Urgent.News

What's breaking now, across thousands of outlets.

Business

Google is fined more than €400m by Irish regulator over its use of location data

Watchdog says users may have been unaware their information was used to target adverts or infer their interests Google has been fined more than €400m (£345m) over the way it processed users’ location data. The fine, by Ireland’s Data Protection Commission (DPC), comes after complaints from multiple European consumer organisations that Google was following every step users took. Continue reading...

Google is fined more than €400m by Irish regulator over its use of location data

The Irish Data Protection Commission (DPC) has imposed a fine of over €400 million on Google for its handling of users' location data. This substantial penalty comes after complaints from several European consumer groups who alleged that Google's use of location data was excessive and potentially breached users' privacy.

The DPC launched its investigation six years ago to determine if Google had a lawful basis for its use of location data. The regulator found that Google users may have been unaware that their location was being used to target ads or infer details about their interests and personal life. Graham Doyle, a deputy commissioner at the DPC, explained that location data can provide both benefits and potential privacy risks.

It can greatly enhance online services but can also reveal sensitive information about individuals, such as their religious beliefs, political leanings, health conditions, or sexual orientation.

The European Consumer Organisation based its complaint on research by the Norwegian consumer agency, which revealed that Google used various tactics to ensure location history and web and app activity were enabled. The DPC's inquiry examined Google's processing of web and app activity, location history, and location accuracy between May 2018 and February 2020.

In response to the fine, the DPC ordered Google to bring its processing practices into compliance with the EU's General Data Protection Regulation (GDPR) within six months. This is the fourth-largest fine imposed by the Irish regulator, which has EU-wide responsibility for tech giants with headquarters in Ireland. Previous fines have been handed to Meta (Facebook), TikTok, and Instagram (also owned by Meta).

Doyle emphasized that the GDPR aims to provide high-level protection for personal data across the European Economic Area (EEA) and requires that personal data must be processed lawfully, fairly, and transparently. Google's failure in these areas has left individuals unaware that their location data was being used to influence them with ads or infer their interests, potentially leading to a loss of control over their personal data.

The DPC stated that retaining users' location data for longer than necessary exacerbated this loss of control.

Written by urgent.news from Guardian Business's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 9 other outlets

Read the original at theguardian.com →

More in Business

More from Monday 21 September →