
Ireland DPC: Google Ireland DPC Location Data Fine Is €403M
Summary
- Ireland's Data Protection Commission fined Google 403 million euros for unlawfully handling user location data.
- The DPC, Google's lead EU privacy regulator, also ordered Google's Irish subsidiary to comply with EU law within six months.
- The fine resulted from an inquiry into Google's practices between May 2018 and February 2020, following complaints from consumer groups led by BEUC.
- Regulators found Google's Web & App Activity, Location History, and Location Accuracy features violated GDPR principles by being unfair, unlawful, and lacking transparency.
- Google stated the case concerns "historical policies" that have since been updated, including new automatic data deletion options.
The Landmark Fine and Compliance Order
The inquiry concluded that Google processed location data unlawfully and unfairly through its "Web & App Activity" and "Location History" features.
Ireland's Data Protection Commission (DPC), acting as Google's primary privacy regulator within Europe, has imposed a substantial fine of 403 million euros, equivalent to approximately $462 million, on the tech giant. This penalty stems from the DPC's determination that Google unlawfully handled user location data, violating European Union regulations. The DPC's decision mandates that Google's Irish subsidiary rectify its practices and ensure full compliance with EU law regarding the processing of location information within a six-month period.
Google has publicly stated its intention to appeal this ruling. It is also important to note that the monetary sanction itself requires formal court approval before it can be collected. This action by the Irish DPC underscores the stringent enforcement of GDPR by European data protection authorities, particularly concerning sensitive location data.
Regulatory Findings and Specific Violations
The DPC's investigation, which commenced in February 2020, scrutinized Google's data handling from May 25, 2018, the effective date of the EU's General Data Protection Regulation (GDPR), through February 4, 2020. The inquiry concluded that Google processed location data unlawfully and unfairly through its "Web & App Activity" and "Location History" features. Specifically, the regulator found that Google retained this sensitive data for an excessive duration and failed to provide users with sufficiently clear explanations of its data collection practices.
The "Web & App Activity" feature was capable of combining location information with users' search queries and browsing history, while the "Location History" service, though opt-in, tracked individuals' movements via Timeline even when they were not actively using a Google service. A separate finding concerned "Location Accuracy," a feature designed to enhance Android device positioning beyond standard GPS. For this, Google could not demonstrate that its data handling was lawful, fair, and transparent, a distinct issue from the unlawful processing identified in other features. Notably, "Location Accuracy" could function even without a Google account, and the DPC found that users were not adequately informed about these practices.
Genesis of Consumer Complaints and Privacy Concerns
The DPC's action follows a series of coordinated complaints filed in November 2018 by seven consumer organizations, spearheaded by the European Consumer Organisation (BEUC), with a separate complaint also lodged by a Danish group. These groups sought an investigation, an end to unlawful location data usage—particularly for targeted advertising—and a significant fine to deter future infringements. They highlighted that "Web & App Activity" was often enabled by default, with crucial information about location data collection obscured behind multiple clicks.
Users who attempted to decline the "Location History" service reportedly faced persistent prompts across various Google platforms. Furthermore, the consumer advocates argued that selecting a useful feature, such as photo sorting by location, should not implicitly force users into accepting broader tracking and advertising applications. They firmly rejected Google's advertising interests as a legitimate justification for such intrusive data collection. Graham Doyle, a deputy commissioner at Ireland's privacy regulator, underscored the dual nature of location data, noting its potential to improve services while simultaneously exposing deeply private information, often without users' full awareness that their whereabouts were being used for ad targeting or interest profiling, with prolonged retention further diminishing user control.
Industry Reaction and Google's Response
BEUC's Director General, Agustín Reyna, welcomed the DPC's decision, though he expressed criticism regarding the nearly eight-year delay in enforcement, suggesting that delayed action could be as detrimental as no action at all. Reyna asserted that the ruling confirmed Google had obtained user consent unlawfully and accused the company of tracking hundreds of millions of Europeans for years, potentially revealing sensitive personal details such as children's school locations, hospital visits, and places of worship.
In response, a Google spokesperson stated that the case revolved around "historical policies that have since been updated." The company pointed to changes implemented since 2019, including options for automatic data deletion after three, 18, or 36 months, and the storage of Timeline data directly on users' devices, with automatic deletion of data older than three months. Despite these updates, BEUC indicated that while Google had modified its practices globally following the initial complaint, it had not adequately addressed deceptive design elements, leading to a subsequent complaint filed by the organization in 2022.
Practical Implications
This ruling underscores the stringent enforcement of GDPR by European data protection authorities, particularly concerning location data. Lawyers and compliance officers should review their clients' (or their own organization's) data collection, consent mechanisms, and data retention policies for location information, ensuring full transparency and compliance with EU data protection principles, even for historical practices.
Source
How does this affect you?
Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.
Finish Reading the Full Story and the Expert Analysis.
Get the latest legal & regulatory intelligence in United States
Wansom is AI and can make mistakes.
