HeadlinesBriefing favicon HeadlinesBriefing.com

Google Fined €403M by DPC Over Location Data

Hacker News •
×

The Data Protection Commission (DPC) fined Google Ireland Limited €403 million for GDPR violations regarding location data processing. The inquiry, launched in February 2020 after complaints from European consumer rights organisations including BEUC, covered three features: Web & App Activity, Location History, and Location Accuracy from 25 May 2018 to 4 February 2020.

The decision, made by Commissioners Dr Des Hogan, Mr Dale Sunderland, and Ms Niamh Sweeney, found Google infringed the GDPR on lawfulness and fairness, accountability, transparency, and retention of location data. Google must comply within 6 months.

Deputy Commissioner Graham Doyle commented: "Location data can bring both benefits and harms to individuals. It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private. The GDPR provides a high level of protection of personal data throughout the EEA, and requires that the processing of personal data must be carried out in a lawful, fair and transparent manner. As a result of Google’s failures in this regard, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data. The retention of users’ location data for longer than necessary aggravated this loss of control."

The DPC thanked peer supervisory authorities and will issue the full decision in due course.