Ireland’s Data Protection Commission fined Google €403 million on 21 September, bringing a six-year investigation into three of the company’s location-data features to a close. Google has six months to put its practices right. Most of the coverage has treated it as another entry in the familiar “Big Tech gets fined again” story. That misses what is actually interesting about the case, particularly for companies outside Big Tech that still assume GDPR enforcement is primarily a problem for very large businesses.
The substance of the finding matters more than the headline figure. The DPC did not conclude that using location data for advertising is inherently unlawful. Its findings were considerably more specific. It found shortcomings in the lawfulness and fairness of the processing, in the transparency of the information provided to users, in Google’s ability to demonstrate that it was complying with its obligations, and in the length of time the data was retained. Three of those four points are, in one form or another, about explanation, evidence, and retention rather than the underlying activity itself.
That distinction is important. A company can be carrying out processing that GDPR permits and still find itself in serious difficulty because it has not explained that processing clearly enough, cannot demonstrate why it was justified, or has kept the resulting data for longer than it can reasonably defend. Compliance is not simply a question of whether the activity is permitted. It is also a question of whether the organisation can explain what it is doing, demonstrate that it has thought through the consequences, and show why the data still needs to exist.
That is perhaps the part of the decision most worth dwelling on. Companies that handle personal data often treat consent as the finish line. Get the wording approved, get the box ticked, record the permission, and move on. This case is a useful reminder that the difficult questions often come afterwards. Can an ordinary person understand what they have agreed to? Can the company explain, years later, why the information is still being retained? And can it produce the evidence to show a regulator that these questions were properly considered at the time?
There is also a wider point about enforcement. This was the DPC’s first fine against Google, eight years after it became the company’s lead EU supervisory authority, and its fourth-largest penalty overall, behind fines imposed on Meta and TikTok. The length of the investigation is significant. It suggests a regulator prepared to let a case develop over years and build an enforcement record cumulatively, rather than treating the passage of time as a reason to let the matter quietly disappear. For companies, that is an important distinction. A slow regulator is not necessarily a lenient regulator.
For any organisation processing customer data, the practical lessons are fairly straightforward.
- Audit retention schedules as carefully as consent and collection processes. Having a compliant consent mechanism at the point of collection offers little comfort if nobody can explain why the data is still being held several years later.
- Test privacy notices on someone who is not a lawyer, compliance specialist, or product manager. “Technically accurate” and “genuinely understandable to the person reading it” are different standards. The latter is increasingly the one that matters.
- Keep a standing record of compliance evidence rather than relying on a policy document sitting in a shared drive. If the organisation is doing the right thing but cannot demonstrate when, why, and how it did it, that distinction may not carry much weight once a regulator starts asking questions.
- And perhaps most importantly, pay attention to the six-month compliance order, not just the €403 million headline. The fine is what generates the coverage. The corrective measures are what force the organisation to change how its systems actually work. For everyone else, that is the more useful part of the decision to study.
The broader lesson is not that GDPR has suddenly become a mechanism for punishing companies for using personal data. It is that the regulatory question is becoming more demanding: not simply “were you allowed to do this?”, but “can you explain what you did, can you show that you understood your obligations, and can you justify why you are still holding the data?” For companies of any size, those are rather different questions from the one most compliance programmes are built around.
The fine will be forgotten within a news cycle. The operating lesson won't be, for any company still treating consent as the whole compliance job.
.