Ireland fines Google €403 million under GDPR, its fourth-largest penalty since 2018
Ireland's €403 million fine against Google shows how EU regulators investigate and penalize US tech companies operating in Europe.

In September 2026, Ireland's Data Protection Commission fined Google €403 million for violating EU privacy law—the fourth-largest fine the watchdog has issued since the GDPR took effect in 2018. The case illustrates how European regulators investigate and penalize US tech giants, and why companies like Google, Meta and Amazon treat these multibillion-euro fines as a predictable cost of doing business in Europe.
For California companies serving European customers, understanding this enforcement machinery matters: it sets rules that affect how they collect, store and use data globally, and it shows that EU regulators are willing to levy fines large enough to reshape a company's practices. The Google case is one of 2,685 confirmed fines totaling €6.11 billion since GDPR enforcement began in 2018.
How GDPR enforcement works
The General Data Protection Regulation gives Europe's national Data Protection Authorities power to investigate companies, issue warnings, ban processing activities, and impose fines. Enforcement begins when a DPA receives a complaint from someone alleging a privacy violation, or when a regulator initiates its own audit based on suspected noncompliance.
Once an investigation starts, DPAs can demand documentation, conduct interviews, request access to company premises, and audit data handling policies and security measures. They assess whether personal data processing is lawful, transparent, and limited to stated purposes. For example, the Irish DPC's investigation into Google began in February 2020 after complaints from eight European consumer organizations, and examined Google's practices from the GDPR's May 2018 launch through February 2020, covering three product features: Web & App Activity, Location History and Location Accuracy.
The European Data Protection Board, composed of representatives from national DPAs, ensures consistent enforcement across the EU and resolves disputes between countries when multiple regulators have jurisdiction. For multinational companies processing data across borders, a 'lead supervisory authority' takes responsibility—typically the country where the company's main European office sits. This 'one-stop-shop' mechanism means a company usually faces one primary regulator rather than 27 separate enforcement actions.
Fines are scaled to violation severity. Minor breaches carry penalties up to €10 million or 2% of global annual turnover. Serious violations such as unlawful data processing can result in fines up to €20 million or 4% of annual worldwide turnover, whichever is higher. The GDPR requires fines to be 'effective, proportionate and dissuasive,' considering infringement severity, duration, intent, mitigating actions taken and cooperation level.
Why Ireland regulates most US tech firms
Meta, Google, TikTok, Apple, Microsoft and dozens of other US tech giants have European headquarters in Ireland. This creates a regulatory arrangement that gives Ireland's DPC jurisdiction over their data processing across all EU member states under the GDPR's 'one-stop-shop' mechanism. Companies designate their main establishment—typically their European headquarters—and are regulated by that country's supervisory authority. For US tech companies, Ireland's established tech hub, English-speaking workforce, and historical business-friendly environment made it a natural choice for European operations.
The result: Ireland's DPC has become the single most influential GDPR regulator in the world. As of March 2026, Ireland's DPC is responsible for 9 of the top 10 largest GDPR fines ever issued, including Meta's €1.2 billion fine in May 2023 (the first fine to reach billions), TikTok's €530 million penalty in 2025, and Instagram's €405 million sanction. Ireland's total: about €3.5 billion in fines issued since 2018, though the commission covers only a fraction of the 2,685 confirmed fines issued across all EU regulators.
This concentration has drawn sharp criticism from other EU nations and the European Commission. Critics have documented that the Irish DPC issued decisions in 'just four out of 196 cases where it claimed a leading role' as of 2021, and that the commission frequently accepted companies' assurances that problems no longer existed rather than imposing penalties. The EDPB has instructed the DPC to investigate specific violations; in at least one case, the DPC chose not to comply but sued the EDPB instead. Critics argue that Ireland's enforcement gap—where fines are imposed reluctantly and under pressure from the EDPB—reflects the country's dependence on attracting and retaining big tech headquarters through lenient oversight.
Google's location data investigation
Ireland's DPC investigated Google's handling of location data from May 2018 (when GDPR took effect) through February 2020, following complaints filed by eight European consumer organizations. The investigation examined how Google processed user location through three separate features: web and app activity, location history, and location accuracy. Eight consumer organizations coordinated their complaints, which gave regulators multiple entry points to examine the same underlying practice.
The DPC found four distinct violations. First, Google processed location data unlawfully and unfairly—users did not receive clear information about what Google was doing with their location, nor did they understand how it would be used. Second, Google failed to demonstrate accountability for how it processed location accuracy data, violating GDPR requirements that companies show documented proof they're complying with the regulation. Third, Google's transparency disclosures were inadequate across all three features—the privacy notices and settings didn't clearly explain to users that their location would influence ads or infer their interests. Fourth, Google retained location data longer than necessary.
The practical effect: users were 'unaware that their location was being used to, for example, influence them with ads or to infer their interests,' DPC deputy commissioner Graham Doyle said in a statement. Google argued these were 'historical policies' and said it has since implemented fixes: automatic data deletion options ranging from 3 to 36 months, local storage of Timeline data on devices rather than servers, and simplified controls for ad personalization. The DPC ordered Google to bring its practices into full compliance within six months of the September 21 decision.
Why fines are becoming systematic
The €6.11 billion in cumulative GDPR fines across 2,685 cases masks an enforcement acceleration: the cumulative total grew by about €487.6 million between the CMS Enforcement Tracker's 2025 and 2026 editions. Spain issued 1,048 fines (more than any other country), while Italy, Romania, and Poland each issued between 106 and 490. The Irish DPC, by contrast, concentrated on very large fines affecting major tech companies rather than high-volume enforcement.
The most frequently cited violations involve insufficient legal basis for data processing and noncompliance with general processing principles—issues that directly affect how companies collect, use and justify their use of personal data. Regulators are expected to continue 'a strict enforcement approach,' with improved coordination through the European Data Protection Board's Coordinated Enforcement Framework. This means when one DPA investigates a company's practices, other regulators often coordinate to examine the same issues in their territories, multiplying the enforcement pressure.
“Google's €403 million fine is far smaller than Meta's record €1.2 billion GDPR penalty, but still a material cost for the company.”
Why US companies absorb these costs
Meta's €1.2 billion fine in May 2023 and TikTok's €530 million fine in 2025 are sizable penalties, but manageable against operating budgets measured in tens of billions. Withdrawing from Europe would mean abandoning a lucrative market; paying fines and adjusting practices is the business calculation these companies make. Google's €403 million fine is far smaller than Meta's record €1.2 billion GDPR penalty, but still a material cost for the company.
What this means for California businesses
Any California company serving European customers—whether selling software, operating an app, or collecting user data—must comply with GDPR rules regardless of where it is headquartered. GDPR enforcement applies extraterritorially to companies processing data of EU residents. This means California startups and established tech companies face the same GDPR penalties as Google and Meta if they violate the regulation. A startup that fails to obtain clear consent before processing European users' location data, or that retains data longer than necessary, faces the same fine structure: up to €20 million or 4% of global turnover for serious breaches.
Companies doing business across multiple US states and the EU now operate under divergent privacy rules. For California companies targeting both markets, GDPR compliance typically becomes the baseline standard, then adjusted upward for stricter state-level US requirements where they apply. The cost of GDPR compliance—legal review, privacy impact assessments, consent mechanisms, data retention policies—must be factored into European expansion plans from the start. The Google case shows that regulators have the patience to investigate for six years and impose large fines; for smaller companies lacking Google's resources to absorb penalties, GDPR noncompliance is not a minor risk but a potential existential threat.



