Ireland fines Google €403M over how it handled location data

Ireland's regulator says Google's location processing broke GDPR rules and orders a six-month fix.

CSBadmin
2 Min Read

Google has six months to rebuild how it handles location data in Europe after Ireland’s Data Protection Commission issued a €403M penalty, about $463M.

The regulator opened the file on its own initiative, not from a breach report, and examined practices between May 2018 and February 2020. Complaints from European consumer groups, BEUC among them, prompted the review.

Three findings stand out. Treatment of location data flowing through Location History and Web & App Activity broke rules on lawful and fair processing. Google’s records could not show accountability for those decisions. And data was kept past the point of need.

Deputy commissioner Graham Doyle said users could not have known their movements were shaping ad targeting and interest profiles, and that the retention stretched their loss of control.

Why consent design is the real target

Nothing here turns on a coding error. The exposure lives in product decisions: which signals are collected, how long they persist, and whether the permission a person grants matches what the backend does with the data.

That makes the template transferable. Any analytics or ad pipeline that infers location from app activity is handling personal data with a lawful-basis requirement, whether or not a maps app was ever opened.

Practical work is dull work. Inventory the systems taking in location signals, tie each to a documented basis, default retention to deletion, and test that the settings screen tells the truth.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.