€403 Million Fine: Google Faces Privacy Ruling Over Location Data

Google has been fined €403 million ($463 million) by Ireland’s Data Protection Commission (DPC) for breaching European Union privacy rules over the way it processed users’ location data.

The Irish regulator said its investigation found violations involving three Google features — Web & App Activity, Location History and Location Accuracy — during the period between May 2018 and February 2020.

According to the DPC, Google did not process location information lawfully and fairly through Web & App Activity and Location History. It also found shortcomings in the company’s ability to demonstrate compliance with transparency and accountability requirements concerning Location Accuracy.

The regulator said Google’s handling of the data could leave users unaware that information about their location was being used to infer their interests or potentially influence advertising. It also said the company retained some location information for longer than necessary.

Web & App Activity can store information including browsing and search history, as well as location data. Location History allows Google to record and map places a user visits through compatible devices, while Location Accuracy helps Android devices determine a user’s location more precisely.

Ireland serves as Google’s lead data-protection regulator in the EU because the company’s European headquarters is based in Dublin.

The inquiry began after complaints from European consumer organisations, including the European Consumer Organisation (BEUC), and was formally opened by the DPC in February 2020.

Google said the case concerned historical policies that had since been changed. The company told Reuters that it had introduced stronger user controls, automatic deletion options and less precise location-data storage as part of changes to its practices.

Alongside the €403 million penalty, the DPC ordered Google to bring its processing of the affected location data into compliance with EU privacy requirements within six months.

The penalty is among the largest privacy fines issued by Ireland’s regulator. The DPC has previously imposed larger penalties on major technology companies, including Meta and TikTok. Its records show that more than €4 billion in fines have been imposed through its data-protection investigations since the GDPR took effect.

The regulator said three other investigations involving Google remain ongoing.

.

advertisement

The decision highlights the strict requirements the EU places on companies handling personal data, particularly information such as location records that can reveal details about an individual’s movements and activities.