Ireland’s Data Protection Commission fined Google 403 million euros this week for how it handled location data between 2018 and 2020, and ordered the company to fix its practices within six months. Read the headline number and the natural conclusion is that GDPR enforcement has real teeth. Read the timeline underneath it and the conclusion looks very different: the conduct under investigation ended more than six years before the fine landed.

The case for calling this a win

There is a real argument here, and it deserves stating before I argue against it. A nine-figure fine against one of the world’s largest companies is not nothing. The DPC’s decision, reached by Commissioners Des Hogan, Dale Sunderland, and Niamh Sweeney, found Google fell short on the lawfulness, fairness, accountability, and transparency of how it processed location data across three features: Web & App Activity, Location History, and Location Accuracy. The six-month compliance order gives the finding an operational consequence beyond the money. For a company facing its first DPC penalty despite years of scrutiny, and at a scale that dwarfs most enforcement actions against smaller processors, that is a meaningful marker that a major regulator followed through.

The six-year gap is the actual story

But the timeline is the part that should worry a security or privacy leader more than the euro figure comforts one. The DPC’s own inquiry covered Google’s conduct from 25 May 2018, the day GDPR took effect, through 4 February 2020. The decision was announced on 21 September 2026. That is not a slow investigation. It is an investigation that took longer than the product features it examined have likely existed in their investigated form. Location History, Web & App Activity, and Location Accuracy have all been rebuilt, renamed, and re-engineered multiple times since 2020, and nothing in the DPC’s announcement claims to have re-examined how the current versions behave.

Media Partner

Web3 x AI Fusion — Media Partner

Deputy Commissioner Graham Doyle framed the underlying harm in the DPC’s own statement: “Location data is a type of personal data which is processed by way of location tracking, and includes data collected or processed by Google, which by itself or in conjunction with other information an individual’s location can be inferred. Location data can bring both benefits and harms to individuals. It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private.” That description of risk is accurate today. The finding it accompanies describes a system state from six years ago.

What it means for the security leader

The practical lesson isn’t that GDPR enforcement is worthless. It’s that enforcement outcomes are a lagging indicator, and a security or privacy program that treats regulatory risk as a proxy for current data-handling risk is measuring the wrong thing. A six-year enforcement cycle means the conduct a regulator eventually punishes was already retired, replaced, or quietly patched long before the public ever heard about it, in Google’s case or in any other vendor’s. Waiting for a DPC finding, an FTC consent order, or a state attorney general settlement to tell you which data flows are risky is waiting for information that arrives, on average, years after it would have been useful.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

That argues for a different posture inside any organization that processes location, behavioral, or other sensitive personal data at scale: treat data minimization and retention limits as controls to be audited continuously against current systems, not as compliance boxes to check once against a policy document. It is not that regulators are incapable of moving fast. The EU’s own Cyber Resilience Act, which CyberTech has covered separately, will require exploited-vulnerability disclosure within 24 hours once it takes effect, proof that Brussels can design a clock that runs in hours when it chooses to. GDPR enforcement, by contrast, was built to run in years, and a security leader who confuses the two clocks will misjudge how much protection either one actually provides in real time. CyberTech has argued before that enterprises consistently under-govern the parts of their environment that don’t map to a person logging in with a password. Long-retained location and activity data is the same failure mode wearing different clothes: it accumulates because deleting it is nobody’s job, and by the time a regulator notices, the exposure window has already closed on data that’s long since been through several more product cycles. The DPC’s six-month remediation order is a reasonable response to what it found. It is not, on its own, evidence that today’s practices are sound, and treating it as such is the mistake worth avoiding.

A regulator’s finding tells you what a company’s data practices looked like years ago, not what they look like now. Build your own continuous audit of retention and minimization instead of outsourcing that judgment to an enforcement timeline measured in years.

Source: Data Protection Commission