Ireland’s DPC Fines Google USD 403 Million for Location Data Breach

Ireland: Ireland's Data Protection Commission (DPC) today imposed a fine of EUR 403 million, approximately USD 463 million, on Google for violating European Union rules governing the protection of users' location data.

According to Qatar News Agency, the DPC, acting as Google's lead supervisory authority in the European Union, said an inquiry found that the company had infringed the General Data Protection Regulation (GDPR) between May 25, 2018, and Feb. 4, 2020, through three features: "Web and App Activity," "Location History," and "Location Accuracy."

The Commission stated that the infringements concerned the lawfulness and fairness of processing location data through the "Web and App Activity" and "Location History" features. Additionally, the company failed to meet its accountability and transparency obligations in processing the data and retained some location data longer than necessary.

DPC Deputy Commissioner Graham Doyle expressed that Google's shortcomings may have left users unaware that their location data was being used, potentially influencing them through advertising or inferring their interests. He highlighted that retaining users' location data longer than necessary exacerbated users' loss of control over their personal data.

The DPC has ordered Google to bring its processing of location data into compliance with the GDPR within six months. The Commission began its inquiry in February 2020 after receiving complaints from several European consumer rights organizations about Google's handling of location data associated with certain services and products.

Google, in its response, stated that the case concerned historical policies and that, since 2019, it had implemented extensive changes to how it manages location data. These changes included allowing users to automatically delete data, storing Timeline data directly on users' devices, and providing tools to control how data, including location data, is used for advertising.

The fine is the fourth-largest imposed by the Irish Data Protection Commission on major technology companies, while the total fines it has levied since the GDPR took effect in 2018 have exceeded EUR 4 billion.