Google Fined €403 Million Over EU Location Data Violations

Google has been fined €403 million by Ireland's Data Protection Commission (DPC) for violating the European Union's General Data Protection Regulation (GDPR) in the way three of its features processed users' location data between May 2018 and February 2020.

The DPC, which serves as Google's lead data protection regulator in the European Union, has also ordered the company to bring the affected data processing practices into compliance with GDPR requirements within six months. The regulator has not yet publicly disclosed which specific processing activities are covered by the order and said its full decision will be published at a later date.

The three Google features examined by the DPC are Web & App Activity, Location History, and Location Accuracy.

Web & App Activity is a Google account setting that allows Google to process information about a user's activity across its websites and applications when enabled. This information can include location data.

Location History is an optional feature that records where users travel with signed-in mobile devices, including periods when they are not actively using a Google service.

For both Web & App Activity and Location History, the DPC found that Google violated GDPR requirements concerning lawful and fair processing, transparency, and data retention.

According to the regulator, Google retained certain location data for longer than was necessary.

The third feature, Location Accuracy, is an Android functionality designed to determine a device's location more precisely than GPS alone. Unlike some Google account features, Location Accuracy can be used by Android users regardless of whether they have a Google account.

The DPC's findings regarding Location Accuracy were narrower. The regulator determined that Google breached GDPR transparency and accountability requirements because it could not demonstrate that the relevant processing was lawful, fair, and transparent.

DPC Deputy Commissioner Graham Doyle said the failures could have left users unaware that their location information was being processed for purposes such as influencing advertising or inferring users' interests.

The regulator also said the practices could reduce users' control over their personal information, with lengthy data retention making the situation more significant.

Fourth-Largest Fine Issued by the DPC

The €403 million penalty is the fourth-largest fine issued by Ireland's Data Protection Commission.

However, Google does not have to pay the fine immediately. Under the applicable process, a DPC penalty becomes payable only after it is confirmed by an Irish court.

Google can appeal the decision to Ireland's High Court within 28 days of receiving formal notification of the decision.

Google said the case concerns historical policies that have since been changed and stated that its practices have evolved significantly since 2019.

During the period examined by the DPC, Google introduced several changes to its location data controls.

In May 2019, Google introduced automatic deletion controls for Location History and Web & App Activity. These controls allowed users to automatically delete stored information after three or 18 months.

In June 2020, Google made 18-month automatic deletion the default for Web & App Activity on new accounts and for users activating Location History for the first time.

Google later introduced additional changes to its Location History system.

In December 2023, the company announced that Google Maps Timeline data would increasingly be stored directly on users' devices. Google also announced that automatic deletion would default to three months for users activating Location History for the first time.

The DPC has not publicly confirmed whether these later changes are sufficient to satisfy the requirements of its latest order.

Investigation Began in 2020

The DPC opened its investigation in February 2020 following complaints submitted by European consumer organizations, including BEUC, the European Consumer Organisation.

BEUC's member organizations originally submitted complaints to national data protection authorities in November 2018, raising concerns about Google's location tracking and related data processing practices.

The period examined by the DPC ended on February 4, 2020, the same day the regulator announced that it had opened its inquiry.

The investigation took more than six and a half years to reach a decision.

BEUC Director General Agustín Reyna welcomed the enforcement action but criticized the length of the investigation, arguing that delayed enforcement can reduce the effectiveness of data protection rules.

The case highlights the continuing regulatory scrutiny faced by major technology companies over the collection, use, transparency, and retention of users' location data under European privacy law.