Google got a small fine, compared to what they have. EPA/GODOFREDO A. VASQUEZ

Consumer rights Tech

Google fined €403 million for EU location-data breaches

2 minutes read

Ireland is Google’s lead EU supervisor because the company’s European headquarters are in Dublin.

Ireland’s Data Protection Commission has fined Google €403 million for breaking the EU’s General Data Protection Regulation in the way it processed users’ location data between May 2018 and February 2020.

The company has six months to bring that processing into compliance.

The inquiry, opened in February 2020 after complaints from European consumer groups including BEUC, covered three features: Web & App Activity, which stores browsing and search history across Google services; Location History, which maps where a phone has been; and Location Accuracy, an Android function that uses more than GPS to pinpoint a device.

Ireland is Google’s lead EU supervisor because the company’s European headquarters are in Dublin.

Commissioners Des Hogan, Dale Sunderland and Niamh Sweeney found Google had infringed the GDPR on lawfulness and fairness in Web & App Activity and Location History; on accountability for failing to show that Location Accuracy met the rules on lawfulness, fairness and transparency; on transparency across all three features; and on keeping location data in Web & App Activity and Location History for longer than necessary.

“As a result of Google’s failures, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data,” said deputy commissioner Graham Doyle.

“The retention of users’ location data for longer than necessary aggravated this loss of control.”

Location data, he noted, can improve online services but can also reveal “intrinsically private” information.

The period under review ran from 25 May 2018, when the GDPR took effect, to 4 February 2020.

Coordinated complaints arrived in late 2018 from consumer bodies in the Czech Republic, Denmark, Greece, the Netherlands, Norway, Poland, Slovenia and Sweden.

BEUC called Monday’s ruling “an important decision, close to eight years after a series of complaints”.

Google said the case “centres around historical policies that have since been updated”.

“From 2019 onwards, we’ve significantly evolved our practices and launched robust tools that make managing location data simple.”

The DPC nonetheless ordered changes within six months, which implies the regulator is not satisfied that current practice is fully compliant.

The penalty is the DPC’s first major GDPR fine against Google and the fourth-largest the Irish watchdog has issued.

Larger decisions include €1.2 billion against Meta, €530 million against TikTok and €405 million against Instagram.

The DPC has levied more than €4 billion in total since becoming lead supervisor for most large US tech firms with EU bases in Ireland.

Three other statutory inquiries into Google are at an advanced stage.

Key Topics

More like this

TikTok was fined 530 million euros ($600 million) by its lead EU privacy regulator on May 2 over concerns on how it protects user information and was ordered to suspend data transfers to China if its processing is not brought into compliance within six months. (Photo by Chesnot/Getty Images)
News

TikTok fined €530 million by EU regulator over data protection

By Reuters

Tech

Brussels designates ChatGPT, Reddit and Roblox under Digital Services Act

By Carl Deconinck

Premium
EU bubble

Brussels forces Google to lower quality of searches in the EU

By Carl Deconinck

TikTok, Shein, Xiaomi and three other Chinese companies were named in a privacy complaint filed on January 16 by Austrian advocacy group Noyb, which alleged the firms were unlawfully sending European Union user data to China. (Photo Illustration by Asanka Ratnayake/Getty Images)
News

TikTok, five other Chinese firms hit by EU privacy complaints

By Reuters