may 2018 to february 2020

Ireland fined Google €403 million on Monday. The fine is for conduct that stopped six and a half years ago.

The Irish Data Protection Commission announced the penalty on 21 September: Google did not lawfully or fairly process location data in Web & App Activity and Location History, and failed to be lawful, fair and transparent in the Location Accuracy feature in Android. It is among the largest sanctions the DPC has issued since the GDPR took effect.

The number everyone printed was €403 million. The number worth printing is the date range.

The conduct covered runs from 25 May 2018 — the day the GDPR became applicable, so literally the first day this was enforceable — to 4 February 2020. Google’s response is that the case concerns historical policies and that it updated its practices from 2019 onward.

Six and a half years from the end of the conduct to the decision.

The regulatory clock and the product clock are not running in the same units. Android shipped seven major versions in that gap. The consent flows under investigation were replaced, twice, by teams that have since reorganised. Whatever this fine is doing, it is not stopping the thing it describes, because the thing it describes has not existed for most of a decade. You cannot deter a build that no longer compiles.

The obvious retort is that the delay is the price of doing this properly — cross-border coordination, draft decisions, objections from other supervisory authorities, the Article 60 machinery, and the simple fact that a fine which survives appeal has to be built carefully. That’s true, and it isn’t a trivial defence. A regulator that moved in six months would lose in court in eighteen, and a fine that gets vacated deters nothing at all.

But a lag that stable is a lag you can model. And anything you can model, you can price. Six years at some discount rate, times a probability of enforcement, against revenue booked immediately and compounding the whole time — that arithmetic has an answer, and the answer is usually “ship it.” The deterrent stops being a deterrent somewhere around the point it becomes forecastable. It turns into a line item with a long payment term.

I don’t think the DPC is doing this wrong, exactly. I think the instrument is mismatched to the medium. Fines are a tool built for factories, where the offending conduct is a process that keeps running until somebody makes it stop. Software changes underneath the investigation. By the time the penalty lands it is archaeology with a wire transfer attached.

The remedy side is more interesting than the money, and got a fraction of the coverage: Google has six months to bring its location processing into compliance. That’s an order about the present. The €403 million is an invoice about the past.

Enforcement that arrives this late isn’t a rule. It’s a receipt.


Sources: Google faces €403 million fine for violating EU location data regulations, European Interest ↗ · Google hit with $463 million fine for EU location data rule breach, SecurityWeek ↗ · Google fined $463 million for breaching EU rule on location data, TechXplore ↗