Ireland's Data Protection Commission has fined Google €403m for processing users' location data without a valid legal basis under GDPR. The investigation, triggered by complaints from seven European consumer organisations, found that Google users could have been unaware their location was being harvested to target them with advertising or to infer sensitive details about their health, religion, political leanings, and sexual orientation. The complaint originated from research by Norway's Forbrukerrådet, which documented how Google used design patterns — what they called "various tricks" — to keep location history and web-and-app activity enabled by default. The DPC's inquiry covered the period from 25 May 2018 (when GDPR took effect) to 4 February 2020, examining three specific features: web and app activity, location history, and location accuracy. Deputy Commissioner Graham Doyle emphasised the dual nature of location data: useful for services, dangerous for privacy. Location tracking can reveal visits to places of worship, hospitals, political demonstrations, and specific bars — building a detailed profile of beliefs, health conditions, and sexual orientation without the user's meaningful awareness. The retention of this data beyond necessity compounded the harm. The €403m fine sounds large in isolation but slots into a pattern. The DPC has previously fined Meta €1.2bn, TikTok €530m, and Instagram €405m. Google's fine is the fourth-largest in the regulator's history. Three additional large-scale Google inquiries remain open and are reportedly at advanced stages. The structural problem is time. The complaints were filed circa 2018-2019. The investigation launched six years ago. The fine arrives in 2025. During those six years, the location data extraction it punishes was already happening at scale across hundreds of millions of European users. Google now has six months to bring its processing into compliance — meaning the actual behavioural change may not land until 2026, a full eight years after GDPR took effect. For Google, €403m is a cost of doing business — roughly equivalent to a few days of Alphabet's advertising revenue. The fine-as-deterrent model assumes the penalty exceeds the profit from non-compliance. There is no public evidence that GDPR fines have crossed that threshold for any major platform. The enforcement architecture punishes past behaviour rather than preventing ongoing extraction. The deeper question is whether centralised enforcement through a single national regulator (Ireland, by virtue of hosting EU headquarters for US tech) can keep pace with the scale and speed of data extraction. Three more Google investigations are pending. Each will take years. The extraction continues in the interim.