Ireland's Data Protection Commission fined Google €403 million on September 21, 2026 over location data practices that the regulator had first questioned on August 15, 2018 - when, by its own account, it "required an urgent response." On the day of the decision, Johnny Ryan of the Irish Council for Civil Liberties posted the DPC's 2018 statement with a running total: 2,951 days. Jason Kint, chief executive of publisher trade body Digital Content Next, went further, calling the Irish regulator "a joke."
In Short
In 2018, Ireland's privacy regulator said it needed an urgent answer from Google about how the company tracked people's locations, and it only fined Google for those practices in September 2026. Critics say the delay let Google keep collecting and using that data for years while competitors played by the rules. The €403 million fine covers conduct from 2018 to 2020, so the decision says little about how Google handles location data now, and the DPC did not publish the full text alongside the fine.
A statement that aged badly
The document at the centre of the criticism is short. Published on August 23, 2018 and still live on the DPC's website, the statement runs to four sentences. It opens by noting "the media reports in relation to Google and location data" - a reference to an Associated Press investigation, published that month, which found that Google stored location data from some users even after they had paused the Location History setting.
"For clarity, DPC Ireland, in the immediate aftermath (on the 15th August) of the publication of the Associated Press story, raised a number of questions with Google in relation to those issues and required an urgent response," according to the statement. "Google has committed to a response in the coming days. Once in receipt of that response, the DPC will assess the position and take all appropriate next steps."
The public record does not show when Google answered those questions or what it said. What it does show is that the next formal step came on February 4, 2020, when the DPC opened an own-volition inquiry into Google Ireland Limited's processing of location data. That was 538 days after the "urgent" questions were sent. The decision followed 2,421 days after that.
Ryan, who is Director of Enforce at the ICCL and has been an adjunct full professor at University College Dublin since April 2026, reposted a screenshot of the 2018 statement on LinkedIn on the day of the fine. "From the DPC archives (on today's DPC announcement re Google location data)," he wrote. "'Urgent' meant 8+ years." He credited Louise Hooper with spotting the document, and added: "This DPC decision took a mere 2,951 days."
The arithmetic holds. August 23, 2018, the date of the statement, to September 21, 2026, the date of the fine, is exactly 2,951 days. Counted from August 15, when the DPC says it sent its questions, the figure is 2,959. Counted from November 27, 2018, when consumer groups in seven countries announced complaints over the same Google features, it is 2,855 days - the figure PPC Land used in its coverage of the decision. Each start date produces a gap of roughly eight years.
What the DPC actually decided
The decision itself was announced on September 21, 2026 and signed by Commissioners Des Hogan, Dale Sunderland and Niamh Sweeney. The DPC found four categories of infringement across three Google features: Web & App Activity, Location History and Location Accuracy on Android. Web & App Activity and Location History breached the principles of lawfulness and fairness, transparency and storage limitation. Location Accuracy breached transparency, and Google could not demonstrate that the processing met the lawfulness, fairness and transparency principle - an accountability failure.
Google was given six months to bring its processing into compliance. The DPC did not break the €403 million down by infringement, did not explain how the figure was calculated and did not publish the decision text with the announcement, saying it would be released later. Reuters put the penalty at about $463 million.
Google's response, given to the Irish Examiner, was that the case concerned historical policies that had since been updated. The company said it substantially changed its practices from 2019, including auto-delete options at three, 18 or 36 months and on-device storage of Timeline data.
That defence exposes a gap in the decision. The period the DPC examined ran from May 25, 2018 - the day the GDPR took effect - to February 4, 2020, the day the inquiry opened. It is a window of 620 days. The time between the end of that window and the fine was almost four times as long. A six-month compliance order issued in 2026 against conduct that ended in early 2020, by a company that says it rebuilt the relevant settings starting in 2019, raises an obvious question that the DPC's announcement does not answer: what exactly must Google now change?
