Nobody Attacked Google.
On 21 September Ireland's Data Protection Commission announced a final decision against Google Ireland Limited and imposed administrative fines totalling €403 million. The inquiry was opened in February 2020 and examined how Google handled location data in three features between 25 May 2018 and 4 February 2020. The findings were lawfulness and fairness, accountability, transparency, and retention. Google has six months to bring its processing into compliance, and the Irish Times reports it is understood the company may appeal elements of the decision. There is no attacker in this story. There is no breach, no stolen record and nothing to patch.
Most security leaders will note the size of the company involved and move on. That is the wrong read. Strip out the scale and what remains is a set of failures any organisation holding customer data can reproduce, and which almost none could currently disprove. Three of the four headings concern records, explanations and deletion. All three are cheap to fix in advance and expensive to fix under an order.
What happened
- 25 May 2018The GDPR becomes applicable. The examined period starts here.
- Prior to the inquiryEuropean consumer rights organisations complain to the DPC about Google's processing of location data in connection with certain services and products. The Irish Times reports that BEUC co-ordinated the complaints, and that eight consumer organisations, from Norway, the Netherlands, Greece, the Czech Republic, Slovenia, Poland, Sweden and Denmark, filed or reported concerns. Neither the DPC nor the reporting dates the complaints.
- 4 February 2020The end of the examined period. Anything after this date falls outside the decision.
- February 2020The DPC opens an own-volition inquiry in its role as Lead Supervisory Authority for Google, whose European headquarters are in Dublin. Three features are in scope. Web & App Activity is an account setting, available only to account holders, that processes activity across Google services and can include browsing history, search history and location data. Location History is an opt-in service that tracks a compatible device and infers place visits, activities and routes, populating a private Maps Timeline and recording where the user goes with their signed-in devices even when no Google service is in use. Location Accuracy is an Android feature that determines a device's position more precisely than GPS alone, and it is available whether or not the user has a Google account.
- 21 September 2026The Commissioners for Data Protection, Dr Des Hogan, Mr Dale Sunderland and Ms Niamh Sweeney, announce the final decision, setting out findings under four headings. Administrative fines total €403 million, reported at around $462 million, which the Irish Times records as the fourth largest the DPC has issued. Google is ordered to bring its processing into compliance within six months. The full decision will be published later.
- 21 September 2026, Google's accountGoogle says the case "centers around historical policies that have since been updated" and that "from 2019 onwards, we've significantly evolved our practices and launched robust tools that make managing location data simple". On the detail of those tools the reporting differs. BleepingComputer describes Maps Timeline data now held on the device and removed automatically after three months, and Web & App Activity recording an estimated general area rather than a precise device location. The Irish Times reports automatic deletion after a user-set period of between three and 36 months, on-device Timeline storage, and simplified management of how personal data is used for ad personalisation. We state both rather than choosing between them, and we have verified neither.
Why this one is different
Fines against large technology firms arrive often enough that boards treat them as a problem belonging to a different class of company. This one is worth reading closely for four reasons, and none is the number.
There is no incident. The DPC found against Google on lawfulness and fairness in Web & App Activity and Location History; on accountability in Location Accuracy; on transparency across all three features; and on retention in the first two. None of the four headings is a security control failure. No firewall, endpoint agent or penetration test would have changed the outcome. The exposure came from decisions about collection, explanation and deletion, which sit outside the security function in most organisations and are therefore owned by nobody in particular.
One finding was about evidence, not conduct. On Location Accuracy the DPC announced no finding of unlawful processing. What it announced was that Google could not demonstrate compliance with the lawfulness, fairness and transparency principle. Under the accountability principle that inability is an infringement in its own right, and the obligation to evidence compliance rests with the controller. So a company whose processing is lawful, but whose records cannot show it, carries exposure on the records alone. Ask most UK executive teams to produce the documented lawful basis for each category of personal data they hold and you will get a project, not a document.
Fixing it afterwards did not prevent the fine. Google's position is reasonable and probably accurate: the policies are historical and were changed years ago. The timing is worth stating precisely, because it cuts both ways. Google dates its changes from 2019, which places part of the remediation inside the examined period rather than after it, and the fine landed regardless. Liability in a case of this kind attaches to conduct in the examined window, not to the state of the product at the point of decision. Remediation is a mitigating argument, not a defence.
Retention made the loss of control worse. The DPC was explicit that holding location data longer than necessary aggravated the loss of control. Retention is among the cheapest data protection controls and the most widely ignored, because deleting data feels like destroying an asset and nobody is rewarded for it. It is also one of the few controls that shrinks every future incident, regulatory or criminal, at a stroke.
"The decision is good news for consumers, as it holds Google accountable and confirms the illegality of the way the tech giant obtained consent to use peoples' location data ... However, the time needed to come to this conclusion is disproportionate with the seriousness of the infringement. Late enforcement can be as harmful as no enforcement at all. Consumers' fundamental rights need to be upheld faster and better."
