Ireland's Data Protection Commission (DPC) has fined Google €403 million (about R7.5 billion) for infringing the EU's General Data Protection Regulation (GDPR) on location data. The DPC, acting on behalf of the European Union, found that Google breached users' location data between May 2018 and February 2020. The technology giant was found to have infringed the GDPR in respect of the lawfulness and fairness of its processing of location data in web and app activity and location history.
The DPC's inquiry, launched in February 2020, resulted in a final decision that Google infringed the GDPR. DPC deputy commissioner Graham Doyle stated that Google's failures could have led to individuals being unaware that their location was being used to influence them with ads or infer their interests. The retention of users' location data for longer than necessary aggravated this loss of control. Doyle emphasized that the fine and subsequent actions aim to ensure Google complies with the GDPR.
Alongside the fine, the regulator ordered Google to bring its processing into compliance within six months. Google has faced other major privacy penalties in Europe, including a €50 million fine by France's data protection regulator CNIL in 2019 for breaches of the EU's General Data Protection Regulation relating to transparency and consent for personalised advertising.
The DPC has also investigated Google's handling of personal data in Ireland, including an investigation into Google's processing of personal data in the development of its PaLM 2 artificial intelligence model. This investigation was opened in 2024 and was still ongoing at the end of that year. The DPC's actions demonstrate its commitment to enforcing the GDPR and protecting users' data.
Google's fine is one of several recent penalties imposed on technology giants for data breaches. In a related case, Facebook's parent company was ordered to pay $375 million for profiting from exposing youngsters to online abuse. These rulings highlight the growing scrutiny of technology companies and their handling of personal data.
The fine and subsequent actions against Google demonstrate the European Union's commitment to enforcing data protection regulations. The GDPR, which came into effect in 2018, aims to protect users' personal data and impose significant fines on companies that breach these regulations. The DPC's decision sets a precedent for other technology companies handling user data.
Google has not immediately responded to the fine and the order to comply with the GDPR. The company will need to review its data processing practices and ensure compliance within the given timeframe. The fine and subsequent actions serve as a reminder to technology companies of the importance of prioritizing users' data protection and complying with regulations.
Key points
- Google fined R7.5 billion for breaching users' location data
- European Union's General Data Protection Regulation (GDPR) infringed by Google
- Google ordered to comply with GDPR within six months