Google has been fined €403m by the European Union's data privacy watchdog for breaching the bloc's strict privacy rules. The Irish Data Protection Commission, the lead regulator for Google in the EU, found that the company did not lawfully or fairly process location data in users' Web & App Activity and Location History. This investigation, which began six years ago, examined Google's application of the General Data Protection Regulation from its implementation in 2018 until February 2020.

The investigation revealed that Google failed to be lawful, fair, and transparent when processing personal data in its Location Accuracy feature in the Android mobile operating system. Ireland's Data Protection Commission stated that location data is a type of personal data collected by Google, which can be used to infer someone's location. This data can bring both benefits and harms to individuals, enhancing online services while revealing private information.

Google responded to the fine, stating that the case centers around historical policies that have since been updated. From 2019 onwards, the company has significantly evolved its practices and launched robust tools to make managing location data simple. The company has made efforts to improve its data handling practices, but the fine reflects its past actions.

This fine is the fourth-biggest EU privacy fine issued by the Irish watchdog. Previously, the regulator handed out bigger fines to TikTok and Meta, including a €1.2bn fine for Meta. The regulator still has three other ongoing privacy investigations involving Google, indicating continued scrutiny of the company's data practices.

The Irish Data Protection Commission's decision highlights the importance of companies handling user data in a lawful and transparent manner. Deputy Commissioner Graham Doyle emphasized that location data can reveal a significant amount of information about an individual, including inherently private information. This underscores the need for robust data protection regulations and enforcement.

The fine and the investigation's findings demonstrate the EU's commitment to enforcing its data protection regulations. The General Data Protection Regulation, implemented in 2018, sets a high standard for companies handling personal data. Google's fine serves as a reminder to companies of the importance of complying with these regulations.

The €403m fine against Google reflects the company's responsibility to protect users' location data. As a major tech company, Google's data handling practices are under close scrutiny. The company must ensure that its practices align with regulatory requirements and user expectations, prioritizing transparency and data protection.

Key points

  • Google fined €403m for breaching EU data protection regulations
  • Investigation found Google mishandled users' location data in Web & App Activity and Location History
  • This is the fourth-biggest EU privacy fine issued by the Irish Data Protection Commission

Share this story

Written by

SaharaWire Newsroom
SaharaWire

Reporting for SaharaWire from the Nairobi bureau.