Google has been fined 403 million euro (over Rs 4,000 crore) by Ireland’s Data Protection Commission (DPC) over how it handled users’ location data. The regulator found that Google broke the European Union’s General Data Protection Regulation (GDPR) between 2018 and 2020, reports Reuters. The case looked at three Google features: Web & App Activity, Location History and Location Accuracy. Google said the investigation focused on older policies and that it has since made major changes to how it handles location data.
The DPC is the main EU privacy regulator for many large technology companies. It opened the investigation in 2020 after complaints from several consumer rights groups, including the European consumer organisation BEUC.
Also read: OpenAI calls for global AI standards, warns about risks of recursive self-improvement
The regulator said Google’s practices did not always give users enough information about how their location data was being used. This included the use of location information through Web & App Activity and Location History.
Web & App Activity collects information about a user’s activity across Google services. Meanwhile, Location History records a user’s location using their mobile devices.
“As a result of Google’s failures, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data,” DPC Deputy Commissioner Graham Doyle was quoted as saying in the report.
Along with the fine, Google has been given six months to bring its location data processing in line with EU privacy rules. The DPC said it has three other statutory investigations into Google that are at an advanced stage.
Google said it has changed several of its practices since the period covered by the investigation. These changes include tools that let users automatically delete personal data and an option to store timeline data directly on their devices. The company also said users now have more control over how their data, including location information, is used for advertising.
“The fine was the fourth largest of the more than 4 billion euros in total levied by the DPC since it became the lead EU regulator for most big US tech firms under the strict 2018 GDPR due to the location of companies’ EU operations in Ireland,” the report claimed.
Also read: Google to share child abuse reports directly with Indian agencies: Here is why it matters