SCIENCE & TECH

Irish watchdog fines Google €403m over location data

The decision lists four failures, including keeping users’ location data for longer than necessary.

The entrance to Google's offices in Dublin, Ireland
Photo: OutreachPete / Wikimedia Commons, CC BY 2.0

Google has been fined €403m by Ireland’s Data Protection Commission (DPC) for breaking EU privacy rules in how it processed users’ location data, the regulator has said.

The DPC’s inquiry covered Google’s processing of location data in three features – Web & App Activity, Location History and Location Accuracy – from 25 May 2018, when the GDPR came into force, to 4 February 2020.

It had opened the investigation that month in its role as Google’s lead supervisory authority in the EU, after complaints from several European consumer rights organisations.

The decision, made by the commissioners for data protection Des Hogan, Dale Sunderland and Niamh Sweeney, found that Google had infringed the GDPR. It lists four failures:

  • the lawfulness and fairness of its processing of location data in Web & App Activity and Location History
  • its accountability obligations, by failing to demonstrate compliance with the lawfulness, fairness and transparency principle in Location Accuracy
  • its transparency obligations across all three features
  • its retention of location data in Web & App Activity and Location History

The DPC has imposed administrative fines totalling €403m and ordered Google to bring its processing into compliance within six months; it will issue its full decision in due course.

The decision comes more than six years after the DPC opened the inquiry, the dates show.

The DPC’s statement does not include a response from Google.

Location data “can bring both benefits and harms to individuals”, said Graham Doyle, the DPC’s deputy commissioner.

“It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private,” Doyle said.

“The GDPR provides a high level of protection of personal data throughout the EEA, and requires that the processing of personal data must be carried out in a lawful, fair and transparent manner,” Doyle added.

Google’s failures, Doyle said, meant individuals “could have been unaware” their location was being used to influence them with adverts or infer their interests, and could lose control over their personal data.

Keeping that data “for longer than necessary aggravated this loss of control”.

What are Web & App Activity, Location History and Location Accuracy?

The DPC described the three features as follows:

  • Web & App Activity – a Google account setting that can process a user’s browsing history, search history and location data
  • Location History – an opt-in service that uses a device’s location to build a private “Timeline” map, and keeps that data even when a person is not using a Google service
  • Location Accuracy – an Android feature that pinpoints a device’s location more precisely than relying on GPS alone, available to all Android users whether or not they hold a Google account