Ireland’s Data Protection Commission (DPC) has fined Google €403 million ($463 million) over the way it has handled location data from Android and Google account users, after finding out that the tech giant lacked any sort of legal basis for processing the information and its users were not given enough clarity regarding what they were agreeing to.
The DPC found that Google failed to process location data lawfully, fairly and transparently across three products which included Web & App Activity, Location History and Location Accuracy. The first two products can track browsing and search activity as well as the places a user’s device has previously visited, while Location Accuracy is just an AndroidOS setting.
The Irish regulator has also pointed to the extensive privacy risks that come with location tracking. Deputy Commissioner Graham Doyle said location data can make online services more useful, but can also reveal highly private and sensitive information about a person.
According to the Guardian, the commissioner said users may not have known their whereabouts were being used to target advertising or infer what their interests could be. Keeping the information for longer than necessary, he added, further reduced users’ control over their data.
The Irish regulator’s inquiry started from the date the General Data Protection Regulation took effect on May 25, 2018 for a period of almost two years till February 4, 2020.
The case began with complaints from seven European consumer organizations, accusing Google of tracking users throughout their daily lives. Their concerns drew on 2018 research by Norway’s consumer agency, the Forbrukerrådet, which argued that Google used “various tricks” to keep Location History and Web & App Activity enabled.
The research also stated how and why location tracking can expose much more than simply the geographical locations someone has been to. Visits to places of worship can reveal religious beliefs, attendance at demonstrations can point to political views, hospital visits can indicate health conditions, while the venues someone visits can reveal their sexual orientation.
Finn Myrstad, digital policy director at the Norwegian Consumer Council, described the ruling as a milestone. According to the Guardian, Myrstad said people should be able to understand what they are agreeing to without being misled or pressured into choices they would not otherwise make.
The European Consumer Organisation, known as BEUC, likewise described geolocation as one of the most invasive forms of consumer surveillance.
While BEUC director general Agustín Reyna welcomed the decision, he criticized the time it took to reach it. He described the delay as “disproportionate with the seriousness of the infringement” and warned that “late enforcement can be as harmful as no enforcement at all.”
For context, the DPC opened its investigation six years ago.
Google, meanwhile, has pointed to changes the company claims it has made since the period covered by the inquiry. A spokesperson said the case concerns historical policies that have since been updated, adding that the company had notably changed its practices from 2019 onward and introduced tools to make location data easier to manage.
The DPC has also given Google six months to bring its processing practices into compliance with the GDPR.
Google’s European headquarters are in Dublin, making the Irish watchdog its lead regulator across the 27-member EU. The DPC holds the same role for most major US technology companies with their European bases in Ireland.
The €403 million penalty is the fourth-largest fine issued by the Irish regulatory commission. According to the Guardian, the DPC has previously fined Meta €1.2 billion, TikTok €530 million and Meta-owned Instagram €405 million.
The latest decision may not be the regulator’s final action against Google this year, with three other investigations into the company already at an advanced stage.
The smartest crypto minds already read our newsletter. Want in? Join them.