Google fined €403 million in EU over mishandling of users’ location data

Edited By: Shalini Chandran
The Google logo is displayed on a building at Google headquarters in Mountain View, California | File photo: AFP
The Google logo is displayed on a building at Google headquarters in Mountain View, California | File photo: AFP

Dublin: Google has been fined €403 million (USD 463 million) by Ireland's Data Protection Commission (DPC) for breaching the European Union's strict privacy rules over the handling of users' location data.

The DPC said its investigation found that Google had not lawfully or fairly processed location data collected through its Web & App Activity and Location History settings.

Web & App Activity records users' browsing and search history, while Location History allows Google to map places users have visited with their mobile phones.

The regulator also found that Google had failed to process personal data lawfully, fairly and transparently through its Location Accuracy feature on the Android operating system.

Ireland acts as Google's lead data protection regulator in the 27-member EU because the company's European headquarters is based in Dublin.

The investigation was launched six years ago and examined Google's processing of personal data under the EU's General Data Protection Regulation (GDPR) between the regulation's introduction in 2018 and February 2020.

Google said the case concerned "historical policies" that had since been changed.

"From 2019 onwards, we've significantly evolved our practices and launched robust tools that make managing location data simple," the company said in a statement.

The DPC noted that location data is personal information that can be collected by Google and used to determine or infer a person's whereabouts.

"Location data can bring both benefits and harms to individuals," DPC Deputy Commissioner Graham Doyle said. He added that while such data can improve online services, it can also reveal significant information about individuals, including information that is inherently private.

The €403 million penalty is the fourth-largest EU privacy fine imposed by the Irish watchdog. The DPC has previously issued larger penalties against companies including TikTok and Meta, with Meta receiving a €1.2 billion fine.

The regulator said three other privacy investigations involving Google are still ongoing.