Google Fined €403 Million for GDPR Violations Over Location Data Processing
Google Ireland Limited was fined €403 million for violating GDPR by processing user location data, with a six-month compliance remediation required.
Ireland's Data Protection Commission imposed a €403 million fine on Google Ireland Limited for breaching GDPR by processing users' location data, following a 2020 inquiry into practices from 2018 to 2020.
- Google Ireland Limited fined €403 million for GDPR violations on location data processing
- Inquiry from 2020, focusing on 2018-2020 practices
- Google failed to meet GDPR accountability and transparency requirements
- Six-month compliance remediation required
- EU Data Protection Commission enforcement action
Full article502 words · extracted from gbhackers.com · click to collapse
Ireland’s Data Protection Commission (DPC) has imposed a €403 million administrative fine on Google Ireland Limited for breaching the EU General Data Protection Regulation (GDPR) by processing users’ location data.
This decision follows an inquiry initiated in February 2020 after complaints from European consumer rights organizations, including BEUC. The investigation examined Google’s practices from May 25, 2018, to February 4, 2020.
The DPC found that Google’s Web & App Activity and Location History controls did not comply with GDPR requirements for the lawfulness and fairness of location data processing.
Additionally, Google failed to meet accountability obligations for Location Accuracy, as it could not demonstrate adherence to the regulation’s principles of lawfulness, fairness, and transparency.
The regulator also identified transparency violations across all three features, as well as issues with how Google retained location information collected through Web & App Activity and Location History.
This enforcement action concerns three settings within Google’s ecosystem. Web & App Activity, available to Google Account holders, can process activity across Google services, websites, and apps, including browsing history, search history, and location data.
Location History is an opt-in service that uses data from compatible mobile devices to infer visits, activities, and routes, displaying those movements in the Timeline feature on Google Maps. This setting can create a private map of locations associated with signed-in devices, even when a user is not actively using a Google service.
Location Accuracy, on contrast, is an Android operating system feature designed to help devices determine locations more accurately than GPS alone.
This feature is accessible to all Android users, regardless of whether they have a Google Account. The DPC’s conclusion was based on Google’s inability to demonstrate that its processing of location data for this feature met the accountability standards required for lawful, fair, and transparent handling of personal data.
The regulator’s findings highlight the distinction between consent or control settings, platform-level capabilities, and the documentation needed to demonstrate GDPR compliance.
Google has been ordered to achieve compliance within six months. Deputy Commissioner Graham Doyle stated that while location information can enhance online services, it can also reveal private details about individuals.
He noted that users might not have realized their location data could be used to influence advertising or infer interests, reducing their control over personal data. He said retaining location information longer than necessary further exacerbates this issue.
The DPC emphasized that data processing must be lawful, fair, and transparent throughout the European Economic Area, reflecting the scrutiny businesses face when integrating account activity, mobile device signals, and inferences.
The DPC collaborated with supervisory authorities on this case and will publish the decision in due course. Google now faces a remediation period and a significant financial penalty focused specifically on processing location data.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.