![]()
Google has been fined more than 400 million euro, around £345 million, after Ireland's Data Protection Commission found the company breached GDPR rules on how it handled users' location data. The fine affects anyone in the European Economic Area who used Google services during the period under investigation, and it is a reminder of how easily location tracking can be used without people fully realising it.
The DPC opened its inquiry into Google Ireland six years ago after complaints from several European consumer rights organisations about how the company processed location data. Investigators examined "web and app activity," "location history" and "location accuracy" settings between May 25, 2018 and February 4, 2020, looking at whether Google's processing was lawful, fair and properly accountable under GDPR. The regulator concluded that Google users could have been unaware their location was being used to target them with ads or to infer their interests. The 403 million euro penalty is the fourth largest the DPC has issued since GDPR took effect, and Google has been ordered to bring its data processing into compliance within six months.
How to spot it
- Location data collected through Google services can, alone or combined with other information, reveal where an individual has been.
- The DPC found this data could be used to influence users with targeted ads or to infer personal interests without users realising it.
- Retaining location data for longer than necessary made this loss of control worse, according to the regulator.
What to do if it happened to you
Google says the practices at issue were historical and have since been updated. From 2019 the company introduced tools allowing users to set their account to automatically delete location data on a rolling three, 18 or 36 month basis. Users can also turn off personalised ads entirely or manage how location data is used for advertising. Google "Timeline" data is now stored directly on the user's device rather than centrally, and the company says it no longer stores precise device location within Web & App Activity when searches are made, saving only an "estimated general area" instead. Deputy commissioner Graham Doyle said the GDPR requires personal data to be processed lawfully, fairly and transparently, and that Google's failures meant users could lose control over their own information. Three other large-scale inquiries into Google remain open and are described as being at an advanced stage.
As our consumer reporter often warns, it pays to check your privacy settings before a company's data habits catch up with you rather than after.
Source: The Independent