Ireland’s privacy regulator has fined Google €403 million for GDPR violations involving users’ location information. The authority found problems with transparency, data retention and the legal basis for processing Google location data.
DPC Investigates Three Google Features
Ireland’s Data Protection Commission launched its investigation in February 2020. The inquiry followed several complaints from consumer rights organisations.
The regulator examined three Google features that operated between May 25, 2018, and February 4, 2020.
Web & App Activity allowed Google to process activity across its services. That information could include browsing history, searches and location data.
Meanwhile, Location History tracked users who carried compatible mobile devices. The service could identify visited places, activities and travel routes.
It also displayed the information through a private Maps Timeline. Tracking could continue even when users did not actively use a Google service.
Finally, Location Accuracy helped Android devices determine their position more precisely than GPS alone. The feature worked regardless of whether a person had a Google Account.
Regulator Finds Multiple GDPR Violations
The DPC found that Google’s handling of data through Web & App Activity and Location History failed to meet GDPR requirements.
Google also failed to demonstrate compliance with GDPR principles when processing personal information through Location Accuracy.
Furthermore, the regulator found transparency failures across all three features. As a result, users may not have understood how Google collected and used their location information.
The DPC said some people may not have known that Google used their location to influence advertising or infer their interests.
In addition, Google retained data from Web & App Activity and Location History longer than necessary. According to the regulator, this practice further reduced users’ control over their personal information.
Google Must Change Its Data Practices
The DPC imposed administrative fines totalling €403 million, or approximately $463 million.
It also ordered Google to bring its data processing practices into compliance within six months. However, the authority has not yet published its full decision.
The regulator plans to release the complete findings at a later date.
Google Says Policies Have Changed
Google said the investigation focused on historical policies that the company has since updated.
According to the technology company, it began significantly changing its location data practices in 2019. It also introduced tools that give users more control over their information.
For example, users can now choose when Google should automatically delete data from their accounts.
Google also stores Maps Timeline information directly on users’ devices. Moreover, the service automatically deletes Timeline data older than three months.
The company says Web & App Activity does not store a device’s precise location. Instead, it saves an estimated general area.
Despite these changes, the DPC’s decision requires Google to address the identified violations and demonstrate GDPR compliance.
The €403 million penalty highlights the regulatory risks surrounding Google location data and other sensitive personal information.


0 responses to “Google Fined €403 Million Over Location Data Violations”