Overview
- The Irish Data Protection Commission issued the €403 million fine on Monday after a multi-year probe into Google’s handling of location data.
- The decision covers three services—Web & App Activity, Location History and Location Accuracy—and examines data practices from May 25, 2018 to February 4, 2020.
- Regulators found Google breached GDPR requirements for lawfulness, fairness and transparency, stored location data longer than necessary, and left users unaware their movements could be used for advertising and profiling.
- The DPC has given Google six months to bring its processing into compliance, while Google says the problems relate to earlier practices and that it updated controls and tools from 2019 onward.
- Privacy groups welcomed the ruling but criticized the long investigation times that stem from Ireland’s role as the EU regulator for many US tech firms, and the decision could influence other pending cases and how companies design consent and retention controls.