MikhbarMIKHBAR
Computing

Google Fined €403 Million Over GDPR Location Data Breaches

The Irish regulator concluded an investigation into Google's handling of location-based services, citing multiple violations of European privacy laws. The company has been ordered to update its data processing practices within six months.

Google Fined €403 Million Over GDPR Location Data Breaches

An Extensive Regulatory Inquiry

Ireland’s Data Protection Commission (DPC) has officially fined Google €403 million ($463 million) following an extensive investigation into how the tech giant processes sensitive user location information. The probe, which was initiated in February 2020 following a series of complaints from consumer rights advocacy groups, scrutinized Google's data handling practices throughout the GDPR application period spanning from May 25, 2018, to February 4, 2020.

The inquiry focused on three specific features that monitor user movement and behavior: Web & App Activity, Location History, and Location Accuracy. According to the regulatory findings, Google failed to satisfy the fundamental transparency obligations required by the General Data Protection Regulation (GDPR) for all three systems. Furthermore, the DPC identified that the company retained information gathered via Web & App Activity and Location History for longer than was strictly necessary, an act that aggravated the loss of individual control over personal digital footprints.

Google fined $463 million for breaching EU location data rules
Image related to the report from Engadget · Source: Engadget

Features Under the Microscope

The investigation provided a detailed breakdown of the three primary Google mechanisms flagged by the regulator. The first, Web & App Activity, is a setting that tracks activity across various Google services, including search history, browsing behavior, and associated location data. The second, Location History, acts as an opt-in service that enables the tracking of compatible mobile devices to infer routes, visited locations, and user activities, often creating a private timeline for the user.

The third feature, Location Accuracy, is an Android-specific setting designed to enhance device positioning beyond standard GPS capabilities. The DPC found that while Google processed data for these features, it did so without fully adhering to the lawful and fair processing principles mandated by the GDPR. For those interested in broader industry security, organizations are encouraged to

Transparency and Consumer Impact

A central component of the DPC’s criticism was the lack of clarity provided to the average user. Regulators argued that because transparency requirements were not met, many individuals remained unaware that their location data was being utilized for secondary purposes, such as inferring personal interests or targeting advertisements. As noted by the authority, the extended retention of this location information further compromised user autonomy, preventing individuals from effectively managing their own data.

The regulatory ruling mandates that Google bring its data processing operations into full compliance within the next six months. While the full decision has not yet been released to the public, the Irish authority has committed to publishing the complete details in the near future. The industry continues to evolve as privacy standards tighten, with other recent developments including efforts to improve user anonymity, such as how

Google logo on the side of a building.
Image related to the report from Engadget · Source: Engadget

Google’s Response and Historical Context

In response to the fine, a spokesperson for Google highlighted that the ruling concerns legacy policies that the company has already overhauled. "This case centers around historical policies that have since been updated. From 2019 onwards, we've significantly evolved our practices and launched robust tools that make managing location data simple," the representative explained to BleepingComputer. The company pointed to new controls that allow users to set automatic deletion schedules for their activity and location history, with Maps Timeline data now stored locally on devices and purged after three months.

This financial penalty is part of a larger pattern of scrutiny facing major technology firms in the European Union. The DPC has noted that several other large-scale inquiries concerning Google remain open and are currently at an advanced stage. As regulators continue to enforce stricter privacy protections, other organizations have also faced significant disciplinary actions, such as when a

Sources

  • BleepingComputerGoogle fined €403 million over location data privacy violations
  • EngadgetGoogle fined $463 million for breaching EU location data rules