Google has been fined €403 million for violating the European Union’s stringent privacy regulations after mishandling users’ location data, the bloc’s data privacy authority said. Ireland’s Data Protection Commission investigation found that Google did not lawfully or fairly process location data in users’ Web & App Activity—a feature that monitors browsing and search history—or in Location History. This service tracks the locations users have visited with their mobile devices.
Moreover, regulators found that the company failed to maintain lawful, fair, and transparent practices when processing personal data through its Location Accuracy feature in the Android operating system. As Ireland is the lead regulator for Google within the 27-country EU, this oversight stems from the company’s European headquarters being situated in Dublin.
The comprehensive investigation, which commenced six years ago, evaluated Google’s compliance with the General Data Protection Regulation (GDPR) from its implementation in 2018 until February 2020.
“This case centres around historical policies that have since been updated,” Google said in a statement. “From 2019 onwards, we’ve significantly evolved our practices and launched robust tools that make managing location data simple.”
“Location data can bring both benefits and harms to individuals,” Deputy Commissioner Graham Doyle said. “It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private.”
Location data qualifies as personal data Google collects and can be used to determine an individual’s location.
The Irish Data Protection Authority has imposed the fourth-largest privacy fine in the European Union, following prior substantial fines against TikTok and Meta, including a notable €1.2 billion fine against Meta. The regulator has also indicated three ongoing privacy investigations involving Google.
This article used information from The Associated Press.
