A €403 million fine for the mishandling of user geolocation data. The fine imposed on Google The Irish Data Protection Commission (DPC) found violations of the GDPR, the European General Data Protection Regulation. The decision focused on the way location information was processed, the lack of transparency towards users, and the retention of data beyond the necessary time.
The measure comes at the end of an investigation launched in February 2020, following complaints from several European consumer protection organizations. The investigations cover the period between May 2018, when the GDPR became applicable, and February 2020. Google maintains that the contested policies have since been modified and asserts its support for the measures introduced starting in 2019.
Violations in Google settings
The Irish regulator examined the data processing through some of the features used in the group's services. These include:Web and app activity“, the setting that records activities such as browsing and searches, and “Location history", the service that reconstructs the places visited by users with their phones. According to the DPC, Google did not comply with the requirements of lawfulness and fairness in the processing of location data through these features. For "Location accuracy“, present in the Android operating system, the regulator also found violations of transparency obligations.
The full formal reasons for the decision are not yet available. However, the information provided by the authority also reveals a dispute over the retention period for the information, which was retained for longer than necessary.
Location and advertising: the risk of losing control over your data
The case involves information that can reveal much more than just a person's location. Geolocation data allows us to reconstruct habits and deduce personal interests, also fueling the personalization of advertising. According to the Deputy Commissioner of the DPC, Graham DoyleThe shortcomings found could leave users completely unaware that their location was being used to target advertising or gather information about their interests. This resulted in a tangible loss of control over their personal data.
The regulator thus emphasizes the dual nature of this information. It can improve the usefulness of online services, but it can also reveal highly private aspects of people's lives. Therefore, its processing requires adequate safeguards and clear instructions on how it is used.
Google's response and other open investigations
Google traces the case back to past procedures.This case concerns previous policies that have since been updated“,” a spokesperson for the group said. “Since 2019, we have significantly improved our procedures and introduced effective tools that simplify location data management.”
The 403 million fine represents the fourth highest fine imposed by the Irish DPC, which oversees Google's European operations because the group has its headquarters in Dublin, the EU. The most serious precedent concerns Meta, fined in 2023 for 1,2 billion euros for the transfer of personal data from the European Union to the United States. Meanwhile, Google's confrontation with the authority does not end with this provision. The DPC has announced that it has three other privacy investigations still ongoing involving the group.
