
€403M Fine on Google: What Global Enforcement Means for India’s DPDPA Landscape?
When a legacy UX decision costs €403 million, “industry standard” is no longer a defense. India is sitting on a time bomb of legacy data only.
Ireland’s Data Protection Commission (DPC) has penalized Google €403 million over historical location-tracking practices across Web & App Activity, Location History, and Location Accuracy.
The regulatory verdict is absolute: opaque opt-outs, prolonged data retention, and deceptive setting configurations degrade user agency directly violating statutory principles of lawfulness, fairness, and transparency.
As India’s Digital Personal Data Protection Act (DPDPA) framework takes effect, Indian boards, product leaders, and legal counsel must treat this ruling as a blueprint for risk:
Explicit Consent Over Implicit Design: Section 6 of the DPDPA mandates clear, affirmative, and unbundled consent. Burying tracking permissions in general terms or relying on friction heavy opt-outs is now a primary compliance liability.
Purpose-Bound Retention: Retaining location vectors “just in case” directly violates purpose limitation mandates. Under DPDPA, once the primary service fulfilment ends, data erasure must be automated and accounted for.
The Cost of Obfuscation: With DPDPA penalties capping up to ₹250 crore, dark patterns and ambiguous data collection flows are no longer growth tactics rather, they are overconfident corporate liabilities.
How is your executive team stress-testing product design against upcoming DPDPA enforcement? Days are limited, responsibility is bigger, be Responsible!
This blog is an academic initiative brought to you by the Data Privacy Pro team of AMLEGALS. Subscribe – Stay updated, Stay compliant.
