Home » Google hit with £345m GDPR fine over secret use of customers’ location data

Google hit with £345m GDPR fine over secret use of customers’ location data

by Simon Jones Tech Reporter
21st Sep 26 11:03 am

Google has been fined €403mn (£345mn) by Ireland’s data protection regulator over breaches of European privacy rules relating to the processing of users’ location data, in one of the largest penalties imposed by the authority since the EU’s General Data Protection Regulation came into force.

The Data Protection Commission launched its investigation six years ago following complaints from several European consumer rights organisations about how Google Ireland processed location information.

The inquiry examined whether the company’s handling of location data was lawful and fair, as well as whether Google had met its accountability obligations under GDPR.

The regulator found that users could have been unaware that information about their location was being used to influence them through advertising or to infer their interests.

The investigation covered Google’s “web and app activity”, “location history” and “location accuracy” services between May 25 2018 and February 4 2020.

Alongside the €403mn administrative fine, the DPC ordered Google to bring its processing of location data into compliance with GDPR within six months. The penalty is the fourth largest fine issued by the Irish regulator since the legislation took effect.

Graham Doyle, deputy commissioner at the DPC, said: “Location data is a type of personal data which is processed by way of location tracking, and includes data collected or processed by Google, which by itself or in conjunction with other information an individual’s location can be inferred.

“Location data can bring both benefits and harms to individuals.

“It can greatly enhance the utility of online services, but it can also reveal a significant amount of information about an individual, including information that is inherently private.”

Doyle said GDPR required personal data processing across the European Economic Area to be “lawful, fair and transparent”.

He added: “As a result of Google’s failures in this regard, individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data.

“The retention of users’ location data for longer than necessary aggravated this loss of control.”

Google said the case concerned historical practices that had since been changed.

A spokesperson said: “This case centres around historical policies that have since been updated.

“From 2019 onwards, we’ve significantly evolved our practices and launched robust tools that make managing location data simple.”

The company said users could now configure their accounts to automatically delete data on a rolling three-, 18- or 36-month basis, while new controls allow personalised advertising to be switched off and give users greater control over how location data is used for advertising.

Google’s “Timeline” location data is now stored directly on users’ devices. The company also said it no longer stores precise device location in Web & App Activity when searches are made, instead retaining an “estimated general area”.

The ruling comes as the DPC continues three other large-scale statutory investigations involving Google, all of which are at an advanced stage, potentially exposing the technology group to further regulatory scrutiny in Europe.

Jamie Akhtar, CEO and Co-founder of CyberSmart: “During a cybersecurity evaluation, Google’s Gemini model was mistakenly given internet access when it should have been confined to a closed testing environment. Believing that real systems formed part of the exercise, it accessed three companies by guessing a password and using credentials exposed in public repositories. Gemini reportedly stopped after recognising that the targets were genuine, and Google says no harm was caused, but the incident demonstrates how quickly a capable AI agent can move beyond its intended boundaries when technical safeguards fail.

The fault here does not lie with the AI itself, but with the companies responsible for how it is deployed, tested and secured. Organisations cannot give advanced systems broad permissions and then blame the technology when safeguards fail.

Organisations testing or deploying autonomous AI must treat these agents like highly privileged users. Test environments should be isolated by default, outbound connections restricted to approved destinations, and consequential actions protected by human authorisation, least-privilege access and an immediate kill switch. More broadly, businesses should enforce multi-factor authentication, eliminate default or reused passwords, scan public code repositories for exposed secrets, rotate compromised credentials and monitor continuously for unusual automated activity.”

Nathan Davies-Webb, Principal Consultant, Acumen Cyber; “I think there’s a nuanced difference between this and some of the other breaches we’ve seen. Others have seemed complex in nature, but this breach is essentially brute force. Where this is simpler to achieve, I think it promotes the ethical concerns even more because this isn’t the development of some abstract machine behaviour. It’s a pretty simple technique and one where, unlike developing a technical exploit, you can’t actually predict the effectiveness of how many passwords you have to guess before you gain entry – and it was apparently okay with that. I think these recent compromises are reflective of a wider AI problem; nobody has actually decided who is accountable when it goes wrong. As we evidently can’t seem to have worked this out, legislation will have to do so on our behalf.”

Leave a Comment

You may also like

CLOSE AD