Ireland’s Data Protection Commission (DPC) has fined “Google” €403 million ($463 million) for violating the European Union’s General Data Protection Regulation (GDPR) in its processing of users’ location data, according to the regulator.
The commission announced its final decision on Monday after an inquiry into the data practices of “Google Ireland Limited”. The investigation was launched in February 2020 following complaints from several European consumer rights organisations.
Investigation into three Google features
The inquiry examined how “Google” processed location data through three features — Web & App Activity, Location History and Location Accuracy — between May 2018 and February 2020.
The DPC found that the company breached GDPR requirements concerning the lawfulness and fairness of its data processing, as well as its accountability obligations. The regulator also said “Google” violated transparency requirements across all three features.
Google given six months to comply
The decision found that the company retained users’ location data for longer than necessary. The DPC imposed administrative fines totalling €403 million and ordered “Google” to bring its data processing practices into compliance within six months.
Graham Doyle, deputy commissioner at the Data Protection Commission, said location data could reveal inherently private information about an individual.
He warned that users could lose control over their personal data, adding that retaining location information for longer periods had worsened that loss of control.