timeline information is now stored on the user’s device and that data older than three months is automatically removed. Google also said Web & App Activity saves an estimated general area rather than a device’s precise location. Separately, The Irish Times reported that users can choose automatic deletion periods ranging from three to 36 months and that Google simplified controls over the use of personal data for advertising.
Moving Timeline data onto a device can reduce the amount centrally held by Google. Shorter default retention can reduce the historical record available for later use. Area-level information can be less revealing than precise coordinates. Each change addresses a recognizable privacy risk.
None of those facts, by itself, proves present compliance. Device storage does not answer every question about collection, processing or synchronization. A user-selected deletion period does not establish whether each retention period is necessary for each purpose. “General area” also lacks enough detail in the available statements to measure how much location precision remains.
The six-month compliance order is consequently more informative than Google’s claim that the policies are old. If the DPC considered every relevant problem resolved, an order to bring processing into compliance would be difficult to explain. The order suggests that at least some legal or operational work remains, although the unpublished decision is needed to identify it.
Retention may prove especially resistant to the historical-policies defence. A redesigned consent flow changes what future users see. Data kept from an earlier system can persist after that interface disappears. The DPC’s finding that Google retained location information longer than necessary therefore reaches the data lifecycle, not merely the screen through which collection began.
Six Years is Part of the Enforcement Outcome
The inquiry opened after complaints from European consumer organizations, including BEUC. Its director general, Agustín Reyna, welcomed the finding but told The Irish Times that the time required was disproportionate to the seriousness of the infringements, adding that late enforcement can be as harmful as no enforcement.
That criticism identifies a structural cost. A slow case can still produce legal precedent and a substantial penalty, but it offers little immediate protection during the disputed conduct. Product teams also receive the regulator’s detailed answer after several design cycles have passed. Privacy law then governs partly through retrospective bills rather than timely boundaries.
Google’s position exposes the other side of the delay. A regulator assessing old systems may order changes to a product that has already been rebuilt, and the public announcement may provide too little detail to show which current practices remain deficient. Speed cannot replace due process, especially in a case covering several services and legal obligations. The policy problem is the size of the gap between a careful investigation and an operationally useful one.
The DPC remains the lead EU privacy regulator for Google because the company’s European headquarters are in Dublin. An Associated Press account said the authority has three other ongoing privacy investigations involving the company. The location decision may therefore influence several files, but it also demonstrates how much enforcement responsibility can accumulate in one national authority under the GDPR system.
A Large Fine is an Incomplete Comparison
The €403 million penalty is the fourth-largest privacy fine imposed by the Irish regulator. Its largest remains the €1.2 billion penalty issued to Meta in 2023 over transfers of Facebook users’ data to the United States.
The comparison shows that the DPC can impose sanctions at a scale beyond routine compliance costs. It does not show that the Google case will have the same effect. Meta’s case concerned international data transfers; Google’s concerns the design, explanation and retention practices surrounding location features. Different conduct, legal questions and remediation requirements make the league table a poor proxy for deterrence.
Enforcement effectiveness depends on more than the amount collected. The useful measures will include what Google must change during the six-month compliance period, whether old location data must be deleted, whether the reasoning alters defaults across services and whether any appeal postpones those effects. The Irish Times reported that Google may appeal elements of the decision, but no outcome is yet available.
For users, current controls deserve attention now: where Timeline information is stored, how quickly location records are deleted and whether Web & App Activity is enabled. For regulators, the harder design problem is institutional. A privacy right enforced six years later remains a legal right, but during those six years it operates largely as a promise that an invoice and a ruling will eventually arrive.
More Like This
Sakana Fugu Is a Router, Not a Frontier Model
Sakana Fugu benchmarks against top AI models, but it's an orchestration layer, not a foundation model. Here's what that category gap costs developers.
AI Video's Realism Gap and the Workflow Layer Bet
Local AI video runs free on your machine. Frontier models win on realism. But the real question is who controls the workflow layer—and what that means legally.