Ireland’s Data Protection Commission (DPC) has fined Google Ireland €403 million after concluding an inquiry into Google’s processing of location data between 25 May 2018 and 4 February 2020. Acting as lead supervisor following complaints from several European consumer groups including BEUC, the DPC found multiple GDPR breaches: unlawful and unfair processing in Web & App Activity and Location History; failures of accountability for Location Accuracy; transparency shortcomings across all three features; and excessive retention of location data in Web & App Activity and Location History. Commissioners Des Hogan, Dale Sunderland and Niamh Sweeney adopted the decision and ordered Google to bring processing into compliance within six months.
The decision highlights that location data can reveal highly sensitive personal information and that users could have been unaware their movements were used to target ads or infer interests, with prolonged retention worsening loss of control. Web & App Activity is an account setting that collects activity across Google services (including location when enabled); Location History is an opt‑in service that builds a Timeline and stores maps of users’ movements even when services aren’t actively used; and Location Accuracy improves Android positioning for all devices regardless of account status. The DPC thanked other EU supervisory authorities for cooperation and will publish the full decision in due course.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.