Now If Google decided to hold the records forever or far beyond any legal requirements then yeah that’s getting evil.
However, several DPAs and local governments have reviewed Google software for their own GDPR compliance. Several of those findings are available online. These findings don't result in fines, because it's not technically an investigation of Google. But it does involve a thorough investigation of the legal issues of using Google's services, and the results are illuminating.
For example, below is a link to a report the Dutch DPA complied on whether Dutch government agencies can use Google Workspace (formerly GSuite). The conclusion is that Google's privacy protection are catastrophically terribad (for a paid product!). It requires linking to a personal account, purposes of processing are not defined, there's definitely processing going on that's not covered by the contract, etc. Google's linking to personal data in a way that cannot be disabled by administrators means they are a Joint Controller instead of a Processor, and it's not possible for them to comply with various obligations because they're too vague about the purposes of processing.
https://www.rijksoverheid.nl/binaries/rijksoverheid/document...
Again, doesn't result in a fine, because they're not be investigated for violations. Someone is just asking "can we use a Google product?" But the results of that research indicate some deep structural problems.
Also that fine that France issued, where they somehow avoided invoking GDPR directly? Still the third-largest GPDR fine on record. So your expectations for fine amounts are a bit off.