Irish DPC Fines Google €403 Million Over Location Data Processing
Key Takeaways
- €403 Million Fine: Ireland’s Data Protection Commission fined Google €403 million over GDPR violations involving its processing of location data.
- Three Features Examined: The inquiry covered Web & App Activity, Location History and Location Accuracy between May 25, 2018, and Feb. 4, 2020.
- Multiple GDPR Infringements: The DPC found violations involving lawfulness, fairness, transparency, accountability and data retention, with the specific findings differing among the three features.
- Six Months to Comply: Google has been ordered to bring the processing covered by the decision into compliance within six months.
Deep Dive
Ireland’s Data Protection Commission has fined Google €403 million over its processing of location data, concluding an investigation that began in 2020 and reached back to the first day the GDPR took effect.
The decision concerns three Google features that handled location information in different ways: Web & App Activity, Location History and Location Accuracy. The DPC examined their processing of location data from May 25, 2018, through Feb. 4, 2020, and found GDPR infringements across all three.
For Web & App Activity and Location History, the regulator found that Google Ireland Limited infringed requirements governing the lawfulness and fairness of its processing. It also found transparency infringements involving all three features and violations concerning the retention of location data through Web & App Activity and Location History.
Location Accuracy presented a different problem. The DPC found that Google failed to meet its accountability obligations because it could not demonstrate compliance with the GDPR principle requiring personal data to be processed lawfully, fairly and transparently.
The findings have resulted in administrative fines totaling €403 million. Google has also been ordered to bring the processing covered by the decision into compliance within six months.
The inquiry had been a long time coming. The DPC opened it on its own initiative in February 2020 after receiving complaints from several European consumer rights organizations, including BEUC. Ireland's regulator handled the case in its role as Google's lead supervisory authority under the GDPR.
At the center of the case is a category of personal information whose significance is difficult to separate from its intimacy. A person's location can make a digital service considerably more useful. Collected over time, it can also say a great deal about where that person goes and, by inference, what they do.
“Location data can bring both benefits and harms to individuals,” DPC Deputy Commissioner Graham Doyle said. “It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private.”
The regulator's concerns extended beyond the collection of that information to what people understood about its use.
According to Doyle, Google's failures meant individuals could have been unaware that their location information was being used to influence the advertising they saw or to infer their interests. The DPC also found that location data was retained for longer than necessary in Web & App Activity and Location History, which Doyle said aggravated the resulting loss of control over personal data.
The three features at issue do not work in quite the same way. Web & App Activity is a Google Account setting available only to account holders. When enabled, it allows Google to process information about a user's activity on its services, including activity on sites and apps. That information can include browsing history, search history and location data.
Location History is an opt-in service that tracks a user's location while the person has a compatible mobile device. Google uses the resulting data to infer information including places visited, activities and the paths taken between visits. Its Timeline feature displays a private map through Google Maps showing where a user has traveled. The service can save that map based on signed-in devices even when the user is not using a Google service.
Location Accuracy is different again. The Android operating system feature allows a device to determine its location more accurately than it could by relying solely on its GPS unit. It is available to Android users regardless of whether they have a Google Account.
Those matter because the DPC did not make identical findings about each feature. The lawfulness and fairness findings applied to Web & App Activity and Location History. The retention findings also concerned those two features. The accountability finding concerning Google's inability to demonstrate compliance applied to Location Accuracy. Transparency failures ran through all three.
The decision was made by Commissioners for Data Protection Des Hogan, Dale Sunderland and Niamh Sweeney. The DPC also acknowledged the cooperation and assistance of other European supervisory authorities involved in the case. For now, the announcement provides the findings and the size of the penalty, but not the regulator's complete reasoning. The DPC said it will publish the full decision in due course.
The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

