Google Hit With $440 Mn Penalty for Breaching EU Privacy Rules Over Location Data

In 2023, it fined Meta a whopping €1.2 billion ($1.3 billion) for transferring EU user data to the US. A year earlier, it had fined Instagram for violations concerning the processing of children’s personal data.Ireland’s Data Protection Commission (DPC) has fined Google €403 million ($440 million) for breaching EU privacy rules when it comes to processing users’ location data, in one of the regulator’s largest penalties against a major technology company.

According to the DPC findings, Google had violated the EU’s General Data Protection Regulation (GDPR) through three features—Web & App Activity, Location History, and Location Accuracy—between 2018 and 2020. The regulator said users may not have been adequately aware that their location data could be used to influence advertising or infer their interests. 

It identified transparency violations across the three features. The regulator further found that Google retained certain location data through Web & App Activity and Location History for longer than was necessary.

The DPC’s investigation was conducted under the GDPR’s one-stop-shop mechanism, under which a lead supervisory authority can oversee cross-border processing by companies operating across multiple EU countries. Ireland has become the lead data protection regulator for several major US technology companies because many of them have their European headquarters or main EU operations in Ireland.

What’s your take on this story?Add your comment

“As a result of Google’s failures, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data,” DPC Deputy Commissioner and Head of Communications Graham Doyle stated.Also ReadDelvitech to Invest Up to $30 Mn in Bengaluru Manufacturing Facility, Create 800 Jobs

Alongside the financial penalty, the DPC has ordered Google to bring its processing of location data into compliance with the GDPR within six months.

In response to the penalty, Google stated that it has introduced new controls to manage location data and advertising preferences, following concerns over its historical policies. It now allows users to automatically delete personal data on a rolling basis, store timeline ⁠data directly ​on a device, and manage how data, including location, is ​used for ads.

The €403 million penalty makes it the fourth-largest fine imposed by Ireland’s DPC since the regulator became the lead supervisory authority for many major technology companies under the GDPR.

Similar Posts