The complaint the DPC chose not to make its own
The 2018 statement is not the only record that complicates the timeline. On November 27, 2018, consumer organisations in Norway, the Netherlands, Greece, the Czech Republic, Slovenia, Poland and Sweden said they would file complaints against Google, coordinated by the European consumer organisation BEUC and built on a report by the Norwegian Consumer Council, Forbrukerrådet. PPC Land's reporting on the decision documented the complaint's arguments in detail: that consent for Location History was not freely given because of repeated prompts across preinstalled apps, bundling with other features and interface design; that Web & App Activity was switched on by default; and that neither contract nor legitimate interest could justify advertising use of the resulting data.
The complaint template named Google LLC, the US parent. Google Ireland Limited only became the data controller for users in the European Economic Area on January 22, 2019, which is what placed the case under the DPC's one-stop-shop jurisdiction. When the DPC finally opened its inquiry in February 2020, it did so on its own initiative rather than as a complaint-handling procedure.
The September 2026 statement does not say which GDPR articles were breached, does not address the dark pattern arguments that formed much of the 2018 complaint, and does not mention Article 25, the data protection by design obligation the complainants invoked. It also does not explain how processing before January 22, 2019, when Google LLC was still the controller, was attributed to Google Ireland.
BEUC's director general, Agustín Reyna, welcomed the decision but said the time it took was out of proportion to the seriousness of the infringement and that late enforcement can be as harmful as no enforcement at all, according to PPC Land's report. BEUC also noted it filed a second complaint in 2022 over further concerns. Its outcome is unknown.
Kint's charge: delay is a revenue transfer
Ryan's post drew attention because of the document. Jason Kint's repost drew attention because of its claim about money.
Kint, chief executive of Digital Content Next since May 2014 and formerly a senior vice president at CBS Interactive, represents publishers that compete with Google for advertising budgets. His LinkedIn repost of Ryan's screenshot, which drew 21 reactions and four reposts before comments were turned off, made an economic argument rather than a procedural one.
"Eight years. I can't even begin to lay out the harms due to the failure of the regulator to regulate Google," Kint wrote. "Every bit of data harvesting Google has done through its gatekeeping, location/surveillance, and acting as a third party to collect data (a majority of its data according to UK CMA) is revenue shifting from the rest of the market to Google. Ireland DPC has been a joke."
The parenthetical claim about the UK Competition and Markets Authority is Kint's characterisation; the post does not cite the specific CMA document. The broader argument, though, is one that publishers have been making for years: data collected unlawfully is not a neutral by-product. It feeds targeting and measurement products that advertisers pay for, and every euro of that spend is a euro not spent on inventory sold by companies that do not have access to the same signals.
From that perspective, the cost of the delay is not the gap between €403 million and whatever larger figure might have been imposed. It is nearly eight years in which a practice the DPC has now found unlawful continued to shape the market, with no interim order and no public finding. On Kint's reading, a penalty that arrives after the commercial benefit has been realised, and after the product has been redesigned, functions less as a deterrent than as a cost of doing business.
A pattern, not an outlier
Taken in isolation, a slow case might be explained by complexity, resources or the GDPR's cross-border cooperation procedure, which requires the lead authority to circulate drafts to every concerned regulator in the EEA. The DPC's record makes the isolation argument hard to sustain.
The money that is not collected
Ireland accounts for roughly €4.04 billion, or about 66 percent, of the €7.1 billion in GDPR fines announced across Europe since 2018, from 37 enforcement actions, according to an Alliance Risk analysis covered by PPC Land in May 2026. Headline totals look impressive. But noyb, the Vienna-based privacy group led by Max Schrems, reported that only 0.6 percent of officially announced Irish fines had actually been collected. Meta's €1.2 billion data transfer fine from May 2023 remains under appeal, alongside Meta fines of €390 million, €265 million and €91 million. TikTok's €530 million fine, announced on April 30, 2025, was challenged within a month, and the Irish High Court granted a conditional stay on the order suspending transfers to China in November 2025.
Nothing in the DPC's September 2026 statement suggests the Google fine will follow a different path. Google has not said whether it will appeal.
Courts that had to force the regulator's hand
On January 29, 2025, the EU General Court found that the DPC acted unlawfully by refusing to investigate a noyb complaint about Meta's use of sensitive data, as PPC Land reported. That complaint had been filed on May 25, 2018 - the GDPR's first day. Rather than comply with a binding European Data Protection Board decision instructing it to investigate, the DPC had gone to court to challenge the board's authority.
