Google has been fined €403 million ($463m) by Ireland’s Data Protection Commission (DPC) for breaching European data protection rules over its handling of users’ location data.
The penalty follows a six-year investigation into how Google processed location information through three features: Web & App Activity, Location History and Location Accuracy.
The DPC found that between May 2018 and February 2020, Google had not processed some location data in a lawful, fair and transparent manner, potentially leaving users unaware that their information could be used to infer their interests or influence the adverts they saw.
The regulator also found that Google retained some location data for longer than necessary, which it said further reduced users’ control over their personal information. (Homepage | Data Protection Commission)
DPC deputy commissioner Graham Doyle said location data could reveal highly private information about individuals and therefore required strong safeguards under the European Union’s General Data Protection Regulation (GDPR).
The investigation was launched in February 2020 after complaints from several European consumer rights organisations, including the European Consumer Organisation (BEUC).
Alongside the fine, the DPC has ordered Google to bring its processing of location data into full compliance with GDPR requirements within six months. The €403 million penalty is the fourth-largest fine imposed by the Irish regulator. (Homepage | Data Protection Commission)
Google said the case concerned historical policies that had since been changed, adding that it had significantly updated its approach to location data since 2019.
The company said it had introduced stronger user controls, automatic data deletion options and greater transparency over how location information is managed.
Google is expected to appeal the ruling, according to reports. (RTE)
