Google Slapped with €403M Fine for GDPR-Related Location Data Violations
The Irish Data Protection Commission (DPC) has fined Google €403 million for violating GDPR rules related to processing users' location data. The agency launched an investigation in February 2020 after receiving complaints from consumer rights organizations.
Three Google features were examined, which allowed the company to process users' web and app activity, location history, and location accuracy data:
The Web & App Activity setting allowed Google to collect browsing history, search history, and location data, potentially influencing users with ads or inferring their interests. Location History tracked users carrying compatible mobile devices and displayed this information through a private Google Maps Timeline. Location Accuracy helped Android devices determine their position more accurately than GPS alone.
The DPC found that Google processed location data without meeting GDPR requirements and failed to demonstrate compliance with personal data principles when processing through Location Accuracy.