Google was fined 403 million euros, worth more than Rs. 4,000 crore, by Ireland’s Data Protection Commission (DPC) over its handling of users’ location data. The regulator found that Google violated the European Union’s General Data Protection Regulation (GDPR) between 2018 and 2020.
The case focused on three Google services: Web and App Activity, Location History and Location Accuracy. The DPC said Google did not always provide users with enough information about how their location information was being processed.
The DPC opened its investigation in 2020 after complaints from consumer rights groups, including the European consumer organization BEUC. The regulator examined how Google handled location information through its services during the period covered by the investigation.
Web & App Activity collects information about activity across Google services. Location History records location information from mobile devices. The regulator said users may not have fully understood how this information could be used.
DPC Deputy Commissioner Graham Doyle said, “As a result of Google’s failures, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data.”
DPC gave Google six months to bring its location data processing in line with EU privacy rules. The regulator also said three other statutory investigations into Google are at an advanced stage.
Google said the investigation relates to older policies. The company said it introduced several changes to its approach to location information. These changes include tools for automatic deletion of personal data. Google also added an option to store Timeline data directly on users’ devices.
The company confirmed that users now have greater control over how their data is used for advertizing. The 403 million euro penalty is the fourth-largest fine issued by Ireland’s DPC. The regulator imposed more than 4 billion euros in penalties since becoming the lead EU privacy regulator for many major US technology companies operating from Ireland.
Also Read: Facebook, Instagram Under Scanner as EU Tightens Child Safety Rules; What This Means for You