Executive Summary
The entity that answered for Google’s location data is its Dublin establishment, and Ireland’s Data Protection Commission acted as Lead Supervisory Authority, so a decision taken by one national regulator binds 27 member states. The fine is 403 million euros, about $463 million, and Google has six months to bring that processing into compliance.
Four findings span lawfulness, fairness, transparency, accountability and retention across Web & App Activity, Location History and Location Accuracy. The pattern matters more than the penalty. An accountability finding tests whether you can evidence your basis rather than whether you intended to comply. Retention counted as an aggravating failure in its own right. And the entity a non-EU company chooses to operate through decides which regulator gets to name it and which law it has to answer under.
Ireland’s Data Protection Commission fined Google Ireland Limited 403 million euros on 21 September, about $463 million, for mishandling location data. The regulator also ordered the company to bring that processing into compliance within six months.
The inquiry opened in February 2020 after complaints from European consumer rights organisations, including BEUC. It covered three features, Web & App Activity, Location History and Location Accuracy, from 25 May 2018 to 4 February 2020.

The regulator fined the Dublin entity, not the American parent
The decision names Google Ireland Limited. Not Alphabet, and not Google LLC. The Irish establishment answers for the group’s processing of European users’ data, and Ireland’s regulator acts as the Lead Supervisory Authority for the company across the bloc.
That detail is the one worth understanding. The European Union did not reach across the Atlantic. It regulated the subsidiary that operates inside its borders, and one national regulator produced a decision that binds 27 member states.
This is what digital sovereignty looks like once it stops being a slogan. It is not a firewall or a flag on a data centre. It is jurisdiction, and jurisdiction attaches to the entity you choose to operate through.
The fine is absorbable, the six month order is not
Alphabet can pay 403 million euros without convening the board. Google called the case one about “historical policies that have since been updated”, which is the standard answer to a penalty that covers 2018 to 2020.
The remedy is the harder part. Six months to change how location data is processed, and the findings reach past consent screens into engineering. The regulator found that Google failed its accountability obligations for Location Accuracy, meaning it could not demonstrate that its processing met the lawfulness, fairness and transparency principle. That is a finding about evidence, not intent. You have to be able to show the basis, which means records and retention rules a regulator can inspect.
Retention was also a finding. Holding location data longer than necessary was treated as an aggravating failure, not a filing error.
The pressure is not easing. The European Commission fined Google 890 million euros in July under the Digital Markets Act, its first penalty under that law, with 60 days to comply or face up to 5 percent of worldwide turnover. Ireland’s regulator has now issued more than 4.4 billion euros in fines. Google’s own account of the changes it has made, including auto-delete controls, is set out in the BBC report.
What non-EU companies should take from it
Be precise about what this case was not. Nobody ordered Google to store European data inside Europe. The findings were about lawfulness, fairness, transparency, accountability and retention.
The enforcement mechanism is still the sovereignty story. The regulator that just fined Google is the same regulator that governs your European subsidiary, and the entity you operate through is the one that gets named. Which entity holds the customer contract, where the data physically sits, who can read it, and how long you keep it stop being preferences. They become the inputs to your compliance position.
Three things follow for platform teams at non-EU companies. Know which legal entity contracts with European customers and whether it is established in the bloc. Keep a data inventory that can answer where location and device data lives and who can reach it. And put a retention clock on anything you have no reason to keep, because retention was a finding here rather than a footnote.
Related reading. Sovereign cloud is not data residency, and the gap costs money covers why the two get confused. Digital sovereignty is a procurement problem, not a data center one explains why the contract decides more than the rack. And workload sovereignty is the only sovereignty you can test gives you a way to check the claim instead of trusting it.
Get the next one before it is old news
Independent analysis of cloud-native infrastructure, Kubernetes and data centre economics. No vendor spin.
