Google has been fined €403 million, £345 million, by Ireland’s Data Protection Commission, DPC, for breaching European data protection rules in its processing of users’ location data between May 2018 and February 2020.
The penalty follows a six-year regulatory process triggered by complaints from several European consumer rights organizations, including the European Consumer Organization, BEUC, over the legality and transparency of Google’s location-data practices.
The DPC said its investigation found infringements involving the lawfulness and fairness of processing, transparency, accountability and the retention of location data.
The investigation, formally launched in February 2020, examined three Google features — Web & App Activity, Location History and Location Accuracy — during the period from May 25, 2018, when the General Data Protection Regulation took effect, to February 4, 2020.
According to the DPC, Web & App Activity allows Google Account holders to have information about their activity on Google services processed, including browsing and search history as well as location data.
Location History, meanwhile, records users’ locations through compatible mobile devices when the feature is enabled and can be used to infer places visited, activities and routes.
Google’s Location Accuracy feature helps Android devices determine their positions more precisely than GPS alone and is available to Android users regardless of whether they have a Google Account.
The regulator said Google’s handling of location information through Web & App Activity and Location History did not meet GDPR requirements for lawful and fair processing.
It also found that Google failed to demonstrate compliance with the lawfulness, fairness and transparency principles in relation to Location Accuracy.
The DPC further found transparency shortcomings across all three features and concluded that Google retained location data through Web & App Activity and Location History in ways that did not comply with the GDPR.
Graham Doyle, DPC deputy commissioner, said location data could provide extensive information about individuals and reveal details that are inherently private.
Also Read: Meta agrees to $16.68bn settlement over child safety claims
He said the GDPR requires personal data to be processed lawfully, fairly and transparently, adding that Google’s practices could have left users unaware that their location information could be used to influence advertising or infer their interests.
Doyle also said retaining location data for longer than necessary could further reduce users’ control over their personal information.
The GDPR, which came into force across the European Economic Area on May 25, 2018, sets requirements governing how organizations collect, use, store and protect personal data.
Ireland’s DPC acts as the lead supervisory authority for Google and many other major technology companies with European operations based in Ireland.
The DPC has ordered Google to bring the affected processing activities into compliance with the GDPR within six months, in addition to the €403 million administrative fine. The regulator said the full decision would be issued in due course.
Google, however, said the case relates to historical policies that have since been changed. “From 2019 onwards, we’ve significantly evolved our practices and launched robust tools that make managing location data simple,” the company said in response to the decision.
The technology company pointed to measures including automatic deletion controls, which allow users to set their accounts to delete certain data on a rolling three-, 18- or 36-month schedule.
It also cited simplified advertising controls that allow users to turn off personalized advertisements, as well as changes intended to provide greater transparency over location-data practices and account settings.
The DPC’s inquiry began after consumer organizations raised concerns about Google’s processing of location information and whether users were adequately informed about how their data was being used.
The €403 million penalty adds to the substantial regulatory sanctions imposed on major technology companies under Europe’s data protection regime.
The fine is the DPC’s fourth-largest and brings the total amount levied by the Irish regulator against major US technology firms since the GDPR took effect to more than €4 billion.
The decision places renewed focus on the extent to which technology companies must explain the collection and use of location information and give users meaningful control over highly revealing personal data.
NAN