That is Agustín Reyna, director general of BEUC, which co-ordinated the original complaints, quoted by the Irish Times. It is a criticism of the regulator, not of Google, and the sharpest available statement of why the interval matters. A regime this slow to conclude does not reduce the exposure of the companies inside it. It moves that exposure further from the people who created it.
The commercial exposure for UK organisations
Regulatory. A British reader may treat an Irish decision against an American company as remote. It is not. UK GDPR retains the same principles breached here: lawfulness, fairness and transparency, storage limitation, and accountability. Infringing them sits in the ICO's higher penalty tier, a maximum of £17.5 million or 4% of total annual worldwide turnover in the preceding financial year, whichever is higher. The EU position is worth stating precisely, because the usual summary of it is wrong. A UK business with an establishment in the EEA is within EU GDPR's reach and, where its processing is cross-border, deals with a single lead supervisory authority under the one-stop-shop mechanism. A UK business with no EU establishment that offers goods or services to, or monitors the behaviour of, people in the EEA is caught by Article 3(2) instead. It gets no lead authority and no one-stop shop. It must appoint a representative in the Union unless the narrow Article 27(2) exemption applies, which for a commercial service it rarely does, and it can be pursued by the supervisory authority of every member state in which the affected people are. That is materially the worse position, it is the one most UK scale-ups selling into Europe are actually in, and very few of them know it. The three features at issue here, an activity setting, a history log and a positioning service, have ordinary equivalents in most consumer applications, connected products and workforce management tools sold in Britain today. The Irish Times reports three further large-scale DPC inquiries into Google open and at an advanced stage. A regulator's attention, once engaged, is rarely a single event.
Financial. The fine is the visible number and the less interesting one. The expensive part is a six-month remediation programme executed under a regulatory order, across product, engineering, legal and data teams, to a deadline set by someone else and with a regulator reading the output. Work that costs little as a design decision costs a great deal as a retrofit, and it displaces the roadmap for the duration. Consent, retention and transparency are all cheap to build in and expensive to bolt on. For a company mid-way through a funding round or a sale process, the timing risk is larger than the cash.
Contractual. Enterprise buyers increasingly ask suppliers for retention schedules, lawful basis records and sub-processor detail as standard diligence, and a supplier under a compliance order is a procurement problem for every customer it serves. For a UK scale-up selling into regulated enterprise, answering those questions quickly is a commercial asset. Failing to is a stalled deal, and it stalls where legal review meets a deadline.
Governance. This is the exposure that produces the other three. Product decides what is collected, usually as a side effect of a feature decision nobody logged as a data decision. Engineering implements retention, or does not, and rarely across backups, logs and analytics warehouses as well as the primary store. Legal documents the lawful basis, or does not, and is often asked only at launch. Deletion is verified by nobody. The accountability principle requires a controller to demonstrate compliance as a whole, and no single function in a typical organisation holds that view. A board that asks who could produce the evidence, and how long it would take, will learn more in ten minutes than from a year of risk registers.
What leaders should do now
- Produce the retention schedule, then ask for the deletion evidence. Request both in the same meeting. A schedule that exists on paper while the data persists in backups, logs, warehouses and third-party platforms is worse than none, because it documents the gap in your own words.
- Write down the lawful basis for every category of location, device and behavioural data you process. Include telemetry gathered by third-party software development kits inside your own applications, which is where most organisations collect data they have never assessed. If nobody can name the basis, you cannot demonstrate the processing is lawful, and under the accountability principle that is itself the exposure.
- Separate consent from settings. The lawfulness and transparency headings concern what a user could reasonably have understood. The reasoning is not visible until the decision is published, but a control that quietly widens collection, bundles distinct purposes or defaults to the broadest option is the pattern most exposed to it. Review your three most recent changes to collection defaults and ask what users were told at the time.
- Rehearse the accountability answer. Choose a period ending six years ago and ask your team to demonstrate compliance for it. Name who produces the evidence and record how long it takes. That interval is your accountability posture, and it is measurable today at no cost.
- Run the six-month clock as an exercise. Assume an order arrives tomorrow giving you six months. List what you could not fix in that time. That list is the real exposure, it takes an afternoon to write, and it is the most useful document a data protection function can hand a board.
Three questions for the board
- For our three largest categories of personal data, can we produce today the record showing the lawful basis, the retention period and the reason for it, or would we be assembling it after the letter arrives?
- What personal data are we currently holding for longer than we can justify, who decided that, and what would it cost us to stop?
- If our processing this month were judged in 2033, against the evidence we are creating now, what would we want on the file that is not there?
The strategic takeaway
Security investment is argued for on the basis of an attack that might happen. Data protection investment is argued for on the basis of a file that is already open. This decision is the clearest recent demonstration that the second is not the softer risk, only the slower one. The examined period closed in February 2020. The decision arrived in September 2026, and may yet be appealed. In between, product changed, policies changed, and almost everyone who made the original decisions moved on. The record did not, and the record is what was assessed.
