Google Ireland has been fined €403m ($461m) by the Irish Data Protection Commission (DPC) following an investigation into its processing of location data.
The decision comes after the DPC, acting as the lead supervisory authority for Google within the European Union, carried out an inquiry triggered by complaints from several European consumer rights organisations, including the European Consumer Organisation (BEUC). The inquiry began in February 2020.
Access deeper industry intelligence
Experience unmatched clarity with a single platform that combines unique data, AI, and human expertise.
The regulator examined Google’s handling of location data through three features: “Web & App Activity,” “Location Accuracy,” and “Location History.”
The investigation focused on the period between 25 May 2018, when the General Data Protection Regulation (GDPR) began to apply, and 4 February 2020.
The DPC found that Google had breached the GDPR in several ways.
The decision by Commissioners Dr Des Hogan, Dale Sunderland and Niamh Sweeney concluded that Google did not observe the required lawfulness and fairness in processing location data for “Web & App Activity” and “Location History.”
Additionally, Google was unable to demonstrate compliance with these principles regarding “Location Accuracy”, the regulator said.
DPC also cited failures in meeting transparency obligations for all three features, and in the retention of location data associated with “Web & App Activity” and “Location History.”
Google has been instructed to bring its processing into compliance with the GDPR within six months.
Irish DPC Deputy Commissioner Graham Doyle said: “Location data is a type of personal data which is processed by way of location tracking, and includes data collected or processed by Google, which by itself or in conjunction with other information an individual’s location can be inferred.
“Location data can bring both benefits and harms to individuals. It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private.
“The GDPR provides a high level of protection of personal data throughout the EEA, and requires that the processing of personal data must be carried out in a lawful, fair and transparent manner.
“As a result of Google’s failures in this regard, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data. The retention of users’ location data for longer than necessary aggravated this loss of control.”
The DPC is expected to publish its full decision in the future and acknowledged the cooperation of peer supervisory authorities in reaching this outcome.
