€403 Million Fine Highlights Ongoing Regulatory Risk for Alphabet
Google has been hit with another significant European regulatory penalty, this time for its handling of user location data. The Irish Data Protection Commission (DPC) fined Google €403 million ($463 million), finding that the company infringed on the EU's General Data Protection Regulation (GDPR). The fine relates to Google's processing of location data between 2018 and 2020 through three features: Web & App Activity, Location History, and Location Accuracy.
Google claims its approach to location data has changed significantly since 2019. The company says it has introduced robust tools that allow users to automatically delete personal data on a rolling basis, store timeline data directly on their devices, and control how data is used for advertising. However, the DPC's decision requires Google to bring its processing of location data into compliance within six months.
The fine ranks as the fourth-largest penalty imposed by the Irish regulator since it became the lead EU regulator for many major U.S. technology companies under GDPR. The DPC has three separate statutory inquiries ongoing against Google, which are at an advanced stage.