Ireland's Data Protection Commission (DPC) has fined Google €403 million (£345 million) for violating users' data privacy. The penalty follows a six-year investigation into complaints from European consumer rights organisations. The DPC found Google processed location data in a manner that was not lawful, fair or transparent. The investigation examined Google's handling of location data through features like Web & App Activity, Location History, and Location Accuracy.

The DPC's investigation focused on Google's data processing practices between 25 May 2018 and 4 February 2020. The inquiry revealed that location data could reveal significant information about individuals, including inherently private information. Graham Doyle, DPC Deputy Commissioner, emphasised that the General Data Protection Regulation (GDPR) requires personal data to be processed lawfully, fairly, and transparently. Google's practices were found to infringe the GDPR, which established strict data privacy and security requirements across the European Economic Area.

According to Graham Doyle, Google's failures could have left individuals unaware that their location data was being used for purposes such as influencing advertisements or inferring their interests. Retaining users' location data for longer than necessary could further undermine their control over personal information. The DPC ordered Google to bring its data processing practices into compliance with the GDPR within six months. This directive aims to ensure Google prioritises users' data privacy and adheres to regulatory requirements.

In response to the DPC's decision, Google stated that the case concerned historical policies that had since been updated. The tech giant claimed to have significantly evolved its practices and launched robust tools to make managing location data simple from 2019 onwards. Google introduced measures such as automatic deletion controls, allowing users to set their accounts to delete data on a rolling three, 18- or 36-month basis.

Google also cited measures including simplified advertising controls, which allowed users to turn off personalised advertisements, as well as increased transparency around its location data practices and account settings. These updates aim to provide users with more control over their data and enhance their overall experience. The company appears to have taken steps to address the concerns raised by the DPC and improve its data handling practices.

The fine imposed on Google highlights the importance of data privacy and the need for companies to adhere to regulatory requirements. The GDPR has been instrumental in establishing a framework for data protection across the European Economic Area. The DPC's decision serves as a reminder to tech companies of their responsibility to handle users' data in a lawful, fair, and transparent manner.

The €403 million fine is a significant penalty for Google, and the company will need to ensure its data processing practices comply with the GDPR within the specified timeframe. By taking steps to update its policies and introduce new tools, Google aims to regain user trust and demonstrate its commitment to data privacy. The outcome of this case may have implications for other tech companies handling user data.

Key points

  • Google fined €403m for mishandling users' location data
  • DPC ordered Google to comply with GDPR within six months
  • Google claims to have updated its data handling practices since 2019

Share this story

Written by

SaharaWire Newsroom
SaharaWire

Reporting for SaharaWire from the Nairobi bureau.