Google Hit with €403m GDPR Fine Over Location Data Practices
Ireland's DPC fined Google €403 million for unlawful GDPR processing and retention of user location data.
The Irish Data Protection Commission fined Google €403 million ($460 million) for GDPR violations in how it processed location data. The inquiry, opened in February 2020, examined Web & App Activity, Location History, and Location Accuracy from 25 May 2018 through 4 February 2020. The DPC found failures of lawfulness and fairness, accountability, transparency, and data retention, and ordered compliance within six months. Google said the case concerns historical policies updated from 2019; it previously paid $391.5 million to settle a 2022 US location-data lawsuit.
- Irish DPC fined Google €403 million ($460 million) after an inquiry opened in 2020.
- Scope covered Web & App Activity, Location History, and Location Accuracy from 2018 to 2020.
- Findings cited unlawful processing, accountability gaps, poor transparency, and excessive retention.
- Google must bring location-data processing into compliance within six months.
- Google called the policies historical; a 2022 US settlement was $391.5 million.
Full article401 words · extracted from infosecurity-magazine.com · click to collapse
Google has been fined €403m ($460m) by the Irish Data Protection Commission (DPC) for violating GDPR rules regarding to its processing of users’ location data.
Following a lengthy inquiry that started in February 2020, the Commission concluded that the tech giant’s unlawful practices in this area meant that individuals using services such as Google Maps and location accuracy features on Android devices could have been unaware that their location was being used to influence them with ads or to infer their interests. It found that this practice could result in a loss of control over their personal data.
In addition, the firm was found to have retained users’ location data for longer than necessary, aggravating this loss of control.
The investigation focused on Google’s processing of location data in three specific features – Web & App Activity, Location History and Location Accuracy between May 25, 2018, when the GDPR came into force, through to February 4, 2020.
Google was found to have violated the GDPR in four respects:
- The lawfulness and fairness of its processing of location data in Web & App Activity and Location History
- Its accountability obligations under the GDPR by failing to be able to demonstrate compliance with the lawfulness, fairness and transparency principle regarding its processing of personal data in Location Accuracy
- Its transparency obligations in respect of all three features referred to above; and
- Its retention of location data in Web & App Activity and Location History.
Commenting on the fine, Deputy Commissioner of the DPC, Graham Doyle, noted the highly sensitive nature of location data and the potentially serious implications of individuals’ location being inferred.
“Location data can bring both benefits and harms to individuals. It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private,” he said.
The DPC added that the company must also ensure it brings its processing approach into compliance within six months.
Responding to the judgement, a Google spokesperson said: “This case centers around historical policies that have since been updated. From 2019 onwards, we’ve significantly evolved our practices and launched robust tools that make managing location data simple.”
In November 2022, Google agreed to pay $391.5m to settle a lawsuit in the US that alleged the firm harvest location data without the knowledge of most consumers.
Image credit: credit: Stockinq / Shutterstock.com