HomeTechnologyGoogle Fined $463 Million Over EU Location Data Privacy Violations

Google Fined $463 Million Over EU Location Data Privacy Violations

Google Fined $463 Million Over EU Location Data Privacy Violations

Google has been fined €403 million (about US$463 million) by Ireland’s Data Protection Commission (DPC) for violating European Union privacy rules in its handling of users’ location data. The penalty follows a six-year investigation into Google’s processing of location information through three services and features: Web & App Activity, Location History and Location Accuracy. The investigation examined Google’s practices between May 2018, when the EU’s General Data Protection Regulation (GDPR) took effect, and February 2020.
The Irish regulator found that Google had not processed location data lawfully and fairly through Web & App Activity and Location History. It also found that Google failed to demonstrate compliance with GDPR requirements concerning lawfulness, fairness and transparency when processing information through Location Accuracy, a feature of the Android operating system.
The DPC also found transparency shortcomings across all three features and concluded that Google retained some location data for longer than necessary. According to the regulator, these practices could have left users unaware of how their location information was being used and reduced their ability to control their personal data.
Location information can reveal highly detailed information about a person’s movements, including places they visit, routines and other activities. The DPC said such information can provide useful services to users but can also expose information that is inherently private. Web & App Activity allows Google to process information associated with activity on Google services, which can include browsing history, search history and location information. Location History can record places a person has visited and routes travelled using compatible devices. Location Accuracy helps Android devices determine a user’s location more precisely by combining information from different sources. The investigation began in February 2020 after complaints were submitted by several European consumer-rights organizations, including the European Consumer Organisation, known as BEUC. Ireland’s DPC acted as Google’s lead data-protection regulator within the European Union because Google’s European headquarters are located in Dublin. Alongside the financial penalty, the DPC ordered Google to bring its location-data processing into compliance with the GDPR within six months. The regulator said the full decision would be published at a later date.
Google said the case concerns historical policies that have since been changed. The company said it has significantly changed its approach to location-data management since 2019 and has introduced tools designed to give users greater control over their information.
The company has previously introduced features that allow users to automatically delete certain location information and adjust how location data is stored and used. Google maintains that its current practices have evolved considerably from those examined during the investigation. The €403-million penalty is the fourth-largest privacy fine issued by Ireland’s Data Protection Commission. The Irish regulator has previously imposed larger penalties on major technology companies, including Meta and TikTok.
The case also highlights the continuing enforcement of the GDPR, one of the world’s most comprehensive data-protection frameworks. The regulation requires organizations handling personal information in the European Economic Area to meet requirements concerning lawful processing, transparency, accountability and individuals’ control over their data. For Google, the decision adds to regulatory scrutiny of its data practices in Europe. The Irish regulator said it has three other ongoing statutory investigations involving Google, which are at an advanced stage.
The ruling could also have broader implications for the technology industry as European regulators continue examining how companies collect, store and use personal information. Location data is particularly sensitive because it can be combined with other information to create detailed profiles of individuals. The investigation took more than six years to complete, demonstrating the length and complexity of major cross-border privacy cases under the GDPR. Ireland’s DPC coordinated with other European data-protection authorities during the process.
The decision does not concern Google’s current location-data practices alone; much of the conduct examined by regulators occurred several years ago. Google has emphasized that its policies and user controls have changed since the period covered by the investigation. The latest penalty nevertheless sends a strong message about the importance European regulators place on transparency and user control over personal information. Google must now make any additional changes required by the DPC within six months as the company continues to operate under heightened regulatory scrutiny in Europe.

error: Content is protected !!