IRELAND’S Data Protection Commission (DPC) has fined Google €403 million for alleged GDPR violations involving the handling of location data. The investigation began in February 2020 after complaints from European consumer groups, including BEUC, and covered processing between 25 May 2018, when the GDPR came into force, and 4 February 2020. It examined Google’s Web & App Activity, Location History and Location Accuracy features.
According to the DPC, Google did not meet GDPR requirements for lawfulness and fairness in its processing through Web & App Activity and Location History. It also failed to demonstrate that Location Accuracy complied with requirements for lawfulness, fairness and transparency. The regulator found transparency shortcomings across all three features and said location data was retained for longer than permitted.
Web & App Activity could include location data linked to activity across Google services, while Location History recorded device movements in a Timeline. Location Accuracy, an Android feature that improves positioning beyond raw GPS, could affect people without a Google account.
The DPC said users may not have understood that their location data could be used for advertising or to build interest profiles, limiting their control over it. Google has six months to bring its processing into compliance with the GDPR. The penalty is described as the fourth-largest issued by Ireland’s regulator. The article does not report confirmed criminal activity or a technical compromise; the case concerns data-processing practices and regulatory compliance.