Overview
- The Irish Data Protection Commission fined Google €403 million on Monday after finding the company failed to be transparent about using precise location information and kept that data longer than necessary.
- The DPC said the breaches stemmed from three Google features that processed activity and precise location history between May 2018 and February 2020 and that those features were disabled in 2020.
- Alongside the monetary penalty the regulator gave Google a maximum of six months to change its systems so users regain control over location data and retention practices.
- Google responded that the DPC’s findings relate to earlier policies, that it began changing practices in 2019, and that it has since introduced tools to let users manage location settings.
- The DPC acts as the EU lead regulator for many US tech firms so the ruling highlights growing European scrutiny of how companies use sensitive location data and could prompt wider operational changes across the industry.