Ireland's DPC Fines Google USD 403 Million for Location Data Breach
Dublin, September 21 (QNA) - Ireland's Data Protection Commission (DPC) today imposed a fine of EUR 403 million, approximately USD 463 million, on Google for violating European Union rules governing the protection of users' location data.
The DPC, acting as Google's lead supervisory authority in the European Union, said an inquiry found that the company had infringed the General Data Protection Regulation (GDPR) between May 25, 2018 and Feb. 4, 2020, through three features: "Web & App Activity," "Location History" and "Location Accuracy."
The Commission said the infringements concerned the lawfulness and fairness of the processing of location data through the "Web & App Activity" and "Location History" features, as well as the company's failure to meet its accountability and transparency obligations in processing the data and its retention of some location data for longer than necessary.
DPC Deputy Commissioner Graham Doyle said Google's failures may have left users unaware that their location data was being used, for example, to influence them through advertising or to infer their interests.
He noted that retaining users' location data for longer than necessary aggravated their loss of control over their personal data.
The DPC ordered Google to bring its processing of location data into compliance with the GDPR within six months.
The Commission opened the inquiry in February 2020 after receiving complaints from several European consumer rights organizations concerning Google's processing of location data associated with certain services and products.
For its part, Google said the case concerned historical policies and that, since 2019, it had made extensive changes to the way it manages location data. These included allowing users to automatically delete data, storing Timeline data directly on users' devices, and providing tools to control how data, including location data, is used for advertising.
The fine is the fourth-largest imposed by the Irish Data Protection Commission on major technology companies, while the total fines it has levied since the GDPR took effect in 2018 have exceeded EUR 4 billion. (QNA)
English
Français
Deutsch
Español
русский
हिंदी
اردو