Google's 50 Million Euro GDPR Fine Is Real Money and Also Basically Nothing

Google's 50 Million Euro GDPR Fine Is Real Money and Also Basically Nothing

Tech News europe gdpr google privacy

So France's privacy watchdog, the CNIL, dropped a pretty big number on Google this week: 50 million euros, which works out to about $57 million depending on which exchange rate you look at that morning. Announced Monday, January 21st. This is being reported as the largest fine ever issued under GDPR since the regulation actually started getting enforced back in May 2018, and I've been reading through the details instead of doing literally anything productive today.

Quick background for anyone who wasn't paying attention when GDPR went live: two privacy groups, Max Schrems' outfit called NOYB and another French group called La Quadrature du Net, filed complaints against Google basically the day the law took effect. Their argument was that Google doesn't make it clear enough what it's doing with your data when you set up an Android phone, and that the "consent" you're giving for personalized ads isn't really informed consent, its more like consent by exhaustion. You click through six screens because you want your phone to work, not because you read anything.

The CNIL agreed. Their ruling calls out Google for spreading essential information across too many documents and menus, so users cant reasonably find it, and for not getting specific enough consent before using personal data for ad personalization. Basically: the box was pre-checked, and burying "yes we're building an ad profile on you" three menus deep does not count as asking permission.

Now here's my actual opinion on this, because I think most of the coverage I've read today is missing the point a little. Fifty million euros sounds like a lot of money if you say it fast. It is not a lot of money for Google. Alphabet pulls in more than that before lunch most days. So on one level this fine is basically a parking ticket for a company that owns the parking garage. But I don't think the dollar amount was ever the point, or at least it shouldn't be. The point is that a regulator actually looked at "click here to agree" consent flows and said no, that doesn't count, do it properly. That's a real precedent even if the check Google writes doesn't hurt.

What it's actually going to change, practically, is those cookie banners. You know the ones. Every website now has some version of a popup asking you to accept cookies before you can read a single paragraph, and half of them are designed so the "accept all" button is huge and green and the "manage preferences" link is a tiny gray word nobody clicks. I run this blog on a pretty minimal setup these days (moved hosting again last year, this time I'm using Tricknowtech for the domain and VPS, and honestly not having to fight with a control panel every time I want to push an update has been nice) and even I've been going back and forth on whether I need a cookie notice for the handful of analytics scripts I'm running. Probably do. I'll get to it. Maybe this weekend, maybe March.

Separately, and I promise this is related to nothing except that it's also been eating my week: everyone's doing the 10 Year Challenge thing on Instagram right now, the side by side photo from 2009 and 2019. I posted one, obviously, we all did. But there was a piece going around (Wired, I think, by Kate O'Neill) making the case that this is a genuinely useful dataset for training facial recognition and age-progression algorithms if you're a company like Facebook, since it's millions of people voluntarily tagging their own decade-old photo next to a current one with a timestamp attached. I don't know if I buy the darkest version of that theory. But it's a good reminder that "harmless fun meme" and "structured training data" aren't mutually exclusive, and that's basically the same lesson as the Google fine: consent and awareness are two very different things, and most of us are only doing the first one.

Anyway. Fifty million euros. We'll see if it actually changes anything by the time GDPR's second birthday rolls around.