Google Slapped with €403m GDPR Fine Over Location Data Practices
The Data Protection Commission (DPC) has fined Google €403m for violating the EU's General Data Protection Regulation (GDPR). The fine is the result of a six-year-long investigation into how Google processed location data from users in the European Economic Area (EEA).
The DPC found that Google infringed the GDPR by failing to lawfully process its location data, failing to demonstrate compliance with the regulation, and failing to meet transparency obligations. Specifically, the inquiry focused on the 'web & app activity', 'location history', and 'location accuracy' features between May 2018 and February 2020.
The DPC's deputy commissioner, Graham Doyle, stated that location data can bring both benefits and harms to individuals, and that the GDPR provides a high level of protection for personal data. He noted that Google's failures in this regard could have left users unaware that their location was being used for advertising or other purposes.
Google responded by stating that the fine centers around 'historical policies' that have been updated since 2019. The company claimed to have evolved its practices and introduced tools that make managing location data simpler, including auto-delete controls and direct storage of timelines on users' devices.