Home / Insights / What Google’s €403m DPC Fine Means for Irish SMBs

Compliance / GDPR

What Google’s €403m DPC Fine Means for Irish SMBs

Four GDPR failings the regulator called out apply to any business holding personal data, not just Big Tech.

A gavel and justice scales on a wooden surface, representing a regulatory fine
Checklist graphic showing four GDPR compliance principles: lawful basis, transparency, data minimisation and accountability

The Data Protection Commission’s €403 million fine against Google, announced on 21 September, is one of the largest GDPR fines the DPC has issued. It is easy to read that figure and file it under “Big Tech problem”. The four failings the DPC actually pointed to are not specific to Google, or to location tracking, or to companies with global reach. They are questions any Irish business holding customer or staff data should be able to answer today.

What the DPC actually found

The inquiry examined how Google’s Location History, Web & App Activity and Location Accuracy features processed people’s location data between 2018 and 2020. The Data Protection Commission’s decision found breaches across four areas: processing that was not lawful or fair, retaining location data longer than necessary, failing to be transparent about how the data was used, and failing to demonstrate accountability, meaning Google could not show the regulator its processing was compliant when asked. Google now has six months to bring its processing into line.

The same four questions apply to your business

None of the four principles the DPC cited are unique to location data or to a company the size of Google. Every business that processes personal data, which is nearly every business, needs to be able to answer the same four questions. Do you have a lawful basis for each type of data you hold? Would a customer or employee understand how you use their data if they actually read your privacy notice? Are you deleting data once you no longer need it? And could you produce evidence of all of that if the DPC came asking tomorrow? Most Irish SMEs would struggle with at least one of the four.

Why “we’re too small to notice” doesn’t hold up

The DPC does not only investigate multinationals. Complaints from a single customer, a single former employee, or a data breach notification you file yourself can trigger a review of any business, regardless of size. Fines for smaller organisations tend to be proportionate to turnover rather than headline-grabbing, but the regulator’s expectations on the four principles above do not scale down. A five-person accountancy firm is expected to have a lawful basis for the data it holds just as much as a global platform is. The practical risk for most SMEs is not a €403 million fine, it is a slow, disruptive investigation that eats weeks of management time because the basics were never documented.

Where Microsoft 365 already gives you the tools

If your business runs on Microsoft 365, you already have most of what you need to close these gaps, it is usually just not switched on. Retention policies in Microsoft Purview let you set how long email, Teams messages and SharePoint files are kept before automatic deletion, which addresses the minimisation point directly. The same admin tools let you run a Data Subject Access Request search across mailboxes and SharePoint in minutes rather than days, rather than someone manually searching inboxes under deadline pressure. Entra ID’s access reviews and audit logs are exactly the kind of accountability evidence a regulator would expect to see, showing who had access to what data and when. The tools exist on a licence most businesses already pay for. The gap is almost always that nobody has configured them or written down why they are set the way they are.

What to do now

  • Pull up your privacy notice and check it still matches what you actually do with data.
  • Check whether retention policies are switched on in Purview, or whether old mailboxes and shared drives are quietly holding years of data nobody needs.
  • Confirm you could run a Data Subject Access Request search and respond within the one-month GDPR deadline if someone asked today.
  • Write down your lawful basis for the main types of personal data you hold. It does not need to be long. It needs to exist.
  • If you are also in scope for NIS2, your security and data protection obligations increasingly overlap, worth reading our piece on whether NIS2 applies to your business.

None of this needs a six-figure compliance programme. It needs an hour with someone who knows where the settings live in Microsoft 365 and what a regulator actually expects to see. That is exactly what our IT compliance and NIS2 support covers.

Not Sure Where Your Business Stands on GDPR?