Google fined $463m over EU location data violations
Google has been fined €403 million ($463 million) by Ireland’s Data Protection Commission (DPC) for violating EU data-protection rules in its handling of users’ location information.
The DPC, Google’s lead privacy regulator in the European Union, announced the final decision on Monday (September 21) following an investigation into the company’s processing of location data between May 25, 2018 and February 4, 2020.
The inquiry examined three Google features — Web & App Activity, Location History and Location Accuracy. The regulator found shortcomings involving the lawfulness and fairness of location-data processing, transparency and Google’s ability to demonstrate compliance with GDPR requirements.
It also raised concerns over the retention of some location data for longer than necessary.
DPC Deputy Commissioner Graham Doyle said the practices could have left users unaware of how their location information was being used, including to influence advertising or infer their interests.
Keeping the data longer than necessary could further reduce users’ control over their personal information, he said.
The investigation began in February 2020 after complaints from several European consumer organisations, including the European Consumer Organisation (BEUC). The €403 million penalty is the DPC’s fourth-largest GDPR fine.
Alongside the fine, the DPC ordered Google to bring the relevant data-processing operations into full compliance with the GDPR within six months.
Google said the case concerns policies and systems that are now outdated. The company said it has since introduced stronger user controls, automatic data deletion and measures to store less precise location information.
Leave A Comment