A federal jury in the U.S. District Court for the Northern District of California has returned a $425.7 million verdict against Google in Rodriguez v. Google, marking a significant development in the ongoing legal scrutiny of large-scale data-collection practices. David Boies of Boies Schiller Flexner served as lead trial counsel for the plaintiffs, and the verdict has drawn attention from privacy practitioners, in-house compliance teams, and technology industry stakeholders across the United States.

At the heart of the case was the allegation that Google continued to collect user data after individuals had disabled the supplemental Web and App Activity privacy setting. The jury found Google liable, concluding that the company's conduct did not align with the expectations created by its user-facing privacy controls. The verdict highlights the substantial legal exposure that can arise when disclosed privacy options and actual back-end data flows diverge, even where users have taken affirmative steps to limit the collection or processing of their personal information.

For companies operating consumer-facing digital products, the decision underscores the importance of ensuring that privacy representations, consent mechanisms, and internal data-handling procedures remain consistent. Businesses that rely on layered privacy settings, opt-outs, or granular toggles should confirm that engineering practices honor those controls throughout the data lifecycle. Discrepancies between the promises presented in privacy dashboards and the realities of underlying systems can now be expected to attract heightened litigation risk, significant damages exposure, and reputational consequences.

A hearing on fee applications and post-trial motions is scheduled for August 27, 2026. As a result, the final financial impact of the verdict, as well as its ultimate precedential weight, remains subject to further proceedings, including potential post-trial motions and appellate review. Companies should nonetheless treat the verdict as an important marker of jury attitudes toward privacy compliance and the enforcement of user-facing controls.

In the interim, organizations may wish to review their consent architectures, audit the alignment between disclosed privacy settings and actual data practices, and evaluate governance structures that support ongoing compliance oversight in this evolving area.

This press release is provided for general informational purposes only and does not constitute legal advice. Clients and prospective clients should seek tailored guidance from qualified counsel regarding their specific circumstances.