Two of the three findings against Google are not about what it collected. They are about what it could not show. On September 21 Ireland's Data Protection Commission announced fines totalling €403 million against Google following an inquiry into its processing of location data, and ordered the company to bring that processing into compliance within six months.
This is a privacy decision about location data, not a breach and not a secret-handling story. It is worth reading anyway, because the reasoning transfers cleanly to any organisation holding sensitive data it has never been asked to justify.
What is confirmed
The DPC's decision, announced 21 September 2026, concerns three Google features: Web & App Activity, Location History, and Location Accuracy. The inquiry was launched in February 2020 and examined the period from 25 May 2018 to 4 February 2020.
The DPC found infringements in three areas. On lawfulness and fairness, it found Google infringed those requirements in Web & App Activity and Location History, and that for Location Accuracy Google failed to demonstrate compliance with the lawfulness, fairness and transparency principle. On transparency, it found infringements across all three features. And on retention, it found Google kept location data collected through Web & App Activity and Location History for longer than was necessary. The DPC also found infringements of accountability obligations.
The corrective order is compliance within six months. Reporting adds that Google may appeal to the Irish High Court within 28 days of formal notice, and that a DPC fine becomes payable only once an Irish court confirms it — so the headline figure is a decision, not yet a payment.
What remains unknown
The DPC's press release does not enumerate the specific GDPR article numbers, so anyone citing them should read the full decision rather than a summary. It is not public whether Google will appeal, and the DPC has not said publicly what changes would satisfy the six-month order. The examined period ended in February 2020; the decision says nothing about current behaviour, and it would be wrong to read it as a finding about how these features work today.
One more caveat on the number: several reports give the fine in dollars, at figures around $460–463 million. That is currency conversion of the same €403 million, not a different penalty.
The part that transfers
Strip out location data and three questions remain, and every organisation holding sensitive information has to be able to answer them on demand:
- On what basis are you processing this? Not “why it is useful” — on what lawful basis, recorded before the processing started.
- Do the people concerned understand it? Transparency was infringed across all three features. A setting that technically discloses something a user cannot reasonably follow is where these findings tend to land.
- Why do you still have it? The retention finding is the one most organisations would fail. Data is kept because deleting it requires a decision and keeping it does not.
The accountability thread is the sharpest of the four. For Location Accuracy the finding was that Google failed to demonstrate compliance. That is a different kind of failure from doing the wrong thing: it says the records were not there to show the right thing had been done. An organisation can be handling data carefully and still lose this argument, because careful handling that leaves no evidence looks identical to carelessness from the outside.
What to do about your own retention
- Write down the retention period for each category of sensitive data you hold, with the reason. “Indefinitely, in case we need it” is the answer that produces findings. If a category has no owner, that is the first thing to fix.
- Make deletion the default and keeping it the exception. Expiry that happens automatically survives staff turnover; a quarterly cleanup task does not.
- Separate the record of an event from the sensitive content of it. You usually need to prove that an access happened, to whom and when — not to keep a copy of what was accessed. Keeping the evidence while dropping the payload reduces exposure without weakening your audit trail.
- Check what your logs are quietly accumulating. Operational logging is where retention policies go to be ignored: request bodies, headers, error dumps and support attachments outlive the policy that governs the database.
- Keep the decisions, not just the outcomes. Record who decided a retention period, when, and on what basis. That record is what “demonstrate” means in practice.
- Re-check inherited data. Anything imported from an acquisition, a migration or a departed vendor arrived with someone else's retention assumptions and usually nobody's documentation.
Where Secretus fits—and where it does not
A one-time channel is a retention decision expressed as a mechanism: a value delivered through something that stops existing leaves less behind than the same value sitting in a mailbox or a ticket that both outlive it. For Business accounts, the audit log and the compliance report are intended to help you show that a transfer happened and who was involved, which is the evidence side of the questions above.
What it emphatically is not: a determination about anyone's legal position. Using Secretus does not establish compliance with GDPR or any other regime, the compliance report is a support artefact for your own auditor rather than proof of certification, and none of this is legal advice. Applicability depends on your organisation, your jurisdiction and your own controls. Read the DPC's decision, and ask your counsel what it means for you.
Sources
- Data Protection Commission: fines Google €403 million following inquiry into Google's processing of location data, 21 September 2026
- The Hacker News: Google fined €403 million over GDPR violations tied to location data
- BleepingComputer: Google fined €403 million over location data privacy violations
- The Record: EU data regulator fines Google over location data violations
