The Data Protection Commission (DPC) has fined Google Ireland € 403 million (US$ 460 million) following an inquiry into the company’s processing of users’ location data between May 2018 and February 2020. The DPC found that Google breached Europe’s stringent General Data Protection Regulation (GDPR) in relation to the lawfulness and fairness of its processing of location data through Web & App Activity and Location History.
According to a press release, the DPC also found that Google failed to meet its accountability obligations concerning Location Accuracy because it could not demonstrate compliance with the GDPR’s requirements for lawful, fair and transparent processing.
The inquiry was opened in February 2020 after complaints from several European consumer rights organisations, including Bureau Européen des Unions de Consumers (BEUC). The DPC examined Google’s processing of location data through three features which are Web & App Activity, Location History and Location Accuracy.
“Location data can bring both benefits and harms to individuals. It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private,” said Graham Doyle, Deputy Commissioner. “The GDPR provides a high level of protection of personal data throughout the EEA, and requires that the processing of personal data must be carried out in a lawful, fair and transparent manner. As a result of Google’s failures in this regard, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data. The retention of users’ location data for longer than necessary aggravated this loss of control”.
The regulator found further breaches of Google’s transparency obligations covering all three features, as well as breaches concerning the retention of location data through Web & App Activity and Location History.
Web & App Activity is a Google account setting that records information about activity on Google services, websites and apps. Depending on the settings, this can include browsing history, search history and location data. Location History records users’ locations from compatible mobile devices after users opt in. The data can be used to infer information such as places visited, activities and routes. The feature also provides a Timeline through Google Maps showing a private map of a user’s movements. Location Accuracy is an Android feature that uses information from sources including GPS to determine a device’s location more accurately. It is available to Android users regardless of whether they have a Google Account.
In addition to the € 403 million in administrative fines, the DPC has ordered Google to bring its processing into compliance with the GDPR within six months.
The General Data Protection Regulation (GDPR) is a European Union privacy and data protection law that applies to organisations that process the personal data of people in the EU and European Economic Area, subject to its territorial scope. It took effect on May 25, 2018, and allows data protection authorities to impose significant administrative fines for breaches of its requirements. The maximum fines can reach € 20 million (US$ 23 million) or 4 percent of an organisation’s total worldwide annual turnover for the preceding financial year, whichever is higher.
The decision was made by Data Protection Commissioners Des Hogan, Dale Sunderland and Niamh Sweeney. Other European data protection authorities provided cooperation and assistance during the inquiry and the full decision will be published by the DPC at a later date.

