Google Slapped with €403M Fine: What This Means for Your Data and the Future of Tech Giants
Ever wonder if your phone knows your every move — and if that info is being used in ways you didn’t quite sign up for? Well, Google Ireland just got slapped with a hefty €403 million fine by the Data Protection Commission for flouting GDPR rules on location data. That’s not pocket change — it ranks as the fourth-largest fine in Ireland’s data protection history, trailing only Meta and TikTok. From Web & App Activity to Location History and Location Accuracy, Google’s handling of our whereabouts has been under the microscope — and folks, the verdict? Not exactly transparent or fair. It’s a stark reminder that while location data can supercharge our online experience, it also opens doors to privacy pitfalls we might not even see coming. Now Google has six months to clean up its act — because, in the digital world, knowledge is power, but control is everything. LEARN MORE
Google Ireland has been fined €403m by the Data Protection Commission for infringing GDPR with its processing of location data.
It is the fourth-largest fine issued by Ireland’s data protection authority after penalties levied against Meta (€1.2bn and €405m) and TikTok €530m.
DPC found that between May 2018 and the launch of its investigation in February 2020, Google contravened GDPR with the lawfulness and fairness of its processing of location data in three areas: Web & App Activity, Location History and Location Accuracy.
Web & App Activity refers to a Google account setting that, when enabled, processes information such as browsing history, search history and location data related to users’ activity on Google sites and apps.
Location History, meanwhile, is an optional service that tracks the location of users’ compatible mobile devices. It uses a ‘Timeline’ feature that displays as a private map on Google Maps, allowing users to see where they have travelled.
Location Accuracy refers to a feature on Android OS that allows an Android device to determine its location with greater accuracy than by relying on inputs from its GPS unit.
The tech giant was also found by the Commissioners for Data Protection to have infringed on its accountability obligations under GDPR by failing to demonstrate lawfulness, fairness and transparency with regard to its processing of personal data in Location Accuracy.
Similarly, it was found to have failed in its transparency obligations in respect of all three features as well as in its retention of location data in Web & App Activity and Location History.
“Location data is a type of personal data which is processed by way of location tracking, and includes data collected or processed by Google, which by itself or in conjunction with other information an individual’s location can be inferred,” said Graham Doyle, deputy commissioner at the DPC.
“Location data can bring both benefits and harms to individuals. It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private.
“The GDPR provides a high level of protection of personal data throughout the EEA, and requires that the processing of personal data must be carried out in a lawful, fair and transparent manner.

“As a result of Google’s failures in this regard, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data.
“The retention of users’ location data for longer than necessary aggravated this loss of control.”
The company now has six months to bring its processing into compliance with GDPR. The DPC also has three other ongoing inquiries concerning Google, all of which are at an advanced stage.
(Pic: Getty Images)




Post Comment