Google has been fined €403 million ($463 million) by Ireland’s Data Protection Commission (DPC) over breaches of European Union data protection rules relating to the processing of users location data.
The fine followed an investigation into three Google features; Web & App Activity, Location History and Location Accuracy – covering the period from May 2018 to February 2020. The DPC said its findings established infringements of the General Data Protection Regulation (GDPR) concerning the lawfulness, fairness, transparency and retention of location data.
The Irish regulator also ordered Google to bring its location-data processing practices into compliance with the GDPR within six months.
According to the DPC, the investigation was launched in February 2020 after complaints from several European consumer rights organisations, including the European consumer organisation BEUC, concerning Google’s processing of location data through its services and products.
Web & App Activity allows Google Account holders to have information relating to activity across Google services processed, including browsing history, search history and location data. Location History, meanwhile, tracks a user’s location through compatible mobile devices and can record places visited, activities and routes between locations.
The regulator also examined Location Accuracy, an Android feature designed to improve the precision of a device’s location by using information beyond GPS. The DPC found that Google’s processing under the three features failed to meet certain GDPR requirements relating to transparency and accountability.
DPC deputy commissioner Graham Doyle said the shortcomings could have left users unaware that their location information was being used in ways that could influence advertising or help infer their interests.
He also said retaining location information for longer than necessary further reduced users’ control over their personal data.
The regulator’s decision comes as location data becomes increasingly important to digital services, including mapping, advertising, personalised services and mobile applications, while raising concerns over how much control users have over information that can reveal their movements and activities.
Google, however, said the case concerned historical policies that had since been changed. The company said it had significantly evolved its practices from 2019 and introduced tools intended to make the management of location data easier for users.
The €403 million penalty is the fourth-largest fine imposed by the Irish DPC. The regulator has imposed more than €4 billion in fines since becoming the lead EU supervisory authority for many major US technology companies because of their European operations in Ireland.
Furthermore, the latest action adds to regulatory scrutiny of major technology companies over the handling of personal information. The DPC said three other statutory inquiries involving Google are currently at an advanced stage.
The decision highlights the growing regulatory emphasis on transparency and user control as digital platforms collect increasingly detailed information about individuals. Under the GDPR, organisations processing personal data are required to do so lawfully, fairly and transparently.
The DPC said it would issue the full decision in due course, while Google’s compliance with the order is expected to be assessed within the six months stipulated by the regulator.
We’ve got the edge. Get real-time reports, breaking scoops, and exclusive angles delivered straight to your phone. Don’t settle for stale news. Join LEADERSHIP NEWS on WhatsApp for 24/7 updates →
Join Our WhatsApp Channel