There is a commercial reading of this that is more useful than the compliance one. An organisation that can produce its lawful basis records, its retention schedule and its deletion evidence on request is not simply less exposed to a regulator. It is faster through enterprise procurement and, on our reading of what buyers, insurers and acquirers now ask for, better placed in transaction diligence. Building that evidence once and keeping it current is one of the few compliance activities with a direct return, which is why it should not sit unowned between legal, product and engineering.
Confidence note
Confirmed. From the DPC press release of 21 September 2026: that the DPC found Google infringed the GDPR in respect of four matters, and the features to which each attaches; administrative fines totalling €403 million; the order to bring the processing into compliance within six months; that the inquiry was own-volition, opened in February 2020 with the DPC acting as Lead Supervisory Authority for Google because its European headquarters are in Dublin; that it followed complaints from several European consumer rights organisations including BEUC; the examined period of 25 May 2018 to 4 February 2020; the descriptions of Web & App Activity, Location History and Location Accuracy; that the decision was made by Commissioners Dr Des Hogan, Mr Dale Sunderland and Ms Niamh Sweeney; Deputy Commissioner Graham Doyle's statement, which we paraphrase rather than quote, including that individuals could have been unaware their location was being used to influence them with ads or infer their interests, and that retention for longer than necessary aggravated that loss of control; that the DPC recorded the cooperation and assistance of its peer supervisory authorities; and that the full decision will be issued later and is not yet available.
From the Irish Times, 21 September 2026: that €403 million is the fourth largest fine the DPC has issued, behind Meta's €1.2 billion in 2023, TikTok's €530 million and a €405 million penalty relating to Instagram; that BEUC co-ordinated the complaints and that eight consumer organisations from Norway, the Netherlands, Greece, the Czech Republic, Slovenia, Poland, Sweden and Denmark filed or reported concerns; the Agustín Reyna quotation in full; and that the DPC has three further large-scale inquiries into Google open and at an advanced stage. That Google made the statement quoted above, from BleepingComputer and the Irish Times, both 21 September 2026. The ICO's higher-tier maximum of £17.5 million or 4% of total annual worldwide turnover in the preceding financial year, whichever is higher, from the ICO's own fining guidance.
Assessed. That the DPC's acknowledgement of its peer supervisory authorities indicates the draft passed through the GDPR's cooperation procedure is our inference from the wording, not a stated fact. That Google may appeal elements of the decision is reported by the Irish Times as understood, not stated by Google or the DPC. Neither the fine nor the six-month clock should be treated as settled while an appeal remains possible, and readers acting on this briefing should note that a regulator's order can be stayed. The interval of six years and seven months is our own arithmetic on one published date and one month given without a day, so it is approximate to within roughly three weeks, and we have labelled it as approximate in the graphics as well as the text. The dollar equivalent of around $462 million is a reported conversion that moves with the exchange rate, and the two outlets differ slightly: The Record gives $462 million, BleepingComputer $463 million. That this is the first time the DPC has fined Google is as reported by The Record, and we have not checked it against the DPC's full enforcement history. Google's account of its current controls is an unverified company claim and the reported detail differs between outlets, which is why the timeline carries both versions rather than choosing one. Our reading that the accountability heading is the most transferable part of the decision for a mid-market reader is our judgement, as are the observations about what enterprise buyers, insurers and acquirers now ask for in diligence, which rest on commercial experience rather than a measured dataset.
Not known. How the €403 million was apportioned, and under which GDPR articles the findings fall. Both become visible only when the full decision is published. Whether any peer authority objected to the draft. Whether Google will in fact appeal, on what grounds, and whether the six-month order would be stayed if it did. Whether the reasoning on accountability will be read across to smaller controllers. Whether any of the processing found unlawful continues today.
Could your organisation demonstrate compliance for a period ending six years ago?
Garzon Cyber Solutions was built around the argument that security, compliance and the people who sustain them are one capability rather than three cost lines. Lawful basis records, retention schedules and deletion evidence are the same artefacts that enterprise procurement, insurers and acquirers ask for. If your leadership team needs those built once, kept current and owned by someone named, start the conversation.
Start the Conversation →Data Protection Commission, "Data Protection Commission fines Google €403 million following Inquiry into Google's processing of location data", 21 September 2026 · BleepingComputer, "Google fined €403 million over location data privacy violations", Bill Toulas, 21 September 2026 · The Record, "EU data regulator fines Google more than $460 million for location data violations", Suzanne Smalley, 21 September 2026 · Irish Times, "Irish data protection watchdog fines Google €403m over GDPR breaches", Ian Curran and Ciara O'Brien, 21 September 2026 · Information Commissioner's Office, "The maximum amount of a fine under the UK GDPR and the DPA 2018"
Garzon Cyber Solutions delivers cybersecurity advisory, compliance certification and specialist technology recruitment as one integrated capability for organisations in the UK, EU and Americas. We are a young firm and we publish our own research. Founder Jonathan Garzon spent his career selling cybersecurity, compliance and technology to security and technology buyers, working alongside marketing and technical colleagues, before building GCS around a single argument: delivered in the right order, security, compliance and the people to sustain them stop being three cost lines and become one commercial capability.