Google was just fined €403M by Ireland's DPC and $463M in a separate action, both tied to how location and account data was collected and retained (Irish Times, 2026-09-21; ABC News). Neither fine is about a breach — it's about retention: data a company was allowed to collect but kept, correlated, or reused longer than the stated purpose required.
For small and mid-size sites, the same liability shows up in a much smaller, more boring place: your login table. Most auth systems ask for an email up front and keep it forever, whether or not the user ever comes back. That's a data-retention liability you're taking on for zero product benefit in the first session.
The pattern we've been building around
We've been working on ClientN, a free passkey-based sign-in you can drop into a site alongside (or instead of) email/password. Two things about the shape of it are relevant to the fines above, not because ClientN is a GDPR product, but because minimizing what you store is the actual fix, not a bigger cookie banner:
- Each site gets a different anonymous ID for the same person (
CN-xxxxx), not a shared identifier you could correlate against other sites. - You never see or store the person's email unless they explicitly opt to share it with you.
That's it — it doesn't replace your GDPR review, but it removes an entire category of data you'd otherwise be sitting on and eventually explaining to a regulator.
Trying it
Free for sites up to 1,000 logins/month:
- Starter (Node + PHP, MIT licence): https://github.com/clientn/clientn-session-starter
- Docs: https://clientn.com/docs
- Live demo: https://clientn.com/demo
- Dashboard: https://clientn.com/dev
Curious how other devs are thinking about minimizing account-data retention post-fines like these — what's in your login table today that doesn't need to be?
Top comments (0)