When a regulator hands down a verdict, the number is the headline and the language is the story. Ireland’s data privacy ruling against Google came with a €403 million tag, but the more durable part of the decision is the way the regulator spelled out which product behaviours crossed the line, in language close enough to the actual product that a non-lawyer can match each finding to a setting. That kind of verdict reads as a template, not just a verdict.
Below is what stood out to me when I read the report, why the choice of Ireland as the regulator matters for readers who have never been to Europe, and the one question this ruling should put on your phone’s settings screen the next time you open it.
The Ireland question, and why it reaches your account
A lot of readers see “Ireland” in a privacy headline and assume it does not apply to them. That is the wrong read. Most large US tech companies, including Google, Meta, Apple, and Microsoft, route their European operations through Ireland because of how the tax and regulatory framework was set up over a decade ago. That structural choice has a side effect: Ireland’s privacy regulator became the lead enforcement body for those companies under the EU’s General Data Protection Regulation, the privacy law that took effect in May 2018.
Verdicts from the Irish regulator do not stay in Ireland. They extend across the EU, and they tend to set expectations in the UK, Canada, and other places with comparable rules. For a reader in the US, the practical implication is that the same settings cleanup that shows up in your Google Account today is partly the consequence of an Irish ruling, whether or not the regulator was looking at your specific country. Companies rarely run separate products per jurisdiction. They clean up the global product once, because divergent behaviour is more expensive than cleanup.
That is the lens I want to use for the rest of this piece. The €403 million is the news. The cleanup you have already seen in your phone over the last five years is the consequence.
What the regulator actually wrote
The investigation covered the period starting May 25, 2018, the day GDPR took effect, and ending February 4, 2020. The regulator named three specific features in the verdict rather than issuing a single global finding, and published separate conclusions for each one. Three things stand out from the report.
Finding one centred on whether Google could show a valid legal basis for handling location data through Web and App Activity and Location History. In privacy law, the term “legal basis” refers to the reason a company is allowed to use your data in the first place. Standard grounds are consent, contract necessity, and legitimate interest, and regulators scrutinise each one carefully. The Irish view was that none of those grounds held up under scrutiny. Finding two covered whether Google met GDPR’s basic data principles when handling data through Location Accuracy. Those principles include things like data minimisation, purpose limitation, and storage limitation, which together say collect only what you need, use it only for the stated reason, and do not keep it forever. The regulator found Google fell short across the board. Finding three was about transparency duties. As Deputy Commissioner Graham Doyle said in the public statement, users might not have known that their location was being used to show them ads or to figure out their interests, and they could have given up control over their personal data without realising it. Storing the data longer than necessary made that loss of control worse.
The point worth noticing is not any single finding but the way the regulator wrote them. Each finding maps to a setting on your phone, in the same words the company uses in its own product.
What the company actually changed and what stayed
Google’s public position is that the case is about policies that have already been revised. Part of that is true. The company did refresh its account controls in 2019 and after, including easier controls for location saving and auto-delete options that did not exist when the violations happened. Anyone who has opened the Google Account settings in the last few years has seen the cleaner layout and the explicit auto-delete choices.
The features themselves still exist, though. Web and App Activity, Location History, and Location Accuracy are still in your account or on your phone right now, on by default for most users. Improved defaults are still defaults. If you never touch the settings, the same data flows continue, just with a clearer consent screen in front of them. Google can claim the policy changed while the underlying product keeps behaving the same way. Privacy enforcement tends to fix the worst paper trail, not always the underlying product.
- Web and App Activity: still on by default, still saves search history across Google services
- Location History: still opt in, but the opt-in screen is now clearer and the auto-delete options are explicit
- Location Accuracy: still runs on Android by default, still uses Wi-Fi and Bluetooth to improve GPS
- Auto-delete options: did not exist when the violations happened, now a standard toggle in the privacy settings
The audit you can run tonight if you want to
A settings walkthrough is not what I want this piece to be. Walkthroughs age badly the moment Google ships an interface update. Instead, the question I would put in front of you is this: if a regulator opened your phone tomorrow and walked through the same three findings, which of the three behaviours would you wish you had turned off?
That question is the practical version of what the regulator was actually testing. The settings on your phone are the same as the ones the regulator looked at, just in a different default state. If the answer is “I would not have turned any of them off,” you are probably fine. If the answer is “I would have turned Location Accuracy off because I do not need Wi-Fi and Bluetooth positioning,” the change is one toggle. If the answer is “I would have turned Web and App Activity off because I never use the personalised features,” the change is one toggle in myactivity.google.com. None of these changes are irreversible. None of them will stop every data flow Google is involved in, because if you use Google Maps, Gmail, YouTube, or Android, you are inside Google’s data footprint in ways no setting can fully escape. But the audit is the cheap way to find out where on that line you actually want to sit.
What I would tell past me about privacy rulings
Three things, looking back at how many privacy decisions I have watched play out over the last decade:
- The headline fine is rarely the consequence that matters. The consequence that matters is the cleanup the company does to its default settings across the global product, because that cleanup is what changes your phone.
- Regulator findings are usually worth reading in full. They are written by lawyers who know the specifics, and the specifics are usually the same switches on your phone.
- An audit you run tonight will be wrong in six months, because defaults drift and new features get added. Set a calendar reminder for the same time next year. Five minutes will buy you another year of surface area you control.
Trade-offs
An audit is not free in time or convenience. Personalised search gets duller without Web and App Activity. Location History’s Timeline goes away (or shortens) if you tighten it. Google Location Accuracy’s Wi-Fi and Bluetooth positioning gets noticeably worse in dense urban areas, where plain GPS struggles. None of those trade-offs are deal-breakers for most readers, but they are real. The decision is whether you want Google’s apps to remember everything, or whether you want to keep your phone from being a complete record of your day. The audit is the cheap way to find out which side of that line you are on.
For anyone reading the news cycle: do not let the headline euro figure distract you from the more useful signal. The regulator’s findings list is the part that maps to your own phone. The cleanup you have already seen in your default settings over the last five years is the part that already changed your phone. The €403 million is the verdict. Your settings are the consequence. The next audit you run is the part you control.