The Ireland Data Protection Commission (DPC) has imposed a €403 million ($463 million) penalty on Google for violating European Union privacy regulations concerning the handling of user location data. Under the terms of the ruling, the technology giant must bring its location data processing practices into compliance with the General Data Protection Regulation (GDPR) within six months.
The regulatory action stems from an inquiry launched in 2020 after consumer advocacy groups filed complaints regarding Google’s data practices between May 2018 and February 2020. The DPC examined three specific features: Web & App Activity, which tracks user interactions across various services; Location History, an opt-in tool that records a timeline of a user’s movements; and Location Accuracy, a feature that enhances device pinpointing beyond standard GPS capabilities.
According to the regulator, Google failed to process location data fairly or lawfully within the Web & App Activity and Location History features. The DPC also determined that the company did not demonstrate compliance with the GDPR’s requirements for lawfulness, fairness, and transparency regarding the Location Accuracy feature. Furthermore, the investigation found that Google breached transparency obligations and retention rules across all three features.
In response to the fine, Google stated that the penalties relate to historical policies that have since been revised. A spokesperson told the Associated Press that the company has significantly evolved its practices since 2019 and introduced new tools designed to simplify how users manage their location information.
This处罚 adds to a growing list of legal challenges Google faces in Europe. Earlier this year, the company lost its final appeal against a $4.7 billion antitrust fine related to its Android operating system, originally imposed in 2018. Additionally, the European Commission fined Google $1 billion in July for prioritizing its own services in search results, a decision that prompted Google to agree to changes in its European search algorithm.
The DPC revealed that three other large-scale statutory inquiries into Google are currently at an advanced stage. This latest enforcement action represents the fourth-largest fine issued by the commission since the GDPR became effective. The largest penalty to date was a $1.3 billion fine levied against Meta for transferring EU citizens’ Facebook data to servers in the United States.
Three other inquiries still pending is concerning. How many more will it take before they actually respect EU privacy laws?
€403 million is pocket change for Google. They are just treating these fines as operational costs, not actual punishments.
Six months to fix this? Bold of them to think a fine changes overnight. Transparency was clearly never the goal here.