
The Republic of Ireland’s Data Protection Commission imposed a €403m penalty against Google following a six-year investigation into the technology company’s handling of location information. The inquiry was initiated based on complaints lodged by multiple European consumer protection organizations.
The watchdog’s investigation focused on Google’s processing of location data across three specific features—Web & App Activity, Location History, and Location Accuracy—during the period spanning 25 May 2018 to 4 February 2020. The DPC determined that Google’s practices violated the General Data Protection Regulation, the EU’s comprehensive privacy and security framework that took effect on 25 May, 2018. According to the commission, Google processed location information in ways that were neither lawful, fair, nor transparent.
DPC deputy commissioner Graham Doyle emphasized that location data can disclose sensitive personal information about individuals. The investigation found that users may not have been adequately aware their location was being tracked for purposes such as targeted advertising or interest inference, and that the prolonged retention of location information beyond necessity compounded the loss of user control over personal data.
In response, Google stated that the practices in question reflect outdated policies that have since undergone significant revision. The company noted that since 2019, it has implemented enhanced safeguards including automatic data deletion options allowing users to set three, 18, or 36-month rolling deletion cycles. Additional protections introduced include personalized advertising controls and improved transparency measures regarding location data practices.
The DPC has ordered Google to achieve full compliance with data processing requirements within six months of the decision.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI