Google Hit With $463 Million Fine for EU Location Data Rule Breach
Ireland's privacy regulator fined Google 403 million euros for unlawful processing of EU location data.
Ireland's Data Protection Commission fined Google 403 million euros ($463 million) for breaching the EU General Data Protection Regulation by mishandling location data. Investigators found Google did not lawfully, fairly, or transparently process data in Web & App Activity, Location History, and Android's Location Accuracy feature between GDPR's 2018 start and February 2020. Google said the case concerns historical policies updated from 2019 onward. The penalty is the Irish watchdog's fourth-largest EU privacy fine, and three further Google investigations remain open.
- Ireland's DPC fined Google 403 million euros, about $463 million.
- Findings cover Web & App Activity, Location History, and Android Location Accuracy.
- The review covered GDPR processing from 2018 until February 2020.
- Google says the policies were historical and practices changed from 2019.
- Three other Irish privacy investigations into Google remain open.
Full article358 words · extracted from securityweek.com · click to collapse
Google has been fined 403 million euros ($463 million) for breaching the European Union’s strict privacy rules because it mishandled users’ location data, the bloc’s data privacy watchdog said Monday.
Ireland’s Data Protection Commission said its investigation found Google did not lawfully or fairly process location data in users’ Web & App Activity, a Google setting that tracks browsing and search history, and in their Location History, a service that maps places they’ve been with their mobile phones.
Regulators also found the company failed to be lawful, fair and transparent when it processed personal data in its Location Accuracy feature in the Android mobile operating system.
Ireland is the lead regulator for Google in the 27-nation EU because the U.S. tech giant’s European headquarters is based in Dublin.
The investigation, which opened six years ago, examined how Google applied the EU privacy rule book, known as the General Data Protection Regulation, from the time it took effect in 2018 until February 2020.
“This case centers around historical policies that have since been updated,” Google said in a statement. “From 2019 onwards, we’ve significantly evolved our practices and launched robust tools that make managing location data simple.”
Advertisement. Scroll to continue reading.
Regulators said that location data is a type of personal data that’s collected by Google and can be used to infer someone’s location.
“Location data can bring both benefits and harms to individuals,” Deputy Commissioner Graham Doyle said. “It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private.”
It’s the fourth biggest EU privacy fine issued by the Irish watchdog, which has previously handed out bigger fines to TikTok and Meta, including a 1.2 billion euro fine for Meta.
The regulator said it still has three other ongoing privacy investigations involving Google.
Related: Dior, Louis Vuitton, Tiffany Fined $25 Million in South Korea After Data Breaches
Related: TikTok Reaches $400 Million Settlement With US Justice Department Over Children’s Privacy
Related: Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts