Enforcement

Google's €403 Million GDPR Fine Is a Warning for Every Website Owner

Fabio Cerullo  ·  9 October 2026


Ireland's Data Protection Commission (DPC) has fined Google €403 million over unlawful processing of users' location data — one of the largest GDPR enforcement actions of 2026, and a reminder that European regulators are not slowing down. The DPC's investigation found that Google had been processing location data without a valid legal basis under the GDPR.

It's tempting to read a headline like this and file it under “big tech problem.” It isn't. It's a GDPR enforcement problem, and it reaches far smaller organisations than Google every single month.

The number behind the number

Since the GDPR came into force in 2018, cumulative fines across the EU have now passed €7.1 billion, and the pace of enforcement has only accelerated — 2026 alone has already seen multi-million-euro penalties handed down in Ireland, France, Italy and the UK, covering everything from location tracking and adtech to simple failures in handling an employee's personal data after they'd left the company. Regulators are no longer waiting for a breach to investigate; routine audits, user complaints, and even automated scans of a company's own website are enough to open a case.

That last point matters more than most businesses realise.

Cookie consent: the violation regulators can spot without opening an investigation

Most GDPR fines start with a complaint or a formal audit. But there's one category of non-compliance that any regulator, journalist, competitor, or customer can check in under a minute, with nothing more than a browser: whether your website is setting tracking cookies before a visitor has actually consented to them.

It's one of the most common violations of the GDPR and the ePrivacy Directive, and it's also one of the easiest to get wrong without ever realising it. A cookie banner that looks compliant — with clear “Accept” and “Reject” buttons — can still be firing Google Analytics, ad-tech pixels, or third-party trackers the moment the page loads, regardless of what the visitor chooses. The banner is cosmetic; the cookies fire anyway.

This is exactly the kind of gap that turns into a regulatory finding, a lost enterprise deal (most security questionnaires now ask about it directly), or — as this week's news shows — a very public fine.

How to find out if your site has this problem

We built ConsentScan to answer this one question quickly and for free: is your website setting non-essential cookies before consent is given?

Enter your domain and ConsentScan loads your site the way a first-time visitor would, catching any cookies that fire before you've made a choice. It then:

  • Grades your site from A to F, based on the number of non-essential cookies detected pre-consent (A means none; F means ten or more)
  • Names every cookie and its vendor, so your developers know exactly what to fix and who it belongs to
  • Offers a full cookie-by-cookie PDF report you can forward straight to your dev team or DPO, if you want more detail than the grade alone

You don't need to provide an email to see your grade, and the scan takes under a minute.

What to do if you get a C or lower

A poor grade doesn't mean you're facing a €403 million fine tomorrow — but it does mean you have exactly the kind of gap regulators, auditors, and enterprise procurement teams are now routinely checking for. If your scan turns up pre-consent tracking, the fix usually falls into one of three buckets:

  1. Consent management platform (CMP) misconfiguration — the most common cause. Your CMP is installed, but tags aren't actually gated behind the consent signal.
  2. Tag manager sprawl — cookies fired directly by scripts outside the CMP's control, often added by a marketing team or agency without IT's knowledge.
  3. Missing or incomplete vendor disclosures — cookies present in your banner's policy text that don't match what's actually firing on the page.

If you're not sure which of these applies to you, that's exactly the kind of gap a short GDPR/ePrivacy compliance review closes quickly — and it's far cheaper to fix proactively than to explain after the fact. If you're seeing pre-consent tags fire from Google Tag Manager specifically, our guide on why GTM fires cookies before your CMP loads walks through the fix.

Is your site setting cookies before consent?

Get an A–F grade and a named list of every pre-consent cookie in under a minute. No email needed.

Run your free scan →

Cycubix provides secure coding training, CISSP certification, vCISO services, and compliance advisory — including GDPR, NIS2, ISO 27001, and SOC 2 — for finance, government, telecom, and technology organisations in Ireland and globally.