Google has been fined €403 million, roughly $463 million, by Ireland’s Data Protection Commission for violating European Union privacy rules involving its Web & App Activity, Location History and Location Accuracy features.
The regulator found that Google did not lawfully or fairly process location data through Web & App Activity and Location History and failed to meet transparency requirements. Officials also found issues with the retention of location data through the two services.
Web & App Activity can process information including browsing history, searches, and location data. Location History tracks a user’s movements and can create a map showing places they have visited, while Location Accuracy is an Android feature designed to determine a device’s location more precisely than GPS alone.
The DPC said location data can reveal significant personal information, including a person’s movements, activities and interests. Regulators concluded that Google’s practices could have left users unaware of how their location information was being used and limited their ability to control it.
The investigation examined Google’s practices from May 25, 2018, through Feb. 4, 2020. Ireland is Google’s lead privacy regulator in the EU because the company’s European headquarters are located in Dublin.
Google said the case concerns historical policies that have since been updated. The company pointed to newer privacy controls, automatic deletion options, and tools that allow users to store less precise location information.
The DPC also ordered Google to bring its processing of the affected location data into compliance with EU privacy rules within six months.
Comments
No comments yet. Be the first to share your thoughts.