Ireland’s data protection commission has fined Google €403 million (£346m) for breaching GDPR regulations over its processing of users’ location data.
The DPC said its investigation found Google did not lawfully or fairly process location data in its Web & App Activity setting, which tracks browsing and search history, nor in Location History, which maps places users have carried their mobile phone.
The regulator also found Google failed to be lawful, fair and transparent in the processing of personal data in the Location Accuracy feature in Android devices.
The investigation began six years ago, and covers the period from 25 May 2018, when the GDPR took effect, and 4 February 2020.
Location data can “reveal a significant amount of information about an individual, including information that is inherently private”, said DPC deputy commissioner Graham Doyle.
He said as a result of Google’s failures, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data.
The retention of users’ location data for longer than necessary aggravated this loss of control,” he added.
In addition to the fine, the DPC ordered Google to come into compliance in six months.
Google said that since 2019 it has launched tools for managing location data and now allows users to automatically delete their data and to turn off personalised adverts.
It said it also now offers “consolidated detailed information about our location data practices and account settings”.
The fine is one of Ireland’s largest under the GDPR. The regulator said it has three other ongoing privacy investigations ongoing involving Google.