Google will pay off its new €403M GDPR fine in just 55 hours, warns Proton

Google signage at the Google I/O Developers Conference in Mountain View, California, US, on Tuesday, May 19, 2026.
(Image credit: Getty Images / Bloomberg)

  • Google hit with €403M for the unlawful processing of user location data
  • Proton calculates Alphabet can cover the penalty in just about two days
  • Multi-million fines are failing to deter Big Tech repeating GDPR violations

The news that Ireland's Data Protection Commission (DPC) fined Google €403 million (around $462 million) for the unlawful processing of users' location data may sound like a monumental victory for consumer privacy. Yet, industry experts are already warning that the fine is simply too small to force a change in corporate behavior.

According to the privacy firm Proton, Google's parent company, Alphabet, will be able to brush off the historic penalty in less time than it takes to enjoy a long weekend.

"Google will barely notice this fine," noted Jurgita Miseviciute, Head of Public Policy at Proton. "When one of the biggest weapons in the EU's arsenal only costs the offender two days of revenue, it's not a deterrence."

For everyday internet users looking to protect their digital footprint with the best VPN or secure browser, this latest ruling serves as a stark reminder of how profitable your personal data remains.

Proton VPN – best for privacy $2.99 per month

Proton VPN – best for privacy
Based in Switzerland, this privacy-first VPN offers good speeds, advanced anti-censorship features, and a server network that spans 145 countries around the world — including across Africa and Asia, where other providers tend to struggle. While its free VPN plan is handy, it comes with limitations. The good news is that upgrading to a premium subscription will cost you only the equivalent of $2.99 per month.

A multi-million euro 'slap on the wrist'

Following a lengthy inquiry, the DPC announced the enforcement action against Google over controversial location data practices that occurred between 2018 and 2020. It represents one of the largest GDPR penalties the search giant has ever faced.

However, for a company the size of Alphabet, the impact is mathematically minuscule. Based on Alphabet’s own reported 2025 free cash flow of $73.3 billion, which breaks down to roughly $200 million a day, Proton notes that Google's cash flow alone could cover the fine in about two days and seven hours.

To put that into perspective, that is roughly 55 hours, or 199,000 seconds of standard revenue generation.


Leave No Trace logo

(Image credit: Future)

NEW: Leave No Trace — A weekly newsletter on digital privacy and online surveillance.

Leave No Trace investigates the companies and governments putting our digital freedom at risk — and the people fighting back.

📩 Subscribe now to get every edition delivered to your inbox every Friday, launching this September.


The illusion of deterrence

The €403 million fine is not an isolated incident. In 2025 alone, Google picked up five separate fines totaling nearly $4.24 billion. Thanks to its massive financial reserves, the company's free cash flow could replace that entire sum in roughly three weeks, a trend that echoes broader warnings that Big Tech could need only one month to pay off over $7 billion in collective 2025 fines.

This mirrors an equally dismal pattern from the previous year, when the industry needed less than three weeks to pay off over $8 billion in 2024 penalties.

This recurring pattern has left privacy advocates frustrated by the limitations of the European Union's current regulatory framework.

Miseviciute from Proton emphasized that the lack of financial sting makes these penalties a mere cost of doing business rather than a mechanism for actual reform.

"Time and time again fines makes [sic] headlines without changing Big Tech's behaviour at all," she added. "If regulators are serious about compliance, the penalties have to actually bite."

For consumers, this means the responsibility for data security largely remains in their own hands. Location data is uniquely sensitive, capable of revealing everything from your home address to your daily routines and medical visits.

Until regulators find a way to issue penalties that genuinely threaten a tech giant's bottom line, companies will continue to calculate that the astronomical profits of aggressive data harvesting far outweigh the minor risks of a regulatory fine.


Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!


TOPICS
Rene Millman
Contributing Writer

Rene Millman is a seasoned technology journalist whose work has appeared in The Guardian, the Financial Times, Computer Weekly, and IT Pro. With over two decades of experience as a reporter and editor, he specializes in making complex topics like cybersecurity, VPNs, and enterprise software accessible and engaging.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.