A Fine Built on Four Separate Failures
Ireland's Data Protection Commission fined Google EUR403 million on September 21 for how it handled location data in three features: Web & App Activity, Location History and Location Accuracy. The inquiry covered a narrow window, May 25, 2018 to February 4, 2020, and it found four distinct infringements rather than one.
Two features failed on lawfulness and fairness, meaning Google did not have a proper legal basis for how it used the data it collected. The same two features also failed on retention, meaning Google kept the data longer than it needed to. All three features failed on transparency: the DPC said users could stay unaware their location was feeding ad targeting or interest inference.
The Fourth Violation Is the Unusual One
Location Accuracy carried a fourth finding that has nothing to do with what Google did with the data. It is an accountability failure: Google could not demonstrate that its processing met the lawfulness, fairness and transparency principle. That finding describes something different: what Google could not show, six years later, to prove its processing had been lawful all along.
That distinction sets this fine apart from a routine privacy penalty, and it puts Google in company that has mostly gotten there through the same one-stop-shop mechanism, where Ireland regulates on behalf of every EU member state a company operates in.
| Company | GDPR Fine | Year |
|---|---|---|
| Meta | EUR1.2 billion | 2023 |
| TikTok | EUR530 million | 2023 |
| EUR405 million | 2022 | |
| EUR403 million | 2026 |
Google Says the Feature Is Already Gone
Google's response leans on the calendar. The company says the case concerns historical policies it has since replaced: from 2019 it built simpler location controls, added automatic deletion after windows of three to 36 months, and moved Timeline location data from its servers onto users' own devices. Google may appeal parts of the decision.
The consumer group BEUC, whose member organizations across several European countries filed the original complaints, welcomed the fine but flagged the same gap from the other direction: late enforcement can be nearly as harmful as no enforcement at all. Both sides are pointing at the identical six-year lag between the conduct and the ruling. They just draw opposite conclusions from it.
What an EU-Facing Business Should Take From It
The accountability count is the part worth carrying into your own compliance file. A GDPR investigation can reach a feature you have already retired and still fine you for it, so the practice itself is not the only thing that has to survive years of storage. The reasoning behind it does too. Keep a dated record of why a data-processing decision was made at the time you made it, not a reconstruction written after a regulator asks.
The six-year gap also means Google is being ordered to bring a feature into compliance within six months, when that feature already changed on its own around 2023. Enforcement timelines and product timelines run on different clocks. Any company operating in the EU inherits that mismatch, not just Google.
Read next: If Your Company Fails, Your Emails Get Sold | Google Buys a Bankrupt Airline's Data for AI Training



