Google Fined €403 Million for Location Data Violations Under GDPR
Ireland's Data Protection Commission (DPC) has issued its final ruling after investigating Google Ireland Limited. As Google's lead supervisory authority, the DPC opened the inquiry itself in February 2020, prompted by complaints from European consumer groups, including BEUC, about how Google handled location data.
The investigation covered three features: Web & App Activity, Location History and Location Accuracy, over the period from 25 May 2018 to 4 February 2020. The DPC's three Commissioners concluded that Google breached the GDPR in several ways. It processed location data unlawfully and unfairly in Web & App Activity and Location History, and it could not prove it had met the lawfulness, fairness and transparency principles for Location Accuracy. It also fell short on transparency across all three features and kept location data for too long in two of them.
Google was fined €403 million and given six months to bring its practices into line.
Deputy Commissioner Graham Doyle explained that location data can improve online services but can also expose deeply private details. Because of Google's failings, users may not have realised their whereabouts were being used to target ads or infer interests, and excessive retention deepened their loss of control.
The DPC thanked fellow European regulators for their help and will publish the full decision later.
References:
https://www.irishexaminer.com/business/companies/arid-41913715.html