Users could have been unaware that their data was being used for ads, DPC deputy commissioner said.
The Irish data protection watchdog has fined Google €403m and ordered the tech giant to become compliant with the region’s privacy regulations within six months.
The Data Protection Commission (DPC), concluding a six-year-long probe, found that Google did not comply with the EU’s GDPR when processing data generated in the bloc.
Its inquiry, triggered by complaints from European consumer rights organisations, including from BEUC, probed how the company processed location data across its ‘web & app activity’, ‘location history’ and ‘location accuracy’ features between May 2018 and February 2020.
‘Web & app activity’ is a Google account setting that processes information related to users’ activity on Google services, including sites and apps, meanwhile ‘location history’ tracks users’ locations and processes it as visited places, activities and paths between locations.
The complaints raised concerns relating to the “legality of Google’s processing of location data and the transparency surrounding that processing”, the DPC said in a statement announcing the probe in 2020.
The probe found that Google infringed the GDPR by failing to lawfully process its location data, failing to demonstrate its compliance with the GDPR and failing to meet its transparency obligations across the features in question.
“Location data can bring both benefits and harms to individuals,” said DPC deputy commissioner Graham Doyle.
“It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private.
“The GDPR provides a high level of protection of personal data throughout the EEA, and requires that the processing of personal data must be carried out in a lawful, fair and transparent manner.
“As a result of Google’s failures in this regard, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data. The retention of users’ location data for longer than necessary aggravated this loss of control”.
In a statement to SiliconRepublic.com, a Google spokesperson said that the case centres around “historical policies” that have been updated since.
“From 2019 onwards, we’ve significantly evolved our practices and launched robust tools that make managing location data simple,” the company said.
In 2019, Google introduced auto-delete controls that allow users to automatically delete data on a rolling three, 18 or 36-month basis. In 2023, it updated its location history feature to enable timelines to be stored directly on users’ devices.
Google also says it does not store precise location data in ‘web & app activity’ and allows users to manage how their data is used for ads.
This is the DPC’s fourth largest fine since the GDPR came into effect. In 2023, Meta received the largest fine issued by the watchdog to date, raking in €1.2bn in penalties after illegally transferring Facebook user data from the EU to the US.
Last year, TikTok was fined €530m for transferring personal user data to China, while Meta was also subject to a separate €405m fine in 2022 for publicly disclosing contact details of children using Instagram’s business accounts.
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.


