The data-protection watchdog has fined Google €403 million after an inquiry found that the tech giant’s processing of location data had breached the GDPR.
The Data Protection Commission (DPC) had opened the probe in 2020 after complaints from European consumer-rights organisations.
The infringements covered a period from May 2018 to February 2020 and Google’s processing of location data in three specific features:
The breaches included:
DPC deputy commissioner Graham Doyle said that, while location data could greatly enhance the utility of online services, it could also reveal a significant amount of information about an individual – including information that was inherently private.
He added that the GDPR required that the processing of personal data must be carried out in a lawful, fair, and transparent manner.
“As a result of Google’s failures in this regard, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data.
“The retention of users’ location data for longer than necessary aggravated this loss of control,” he added.
Google said that the case centred on historical policies that had since been updated.
"From 2019 onwards, we've significantly evolved our practices and launched robust tools that make managing location data simple," RTÉ quoted a spokesperson as saying.