NEWS

Google hit with €403 million fine for tracking location

Google was fined €403 million by Ireland's Data Protection Commission, known as the DPC. The decision came out on September 21.

Google hit with €403 million fine for tracking location
Image: Redação iMasters

Google was fined €403 million by Ireland's Data Protection Commission, known as the DPC. The decision came out on September 21. The case concerns the handling of location data from European users between May 2018 and February 2020.

Besides the fine, the authority set a deadline. The company has six months to bring its procedures in line with European legislation.

In a statement, the company disputed the focus of the decision. According to a spokesperson, the case concerns historical policies that have already been updated since 2019.

The three features that came under the regulator's scrutiny

The investigation focused its analysis on three features. Two of them operate on registered users' accounts.

However, the first one is Web & App Activity, which logs actions across services and pages. The second is Location History, responsible for storing routes and places visited.

The third tool stands out for its reach. Android's Location Accuracy combines network and cell tower signals to position the device with more detail than regular GPS. It also works even without an active account.

Google fell short on disclosure and also on retention

The DPC's findings point to two problems in the first two features. The company failed to provide clear information about the collection and kept records for longer than necessary.

As for Location Accuracy, the accusation is different. The company violated the accountability principle because it failed to demonstrate the legality, transparency and fairness of the process.

However, note this point. Proving compliance became a documentation obligation, not just language in a privacy policy.

Graham Doyle, deputy commissioner of the Irish authority, explained the severity. According to him, location data improves online services while at the same time revealing inherently private information about a person.

Doyle added an important detail. Users were left unaware that their movements were feeding interest profiles and ad targeting.

The case took more than six years to be resolved

The origin dates back to November 2018. At that time, consumer advocacy organizations from seven countries, coordinated by BEUC, filed formal complaints.

The technical basis came from a study by the Norwegian Consumer Council. However, the report pointed to misleading options on Android's settings screens, used to induce continuous tracking authorization.

The process formally began in February 2020. Therefore, more than six and a half years passed between the complaint and the decision.

Agustín Reyna, BEUC's director general, welcomed the outcome and criticized the delay. In his view, late enforcement of the law can be as harmful as no enforcement at all.

Google can still appeal, and the money may take a while

The amount represents the fourth-largest penalty ever imposed by the Irish regulator. The DPC acts as the lead authority because the company's European headquarters is based in Dublin.

The fine, however, depends on judicial confirmation. The company has 28 days to appeal to the country's High Court.

The collection figures explain the scenario. The authority has already imposed more than €4 billion in sanctions and collected around €20 million. The largest fines, against names like Meta and TikTok, remain under appeal.

What has changed in the products since the investigation

The company implemented adjustments over the years. In May 2019, automatic deletion after three or 18 months arrived.

Then, in June 2020, Sundar Pichai announced automatic 18-month deletion as the default for new accounts.

In December 2023, another significant change came. The Google Maps Timeline began storing data only on the device, with a default deletion period of three months for new users.

The Irish authority has yet to publish the full decision. In the meantime, it has avoided publicly saying whether these changes fully meet the requirements.

What product and engineering teams can take from this case

First, treat retention as an architecture decision. Deletion deadlines need to be in the code and in the database, with an automatic routine.

Second, document the legal basis for each data collection. Proving compliance requires records, not just text in the policy.

Third, review your consent screens. Defaults that push the user toward the most permissive option become evidence against the company.

Furthermore, separate account data from device data. The Android feature showed that collection without an account also counts.

Finally, keep only the minimum necessary. Data you avoid collecting requires no justification later.

What to watch in the coming months

Keep an eye on the publication of the full decision. It should bring useful details about the criteria applied.

Also follow the appeal at the Irish High Court. And watch whether other European authorities adopt the same understanding on accountability and proof of compliance.

Follow our profile on Instagram!

Translated from the Brazilian Portuguese original · Read the original

More from Redação iMasters
View profile →
Read also