Google has been fined €403 million (£345 million) by Ireland's Data Protection Commission (DPC) for its handling of users' location data. The penalty follows a six-year investigation launched after complaints from several European consumer rights organisations. The DPC found that Google processed users' location data in ways that were not lawful, fair or transparent under the European Union's General Data Protection Regulation (GDPR). This investigation is a significant development in the regulation of tech companies' data practices.
The investigation examined Google's processing of location data through three features: Web & App Activity, Location History, and Location Accuracy, between May 25, 2018, and February 4, 2020. According to the DPC, location data can reveal significant information about individuals, including details that may be considered inherently private. The DPC's Deputy Commissioner, Graham Doyle, emphasized that the GDPR requires personal data to be processed lawfully, fairly, and transparently. Google's practices were found to have breached this regulation.
The DPC's investigation found that Google's approach could have left users unaware that their location data was being processed for purposes including influencing advertisements and inferring their interests. Retaining location data for longer than necessary could further reduce users' control over their personal information. Doyle stated that Google's practices did not meet the requirements of the GDPR, which took effect on May 25, 2018, establishing strict data protection requirements across the European Economic Area.
In addition to the financial penalty, the DPC ordered Google to bring its data processing practices into compliance with the GDPR within six months. Google, however, said the case concerned historical practices that had since been changed. The company pointed out that it had introduced new measures to improve transparency and user control over location data.
Google said it had introduced measures including automatic deletion controls, allowing users to set their accounts to automatically delete data on a rolling three-, 18- or 36-month basis. The company also pointed to simplified advertising controls that allow users to disable personalised advertising, as well as increased transparency around location data practices and account settings. These changes aim to provide users with more control over their data.
The €403 million penalty adds to regulatory scrutiny of how major technology companies collect, process, and retain users' personal information under European data protection rules. This fine is part of a broader effort to hold tech companies accountable for their data practices and ensure they comply with regulations like the GDPR. The DPC's decision sets a precedent for other companies handling user data.
The case highlights the ongoing challenges in regulating tech companies' data practices and ensuring they prioritize user privacy. As technology continues to evolve, regulators and companies must work together to establish and enforce clear guidelines for data collection and processing. The outcome of this case will likely have implications for how companies handle user data in the future.
Key points
- Google fined €403m for mishandling users' location data
- DPC ordered Google to comply with GDPR within six months
- Google introduced new measures to improve transparency and user control over location data