Another case started even earlier. In May 2018, researcher Michael Veale made a single access request to Meta. The DPC's inquiry into it took more than three years to reach a draft report in January 2022, a delay partly attributed to Covid-19 and changes of lead investigator, and a further gap before a preliminary draft decision in October 2025 proposing fines of €360 million to €430 million. When the Irish High Court dismissed Meta's challenge on May 21, 2026, roughly eight years had passed since the original request, and the decision was still not final.
An appointment that sharpened doubts
The decision against Google was signed by three commissioners, one of whom joined the DPC less than a year earlier. Niamh Sweeney's appointment, announced on September 17, 2025, drew criticism because she spent nearly eight years in public policy roles at Meta, including as head of public policy at Facebook in Ireland and director of public policy for Europe at WhatsApp until October 2021. noyb described her as a former senior Meta lobbyist and questioned the regulator's independence. Sweeney took up the five-year post on October 13, 2025, joining Hogan and Sunderland, who were appointed in February 2024.
The Google decision does not concern Meta. But its unexplained figure, unpublished reasoning and narrow time window give critics such as Ryan and Kint little reason to revise their view of the commission.
Why the timeline matters for advertising
For the advertising market, the location data case is not an abstract question of regulatory efficiency. Location signals underpin store visit measurement, local campaign targeting and audience inference across Google's products. Graham Doyle, the DPC's deputy commissioner, said in the regulator's statement that users could have been unaware their location was being used to influence them with ads or to infer their interests, and that holding the data longer than necessary aggravated their loss of control, as PPC Land reported.
That finding describes the exact mechanism Kint identified. If Google's location processing was unlawful between 2018 and 2020, the targeting and measurement products built on it were, for that period, built on an advantage competitors could not lawfully replicate. Publishers selling their own inventory, smaller ad tech companies and location data providers operating under tighter consent rules competed against that advantage for the entire span of the inquiry - and, depending on what the unpublished decision says about Google's current practices, potentially beyond it.
The case also lands in the middle of a separate fight over the pace of cross-border GDPR cases. The EU's procedural regulation for GDPR enforcement went through difficult negotiations in 2025, when noyb published analysis showing average case durations of about eight months across European data protection authorities and about 4.5 months where national deadlines exist. The European Parliament proposed limits of three months for simple cases and nine months for complex ones; the Council suggested 33 months. Against those figures, a 2,421-day own-volition inquiry - preceded by 538 days of correspondence - is an outlier by any proposed standard.
ICCL's Enforce unit, which Ryan leads, has its own long-running dispute with the regulator over real-time bidding. In January 2025, the unit and EPIC filed a complaint with the US Federal Trade Commission over Google's RTB data flows, taking the issue to a US regulator rather than waiting on Dublin.
What remains unknown
The 2018 statement promised that the DPC would "assess the position and take all appropriate next steps." Eight years on, several basic facts are still missing from the public record:
- The text of the decision, which the DPC said at the time of the announcement would be released later
- How the €403 million was calculated and divided across the four infringements
- Which GDPR articles were found to have been breached
- When the six-month compliance period starts; if counted from September 21, it ends on March 21, 2027
- Whether Google's post-2019 changes were assessed or whether current products are covered by the compliance order
- What Google told the DPC in response to the August 2018 questions, and why that response did not lead to an inquiry for another 17 months
- Whether Google will appeal, and if so, whether the €403 million will join the 99.4 percent of Irish fines that noyb found had not been collected
The DPC statement from August 23, 2018 is still online, under the regulator's press releases. As of October 9, 2026, it has been 2,969 days since it was published.
