Google Slapped with €403m GDPR Fine Over Invasive Location Tracking
The Irish Data Protection Commission (DPC) has fined Google €403m for violating EU data protection law, specifically the General Data Protection Regulation (GDPR).
The fine comes after six years of investigation into allegations that Google improperly processed sensitive user data between May 2018 and February 2020.
The DPC found that Google broke GDPR rules by storing location data for longer than necessary, using it to disclose targeted ads, and failing to provide sufficient transparency about this practice to users.
Graham Doyle, deputy commissioner at the DPC, noted that individuals could have been unaware of their location being used for targeted advertising or other purposes, leading to a loss of control over their personal data.