Google Slapped with $463M Fine over Location Data Breaches
The Irish Data Protection Commission (DPC) has fined Google $463 million for violating the EU's General Data Protection Regulation (GDPR) rules regarding the processing of users' location data.
The commission announced its final decision on Monday, following an inquiry into the processing of location data by Google Ireland Limited. The investigation focused on how Google processed location data in three specific features: Web & App Activity, Location History, and Location Accuracy, between May 2018 and February 2020.
The DPC found that Google infringed the GDPR regarding the lawfulness and fairness of its data processing and its accountability obligations. The company also violated transparency obligations across all three features and retained user location data longer than necessary.
Data Protection Commission Deputy Commissioner Graham Doyle stated, 'location data can reveal inherently private information about an individual' and warned that users could lose control over their personal data due to the retention of user location data for longer periods.