Somewhere in a European headquarters this week, a compliance officer is opening a spreadsheet of cookie categories, a regional counsel is drafting a memo about consent banners, and a data protection lead is trying to explain to an American product manager why the version of the website that ships in Frankfurt cannot be the version that ships in Fresno. This scene, repeated across thousands of firms with any exposure to the European market, is the quiet everyday consequence of a regulatory regime that has spent the better part of a decade teaching global companies an expensive lesson: geography still matters, even on the internet.
Google, of all companies, keeps learning it the hard way.
The pattern is familiar enough that it now reads as a script. A US-based platform designs a product for a global user base. The default settings reflect Silicon Valley assumptions about consent, tracking, and data flows. The product ships. European regulators arrive with a fine. The company appeals. Years pass. The fine is upheld, reduced, or, occasionally, overturned on a technicality that has nothing to do with the underlying behavior.
Across Europe, privacy engineers spend their working days translating US product decisions into something local data protection authorities will not object to. These jobs exist because of a specific gap: the gap between how a product is designed and where it is deployed. That gap is where the fines live.
Google’s long-running appeal of a record EU fine ended this year with the company on the hook for roughly $4.7 billion, tied to the practice of bundling its search engine and browser with Android. The case had nothing to do with GDPR directly, but it belongs to the same broader story: a US platform assuming that what works in one market works in all of them, and a European regulator disagreeing, expensively.
The first lesson, then, is the most obvious one, and it is the one most consistently underestimated in product meetings held eight time zones away from Brussels. Default settings are not neutral. They are a policy choice. When a location-tracking toggle is on by default, when a consent banner is designed to make “accept all” the path of least resistance, when a tracking pixel is dropped before a user has meaningfully agreed to anything, a company is making a claim about what users have consented to. European regulators, on the available evidence, do not accept that claim.
The Helsinki Administrative Court’s recent handling of a €1.1 million fine against pharmacy chain Yliopiston Apteekki is instructive here, and instructive in an unexpected way. The court found that the pharmacy had in fact acted contrary to GDPR through its use of Google and Meta tracking technologies between 2018 and 2022. The behavior was a violation. The fine was overturned only because administrative penalties under the regulation cannot be imposed on independent public law institutions, a category that includes universities and, by extension, university-owned pharmacies.
The finding of wrongdoing stood. The financial penalty did not. That distinction matters, because it tells you what European enforcement actually looks like: a slow, procedural grind in which the substantive question of whether tracking was lawful is answered separately from the question of whether this particular defendant can be fined for it. Companies without a public-law shield do not enjoy that separation.
General counsels at mid-sized ad-tech firms across Europe have seen their inboxes this year become a running commentary on the state of European enforcement. Enforcement activity has not slowed in 2025, whatever the political mood music from Washington suggests, and the pipeline of investigations and appeals continues to move.
The second lesson follows from the first. Geographic segmentation is not a workaround. It is the product. Any global platform operating in the EU is, functionally, running a European product and a non-European product, whether or not it admits this internally. Firms that treat the European variant as an afterthought — a set of banners and toggles bolted onto the real product — tend to be the firms that end up in the headlines. Firms that treat it as a genuine engineering problem, with its own defaults, its own data flows, and its own consent architecture, tend not to.
This is where the deeper structural point that Brussels has been circling for years becomes hard to avoid. Europe regulates the infrastructure it does not own. WhatsApp is used by an estimated 85% of European smartphone owners, with penetration above 90% in Italy and Spain. Instagram shapes visual culture. Google structures how the continent accesses news. The rules are European. The code is not. That asymmetry produces exactly the kind of enforcement pattern that keeps catching US firms off guard: regulators with genuine legal authority over products they did not build and cannot easily replace.
The third lesson is the one most product teams resist, because it is the one that costs the most to internalize. Compliance is not a phase. It is a permanent feature of doing business in the market. The fines Google has absorbed for misleading location-tracking settings on Android were not one-off events to be endured and forgotten. They were data points in a decade-long conversation about what “consent” means when the interface is designed by one of the largest companies on earth and the user is a commuter checking directions on a phone.
Product managers working on consumer apps with European user bases find their calendars full of reviews they did not have to schedule five years ago: quarterly privacy audits, consent-flow revisions, vendor assessments, data-processing agreements. None of these produce features. All of them prevent fines. The economics of that trade-off only make sense if you understand that the alternative is not zero cost. The alternative is a regulatory letter, an appeal, and a number with nine digits at the end of it.
The people who seem to handle this well are not the ones with the largest legal teams. They are the ones who stopped expecting the regulatory environment to become simpler some years ago and built accordingly. They assume friction. They design for it. They treat European deployment as a first-class engineering concern rather than a translation task.
There is a temptation, particularly in US coverage, to read every European fine as evidence of protectionism, or as a shakedown, or as a sign that the continent is hostile to innovation. That reading is comforting, and it is mostly wrong. The fines are the visible surface of a set of choices Europe made about what personal data is, who owns it, and what companies have to do to use it. Those choices are contestable. They are also, at this point, settled law with a substantial enforcement apparatus behind them.
Google’s ongoing GDPR difficulties are not the result of one bad decision or one careless launch. They are the compounding cost of a business model that assumes users will accept whatever default is presented to them, running into a legal regime that assumes the opposite. Neither side is going to blink. The fines will keep arriving. The appeals will keep failing, or occasionally succeeding on narrow procedural grounds that do not change the underlying finding of wrongdoing.
The companies that will do best in this environment are the ones that stop treating each enforcement action as a surprise. The surprise ended years ago. What remains is the work.