Google Slapped with Record €403 Million Fine for GDPR Location Data Violations
Google has been fined €403 million by Ireland's Data Protection Commission (DPC) for violating the EU's General Data Protection Regulation (GDPR). The fine is tied to how three of its features handled people's location data from May 2018 to February 2020. The DPC found that Google breached GDPR rules on lawful and fair processing, transparency, and accountability.
The three features are Web & App Activity, Location History, and Location Accuracy. For both Web & App Activity and Location History, the DPC found that Google retained location data longer than necessary and could not demonstrate that this processing was lawful, fair, and transparent. This meant people may have been unaware their location was being used for targeted ads or to infer their interests.
The fine is the fourth-largest issued by the DPC and cannot be collected yet as it needs to be confirmed by an Irish court. Google can appeal to the High Court within 28 days of receiving formal notice of the decision. The company stated that the case 'centers around historical policies that have since been updated'.