Timeline
- May 2018 - Michael Veale makes the access request to Meta that becomes a DPC inquiry still unresolved eight years later
- May 25, 2018 - GDPR takes effect; start of the period the DPC later examined. noyb files a complaint against Meta the same day, later the subject of an EU General Court ruling against the DPC
- August 2018 - Associated Press reports that Google stores location data even when Location History is paused
- August 15, 2018 - DPC sends questions to Google and requires an urgent response
- August 23, 2018 - DPC publishes its statement saying Google has committed to respond "in the coming days"
- November 27, 2018 - Consumer groups in seven countries announce complaints against Google's location tracking, coordinated by BEUC
- January 22, 2019 - Google Ireland Limited becomes the EEA data controller
- February 4, 2020 - DPC opens own-volition inquiry into Google's location data processing; end of the examined period
- August 2020 - Johnny Ryan becomes Director of Enforce at the ICCL
- May 2023 - Meta fined €1.2 billion over data transfers; still under appeal
- January 16, 2025 - ICCL Enforce and EPIC file an FTC complaint over Google's real-time bidding
- January 29, 2025 - EU General Court finds the DPC acted unlawfully in refusing to investigate a noyb complaint
- April 30, 2025 - DPC fines TikTok €530 million
- September 17, 2025 - Irish government names former Meta executive Niamh Sweeney as data protection commissioner
- October 13, 2025 - Sweeney takes up her five-year term
- May 21, 2026 - Irish High Court dismisses Meta's challenge to the Veale inquiry
- May 29, 2026 - Alliance Risk analysis finds Ireland holds 66 percent of announced GDPR fine value
- September 21, 2026 - DPC fines Google €403 million over location data; Johnny Ryan posts the 2018 statement, noting 2,951 days have passed
- Late September 2026 - Jason Kint reposts Ryan's post, calling the DPC "a joke"
- March 21, 2027 - End of Google's six-month compliance period, if counted from the date of the decision announcement
Related PPC Land coverage
- Irish regulator fines Google €403 million over location data processing - The September 21, 2026 decision, its four infringements and Google's response.
- Google faces €403m fine over location tracking flagged in 2018 - The November 2018 consumer complaints and what the DPC's statement leaves out.
- Ireland fines Google €403m over location data flagged in 2018 - BEUC's reaction to the timing and the wider context of Irish fines.
- Eight years of GDPR: 40% of the €7.1B in fines annulled or under challenge - Alliance Risk's analysis of which fines survive, with Ireland at 66 percent of value.
- Former Meta executive becomes data protection commissioner - Niamh Sweeney's appointment and the independence concerns it raised.
- EU court orders Irish data watchdog to investigate Meta privacy complaint - The General Court ruling that the DPC acted unlawfully.
- Irish High Court throws out Meta's challenge to €360-430M DPC fine - An access request from 2018 that has yet to produce a final decision.
- EU's attempt to fix GDPR enforcement backfires spectacularly - noyb's case-duration data and the fight over procedural deadlines.
- TikTok fined €530 million by Irish regulator over data transfers to China - A prior DPC fine with a six-month compliance order, later stayed by the High Court.
- Google faces security complaint over real-time bidding data practices - ICCL Enforce and EPIC take Google's RTB data flows to the FTC.
Summary
Who: Ireland's Data Protection Commission, which fined Google Ireland Limited; Johnny Ryan, Director of Enforce at the Irish Council for Civil Liberties; and Jason Kint, chief executive of Digital Content Next, who led public criticism of the regulator.
What: The DPC fined Google €403 million for location data infringements involving Web & App Activity, Location History and Location Accuracy. Critics pointed to the DPC's own August 2018 statement demanding an "urgent response" from Google, arguing that 2,951 days to a decision shows a regulator that failed to act while Google's data advantage shifted revenue away from competitors.
When: The DPC questioned Google on August 15, 2018 and published its statement on August 23, 2018. It opened an inquiry on February 4, 2020 and announced the fine on September 21, 2026. Ryan posted the 2018 statement the same day, and Kint reposted it in the following days.
Where: Dublin, where the DPC acts as lead supervisory authority for Google across the European Economic Area under the GDPR's one-stop-shop mechanism.
Why: The case concerns conduct between May 2018 and February 2020, and the decision text was not published with the announcement. That leaves open how the fine was calculated and whether it reaches Google's current practices. For advertisers and publishers, the delay meant years in which location-based targeting and measurement, now found unlawful for that period, operated without any regulatory check.
Discussion