Irish Data Authority Imposes Major Fine on Google
The Irish Data Protection Commission (DPC) has levied a €403 million penalty against Google for breaching data privacy regulations related to the collection of users’ location information between 2018 and 2020. The fine addresses shortcomings found in three specific features: Web & App Activity, Location History, and Location Accuracy. The regulator has required Google to bring its data handling practices into full compliance within six months.
Investigation Background and Google's Response
The investigation that led to this fine began in 2020 following complaints from European consumer rights groups, including BEUC. This ruling marks the fourth largest penalty imposed on Google by the Irish DPC since the implementation of GDPR in 2018. Google is also currently facing three additional ongoing probes by the authority.
Google stated that the fine concerns outdated policies, which the company claims have been significantly updated since 2019. Since then, Google has introduced new measures for processing location data, such as automatic data deletion tools. Nevertheless, Graham Doyle from the DPC emphasized that retaining location data longer than necessary contributed to users losing control over their personal information.
Graham Doyle highlighted that due to Google's lapses, users were often unaware that their location data was being exploited for advertising purposes or to profile their interests, resulting in diminished control over their personal privacy.
Google plans to challenge the decision in the appeals court, signaling its intent to contest the allegations vigorously.
This fine reflects a broader trend of increased regulatory scrutiny on tech giants across Europe, especially regarding data protection. Regulatory successes in uncovering violations are intensifying pressure on companies like Google to improve their data management practices. The ruling also underscores the critical role of GDPR in safeguarding consumers’ rights in the digital age.