Data Protection Commission fines Google €403 million over processing of location data
The Data Protection Commission (DPC) has today announced its final decision following an inquiry into Google Ireland Limited (Google). This own-volition inquiry was launched by the DPC, in its role as the Lead Supervisory Authority for Google, in February 2020, following receipt of complaints from several European consumer rights organisations, including BEUC, regarding Google’s processing of location data in connection with certain services and products.
The scope of the inquiry concerned Google’s processing of location data in three specific features – ‘Web & App Activity’, ‘Location History’ and ‘Location Accuracy’ between the date of application of the GDPR, 25 May 2018 to 4 February 2020.
The decision, which was made by the Commissioners for Data Protection, Dr Des Hogan, Mr Dale Sunderland and Ms Niamh Sweeney, finds that Google infringed the GDPR in respect of:
the lawfulness and fairness of its processing of location data in Web & App Activity and Location History,
- its accountability obligations under the GDPR by failing to be able to demonstrate compliance with the lawfulness, fairness and transparency principle regarding its processing of personal data in Location Accuracy;
- its transparency obligations in respect of all three features referred to above; and
- its retention of location data in Web & App Activity and Location History.
The DPC has imposed administrative fines totalling €403m (£369m) and has ordered Google to bring its processing into compliance within 6 months.
Deputy Commissioner, Graham Doyle commented: “Location data is a type of personal data which is processed by way of location tracking, and includes data collected or processed by Google, which by itself or in conjunction with other information an individual’s location can be inferred. Location data can bring both benefits and harms to individuals. It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private.
“The GDPR provides a high level of protection of personal data throughout the EEA and requires that the processing of personal data must be carried out in a lawful, fair and transparent manner. As a result of Google’s failures in this regard, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data. The retention of users’ location data for longer than necessary aggravated this loss of control.”

