The European Union just hit Google with a €403 million ($463 million) fine for secretly tracking citizens' locations — and ordinary Americans can only watch, because Washington has never lifted a finger to protect your privacy the same way.

Ireland's Data Protection Commission found Google violated EU privacy law across three features — Web & App Activity, Location History, and Location Accuracy — by failing to be transparent about how it tracked users, keeping their data longer than necessary, and using it to target ads without meaningful consent. The EU has a law, a regulator, and a penalty with teeth. The United States has none of the above.

The DPC investigation, opened in 2020 after complaints from seven European consumer organizations, covered Google's conduct from May 2018 to February 2020. The regulator determined Google didn't fairly or lawfully process location data in Web & App Activity and Location History, failed transparency rules across all three features, and violated data retention requirements. Users "could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data," DPC Deputy Commissioner Graham Doyle said in a statement. "The retention of users' location data for longer than necessary aggravated this loss of control."

The complaints were built on research by the Norwegian Consumer Council, which found Google used "various tricks" to steer users into leaving tracking enabled. The Norwegian research warned that location data can reveal religious beliefs, political leanings, health conditions, and sexual orientation — the kind of intimate profile any government or corporation could abuse. The European Consumer Organisation called geolocation data "one of the most invasive forms of consumer surveillance."

Google's defense? That was then. "This case centers around historical policies that have since been updated," a spokesperson said, pointing to auto-delete controls introduced from 2019 onward. The company has six months to bring its processing into compliance.

The Guardian framed the story around Google "manipulating users into agreeing to be constantly tracked." TNW and Reuters kept it clinical — breaches of lawfulness, fairness, transparency, accountability. The Verge buried its own lede, burying Doyle's quote about ad influence under a wall of newsletter signups. Engadget noted this is hardly Google's first EU headache — the company already lost a final appeal over a $4.7 billion Android antitrust fine and a separate $1 billion fine for prioritizing its own services in Search.

But here's what none of these outlets linger on: this only happened because Europe passed a law and funded a regulator. The DPC has levied more than €4 billion in total fines against US tech giants under GDPR — including €1.2 billion against Meta and €530 million against TikTok. Meanwhile, Congress has spent years holding hearings and producing exactly zero federal privacy legislation. No law. No regulator. No fine. Your location data is bought and sold on the open market, and the permanent Washington class is fine with that — because Silicon Valley's lobbying operation and the revolving door between Big Tech and the agencies that would oversee them ensure nothing changes.

Three more statutory inquiries into Google are already at an advanced stage in Ireland. Americans will read about those fines too — from the outside looking in.