DEV Community

Amr Abumady
Amr Abumady

Posted on Originally published at clientn.com

What Google's €403M and $463M Fines Actually Mean for Your Login Table

Google was just fined €403M by Ireland's DPC and $463M in a separate action, both tied to how location and account data was collected and retained (Irish Times, 2026-09-21; ABC News). Neither fine is about a breach — it's about retention: data a company was allowed to collect but kept, correlated, or reused longer than the stated purpose required.

For small and mid-size sites, the same liability shows up in a much smaller, more boring place: your login table. Most auth systems ask for an email up front and keep it forever, whether or not the user ever comes back. That's a data-retention liability you're taking on for zero product benefit in the first session.

The pattern we've been building around

We've been working on ClientN, a free passkey-based sign-in you can drop into a site alongside (or instead of) email/password. Two things about the shape of it are relevant to the fines above, not because ClientN is a GDPR product, but because minimizing what you store is the actual fix, not a bigger cookie banner:

  • Each site gets a different anonymous ID for the same person (CN-xxxxx), not a shared identifier you could correlate against other sites.
  • You never see or store the person's email unless they explicitly opt to share it with you.

That's it — it doesn't replace your GDPR review, but it removes an entire category of data you'd otherwise be sitting on and eventually explaining to a regulator.

Trying it

Free for sites up to 1,000 logins/month:

Curious how other devs are thinking about minimizing account-data retention post-fines like these — what's in your login table today that doesn't need to be?

Top comments (0)