3 min read

Google’s €403M location case gives it six months to comply

Ireland’s privacy regulator fined Google €403 million over location-data controls and ordered GDPR compliance within six months.

Google’s €403M location case gives it six months to comply

Image: Engadget

Google must pay €403 million ($463 million) and bring its location-data processing into compliance with the General Data Protection Regulation within six months, after Ireland’s Data Protection Commission found failures across three Google account and Android location controls.

The regulator examined Web & App Activity, Location History, and Location Accuracy—three settings that govern different ways Google can collect, retain, or improve location signals. The DPC opened its inquiry in 2020 following complaints from consumer-rights groups and examined processing from May 2018 through February 2020.

Google’s European headquarters is in Dublin, making Ireland’s DPC its lead EU privacy regulator. The regulator’s published enforcement notice says the penalty is its fourth-largest since GDPR took effect.

Three controls, different regulatory failures

The three settings have different roles. Web & App Activity stores activity across Google services. Location History is an opt-in feature that presents a timeline of places a user has visited with their phone. Location Accuracy helps determine an Android device’s position more precisely than GPS alone.

Google featureFunction described in the inquiryDPC finding
Web & App ActivitySaves activity across Google servicesProcessing was not fair or lawful; transparency and location-data retention rules were breached
Location HistoryOpt-in phone-location timelineProcessing was not fair or lawful; transparency and location-data retention rules were breached
Location AccuracyImproves Android positioning beyond GPS aloneGoogle did not demonstrate compliance with the lawfulness, fairness and transparency principle; transparency rules were breached

The DPC did not describe the case simply as a consent failure. For Web & App Activity and Location History, it found Google had not processed the data fairly or lawfully. For Location Accuracy, Google failed to demonstrate compliance with GDPR’s lawfulness, fairness and transparency principle. The regulator also found Google failed transparency requirements across all three features.

LG’s TV privacy defense leaves its data lifecycle unanswered

Recommended reading

LG’s TV privacy defense leaves its data lifecycle unanswered

Sergey Kuznetsov 10 min read

The retention finding applies to Web & App Activity and Location History, not Location Accuracy. The six-month remediation order covers more than product explanations: Google must make its processing compliant, including the retention practices the DPC found deficient for two of the three controls.

Google says the policies have changed

Google described the enforcement action as a decision about older practices, saying it has changed its location-data tools since the inquiry period.

“This case centers around historical policies that have since been updated. From 2019 onwards, we’ve significantly evolved our practices and launched robust tools that make managing location data simple.”

Google statement to the Associated Press

Google says changes began in 2019, while the DPC’s review window ran through February 2020. The fine and compliance deadline indicate that the regulator did not consider that assertion sufficient to resolve the GDPR findings.

The reporting does not specify which current product flows or technical retention controls Google will change to meet the six-month order. It also does not state whether the DPC will require changes visible to users, changes to Google’s internal handling of signals, or both. Those details will determine whether the remedy changes location controls in practice or primarily the legal basis and disclosures supporting them.

A large fine, with more Google inquiries pending

The €403 million penalty is the fourth-largest issued by Ireland’s DPC since GDPR came into force. The largest cited by the regulator was its $1.3 billion fine against Meta over transfers of EU Facebook user data to U.S. servers.

The DPC also said it has three other statutory large-scale inquiries involving Google open at an advanced stage. Their subject matter, possible remedies, and timelines were not provided in the reporting.

For Google, the immediate figure is €403 million. The six-month compliance deadline applies to settings across Google services and Android’s location stack. The decision distinguishes Google’s claim that its tools evolved from the regulator’s conclusion that the processing required a formal remedy.

Frequently asked questions

Why was Google fined €403 million by Ireland?+

Ireland’s Data Protection Commission found GDPR failures in Google’s handling of location data through Web & App Activity, Location History and Location Accuracy.

When must Google comply with the DPC order?+

The DPC ordered Google to make its location-data processing compliant with GDPR within six months.

Which Google location settings were covered by the inquiry?+

The inquiry covered Web & App Activity, Location History and Location Accuracy, and reviewed processing from May 2018 through February 2020.

Has Google responded to the location-data fine?+

Google said the case concerns historical policies, and that it had significantly evolved its practices and location-data management tools from 2019 onward.

Sergey Kuznetsov

Editor-in-Chief

Sergey Kuznetsov is Head of Product at iXBT.com, one of the largest Russian-language technology media outlets, and the founder of itzine.ru. He has spent over a decade building and running tech newsrooms. At for(geeks) he sets editorial standards and reviews what ships.

/ Keep reading