Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Google fined €403 million over location data privacy violations

Ireland’s Data Protection Commission (DPC) has fined Google €403 million ($463M) for multiple GDPR violations involving users’ location data.

The investigation began in February 2020 after complaints from consumer rights organizations. It examined three Google features active from May 25, 2018, through February 4, 2020: Web & App Activity, Location History, and Location Accuracy.

The DPC said Google processed location data through Web & App Activity and Location History without meeting GDPR requirements. It also said Google failed to demonstrate compliance with GDPR principles when processing personal data through Location Accuracy, failed to meet transparency obligations for all three features, and retained some location data longer than necessary.

Deputy Commissioner Graham Doyle said people might not have known that their location could be used to influence them with ads or infer their interests. He said extended retention worsened that loss of control over personal data.

The DPC is demanding that Google bring its processing into compliance within the next six months. The authority has not yet published its full decision but said it will do so in the future.

Google told BleepingComputer that it has updated its practices and policies since 2019. Google Maps Timeline is now stored on the device and automatically removes data older than three months. Google also says Web & App Activity stores an estimated general area rather than precise device location.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.