Google Fined €403 Million by Ireland for GDPR Location Data Violations
Ireland’s Data Protection Commission (DPC) has fined Google €403 million ($463 million) for multiple GDPR violations related to the processing of users’ location data.
Investigation examined three Google location features
The DPC began its investigation in February 2020 after receiving multiple complaints from consumer rights groups. The inquiry examined three Google features that were active during the GDPR period from May 25, 2018, through February 4, 2020:
- Web & App Activity: A Google Account setting that allows Google to process activity across its services, which can include browsing history, search history, location data and more.
- Location History: An opt-in service that tracks users carrying compatible mobile devices. Even when users are not actively using Google services, the feature can infer places they visit, activities and routes, displaying that information in their private Google Maps Timeline.
- Location Accuracy: An Android feature that helps a device determine its location more accurately than GPS alone. It can be used whether or not the user has a Google Account.
DPC says Google failed to meet GDPR requirements
The DPC found that Google processed location data through Web & App Activity and Location History without meeting GDPR requirements. The company also failed to demonstrate compliance with GDPR principles when processing personal data through Location Accuracy.
Irish authorities allege that Google failed to meet its transparency obligations for all three features. They also found that the company retained location data collected through Web & App Activity and Location History for longer than necessary.
“Individuals may be unaware that their location is being used to influence them with advertising or infer their interests, for example, and may lose control over their personal data,” Deputy Commissioner Graham Doyle said.
“This loss of control was further exacerbated by the fact that user location data was retained for longer than necessary.”
Google must change its data-processing practices
For these failures, the DPC imposed administrative fines totaling €403 million and ordered Google to bring its processing of user data into compliance within six months.
The DPC has not yet published its full decision but said it plans to do so in the future.
Google says its location privacy controls have changed
In a statement to BleepingComputer, Google said it has updated its practices and policies and introduced mechanisms to make location data easier to manage.
A Google spokesperson said:
“This lawsuit centers on past policies that have since been updated. Since 2019, we have significantly evolved our practices and introduced robust tools to simplify the management of location data.”
Google has added controls that allow users to set specific timelines for automatically deleting data from their accounts. Google Maps Timeline information is now stored on the user’s device, and data older than three months is automatically deleted.
Google also says that Web & App Activity saves the estimated general area of a device rather than its exact location.
Join Mikko Hypponen and security leaders from the NFL, Chanel and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix and revalidate at machine speed.
Source: www.bleepingcomputer.com



