Google’s parent company Alphabet has been fined €403 million by Ireland’s Data Protection Commission (DPC) over its processing of users’ location data.
The DPC, which acts as Google’s lead data protection regulator in the European Union, said Monday that Google breached the bloc’s General Data Protection Regulation (GDPR) between 2018 and 2020 in its use of three features: Web & App Activity, Location History and Location Accuracy.
Ireland’s DPC has jurisdiction over many major US technology companies because their European operations are based in the country. Since the GDPR came into force, the regulator has imposed more than €4 billion in fines.
The penalty against Google is the DPC’s fourth-largest fine to date.
The regulator has also ordered Google to bring its data-processing practices into compliance with the GDPR within six months. Google did not immediately respond to a Reuters request for comment.
DPC Deputy Commissioner Graham Doyle said Google’s failures may have left users unaware that their location data could be used to target them with advertising or infer their interests, potentially reducing their control over their personal information.
He added that the issue was compounded by Google retaining location data for longer than necessary.
The DPC launched its investigation in 2020 following complaints from several European consumer organisations, including the pan-European consumer group BEUC, concerning Google’s use of location data.
The complaints questioned the lawfulness and fairness of Google’s processing of location data under its Web & App Activity account setting, which collects information about users’ activity across various Google services.
The investigation also covered Google’s Location History and related data-processing practices.