Key facts
- Google was fined €403 million by Ireland's data privacy authority.
- The fine was issued over Google's handling of user location data.
- The tech giant infringed the EU's General Data Protection Regulation on four counts.
- The issues concerned Google's Web & App Activity, Location History, and Location Accuracy functions.
- Consumer groups alleged Google used 'dark patterns' to obtain consent for location data sharing.
Ireland's data privacy authority fined Google €403 million for its handling of user location data, marking the fourth-largest penalty ever issued by the regulator. The decision concludes an inquiry initiated six years ago by the Irish Data Protection Commission (DPC) following complaints from consumer organizations across the EU, which alleged that Google processed people's location data without sufficient transparency or a valid legal basis.
Privacy commissioners determined that Google infringed the General Data Protection Regulation (GDPR) on four counts related to its Web & App Activity, Location History, and Location Accuracy functions. Consumer groups specifically alleged that Google employed "dark patterns" to encourage users to share their location data. The DPC ordered Google to bring its processing into compliance with GDPR within six months.
A Google spokesperson stated that the case pertains to historical policies that have since been updated. Consumer organizations called the decision good news but noted the disproportionate time taken to reach the conclusion.
