Google fined €403m by Ireland's Data Protection Commission for GDPR breaches
The Data Protection Commission (DPC) has fined Google €403m for GDPR infringements, following an investigation into how the company processes location data. (AP Photo/Jeff Chiu, File)
Ireland's Data Protection Commission (DPC) has fined Google €403m for GDPR infringements, following an investigation into how the company processes location data.
The inquiry by the DPC followed complaints from several European consumer rights organisations regarding how Google processing of location data in connection with certain services and products. The scope of the inquiry concerned Google’s processing of location data in three specific features – “Web & App Activity”, “Location History” and “Location Accuracy”.
The DPC has imposed administrative fines totalling €403m and has ordered Google to bring its processing into compliance within six months. The DPC is the lead European supervisory authority for Google.
Read More
“Location data is a type of personal data which is processed by way of location tracking, and includes data collected or processed by Google, which by itself or in conjunction with other information an individual’s location can be inferred. Location data can bring both benefits and harms to individuals. It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private," said DPC deputy comissioner, Graham Doyle.
"GDPR provides a high level of protection of personal data throughout the EEA, and requires that the processing of personal data must be carried out in a lawful, fair and transparent manner. As a result of Google’s failures in this regard, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data. The retention of users’ location data for longer than necessary aggravated this loss of control."
A spokesperson for Google said on Monday that the case centres around "historical policies that have since been updated. From 2019 onwards, we’ve significantly evolved our practices and launched robust tools that make managing location data simple.”
Google says that it has made several updates over the years including industry-first auto-delete controls to allow users to update their account to automatically delete data on a rolling 3, 18, or 36-month basis. It said its My Ad Center advertising manager lets users manage how data — including location — is used for ads.
It also said no precise location is saved when a search is performed on Google.
In giving its decision, the DPC found that Google had infringed the GDPR in respect of:
the lawfulness and fairness of its processing of location data in Web & App Activity and Location History,
its accountability obligations under the GDPR by failing to be able to demonstrate compliance with the lawfulness, fairness and transparency principle regarding its processing of personal data in Location Accuracy;
its transparency obligations in respect of all three features referred to above;
and its retention of location data in Web & App Activity and Location History.
The decision was made by Commissioners for Data Protection, Des Hogan, Dale Sunderland and Niamh Sweeney.




