Google Slapped with €403M Fine for Breaching GDPR Location Data Rules
Ireland's Data Protection Commission has fined Google $462 million for collecting users' location data in breach of GDPR. The tracking was done by three Google features: Web & App Activity, Timeline, and GLA (Google Location Accuracy).
Web & App Activity is a Google account setting that collects user data when it's enabled, including location information. This data helps personalize search results and ads. For example, it might display ads from stores near the user in a shopping-related search results page.
Timeline is an opt-in feature that logs the location of the user's device periodically. It turns this data into a map, enabling users to check the places they've visited and the routes they took.
The investigation focused on the data collected between May 25, 2018, when GDPR went into effect, and February 4, 2020. The DPC found that Google breached the lawfulness, fairness, and transparency principle of GDPR by not providing users with a detailed overview of their location data collection.