What happened

Ireland's Data Protection Commission has fined Google €403 million, about $463 million, over the way three of its features handled people's location data, and ordered the company to bring that processing into compliance within six months. The commission says its full decision will be published later.

The three features are Web & App Activity, Location History and Location Accuracy. Web & App Activity is an account setting that, when turned on, lets Google process data about activity across its sites and apps, and that data can include location. Location History is opt in and records where a signed in mobile device goes, including when the person is not using a Google service. Location Accuracy works out a device's position more precisely than GPS alone, and it is available with or without a Google account.

The inquiry covered the period from 25 May 2018 to 4 February 2020, and opened in February 2020 after complaints filed in November 2018 by BEUC, the European Consumer Organisation, and its member groups. The commission found breaches of the rules on lawful and fair processing and on transparency for Web & App Activity and Location History. For Location Accuracy it found an accountability failure, because Google could not demonstrate that the processing was lawful, fair and transparent. It also found transparency failures covering all three features, and retention of location data for longer than necessary.

Graham Doyle, deputy commissioner, said these failures meant people could have been unaware that their location was being used, for example to influence them with ads or to infer their interests, and could lose control of their personal data, with long retention aggravating that loss of control. Google said the case centres on historical policies that have since been updated, pointing to auto delete controls introduced in 2019 and a 2023 change keeping Timeline data on devices. At €403 million the fine is the fourth largest the commission has issued, and it cannot be collected until an Irish court confirms it. Google can appeal to the High Court within 28 days of formal notice.

Why this is a GRC story

Consent that is technically captured but not genuinely informed is the failure mode here, and it is a design question rather than a paperwork one. A regulator looking at this decides whether the choice was meaningful, whether the defaults were neutral, and how many separate settings a person had to find and understand before their location stopped being used.

The accountability finding deserves attention on its own. Google was faulted not only for the processing, but for being unable to demonstrate that it complied. Records of processing, the evidence behind a privacy notice, and a written rationale for a lawful basis are treated as controls in their own right. An undocumented justification is indistinguishable from no justification when a regulator asks for it.

Retention shows up as the aggravating factor, and it points at a simple control. Keeping location data longer than necessary turned separate weaknesses into a larger, older exposure, which is the argument for a defensible deletion schedule on location type data.

What to watch

Watch the appeal, since the fine is not payable until the Irish court confirms it, and watch whether the six month compliance order produces real product changes rather than a policy statement. Watch too whether other regulators adopt the same accountability reasoning, because that reasoning travels much further than one fine.

The useful exercise for a smaller organisation is unglamorous. Read your privacy notice next to what the systems actually do, and confirm every retention period you publish exists as a configured setting rather than an intention.

Attribution: Analysis based on The Hacker News and related public reporting. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News