Search
Choose a style
Dark
Light
Time to read: 3 min

Irish watchdog fines Google €400m for GDPR breach

google gavel

The DPC ruling said users may not have known their location data was being used to determine the ads they were shown.

Google has been fined over €400m (£345m) for its processing of user location data in a GDPR ruling.

The fine, which is one of the largest of its kind from Ireland’s Data Protection Commission (DPC), follows claims the Alphabet-owned firm manipulated users into agreeing to be continually tracked on their phones.

European consumer organisations complained Google was collecting extensive location data from users. Research published by the Norwegian consumer agency, Forbrukerrådet, alleged Google used “various tricks” to make sure location history and web and app activity were enabled.

The DPC investigation, which was launched six years ago, found the tech giant’s use of location data “infringed” on the European Union’s (EU) General Data Protection Regulation (GDPR), which establishes strict data privacy laws.

The watchdog found Google’s policy did not lawfully or fairly process location data under the ‘web and activity settings’, which tracks search and browser history, or its location history.

As a result, users could have been unaware that their location was used to influence the ads they were targeted.

DPC deputy commissioner Graham Doyle said “location data is personal data” and the practices “reveal a significant amount of information about an individual, including information that is inherently private”.

He continued: “As a result of Google’s failures… individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data.

“The retention of users’ location data for longer than necessary aggravated this loss of control.”

Google has been ordered to bring its data processing into compliance within the next six months as part of the ruling.

Google says its policy has since evolved

Google responded to the investigation, outlining the policy this case centres around is a historical one. After 2019, the company said, its policy has “significantly evolved”, with “robust tools” introduced since then to manage location data.

Improvements in data protection include “industry-first auto-delete controls”, which enable all users to “set your account to automatically delete your data on a rolling three, 18, or 36-month basis”.

The tech giant has also introduced new safeguards such as increased transparency, which includes “consolidated detailed information about our location data practices and account settings”, as well as “simple ads management”, which gives users the ability to “to turn off personalised ads entirely”.

Affiliate Leaders has reached out to Google but is yet to receive a response.

The DPC has previously fined Meta, Instagram, and TikTok for GDPR violations.

Subscribe to our newsletter