Ireland’s privacy watchdog today fined Google LLC €403 million, or about $462 million, for collecting users’ location data in breach of GDPR.
The tracking was done by three Google features: Web & App Activity, Timeline and GLA.
Web & App Activity is a Google account setting that collects user data when it’s enabled. The collected data includes, among others, the user’s location. Google relies on that information to personalize search results and ads. For example, it might display ads from stores near the user in a shopping-related search results page.
Timeline, the second feature that drew regulatory scrutiny, is provided by Google on an opt-in basis. When it’s enabled, the feature periodically logs the location of the user’s device. Timeline turns the data into a map that enables users to check the places they’ve visited and the routes they took.
Google collects location data with the help of an internal service called GLA, or Google Location Accuracy. The service is the third technology that was found to have breached GDPR.
GLA logs the location of the user’s Android device with the help of the built-in GPS module. If GPS data is unavailable, which is often the case indoors, the service can use location signals from the cellular or Wi-Fi network to which the device is connected.
Wireless networks can collect location data because signal strength decreases with distance. The weaker the signal, the farther away the user is from the nearest cell tower or Wi-Fi router. On its own, that signal strength data is often insufficient to accurately pinpoint a device’s whereabouts. Location services fill in the gaps using data points such as the unique MAC address of the user’s Wi-Fi router.
Ireland’s Data Protection Commission, or DPC, started probing Google’s location tracking practices in 2020. The investigation focused on the data that the company collected between May 25, 2018, the day GDPR went into effect, and Feb. 4, 2020. DPC officials issued today’s fine after determining that Google ran afoul of the regulation.
The search giant was found to have breached the lawfulness, fairness and transparency principle of GDPR. It’s a collection of clauses that requires tech firms to provide users with a detailed overview of the personal data they collect. Companies must also share related details such as how long they retain the data.
In addition to fining Google, the DPC today ordered the company to make its data collection practices GDPR-compliant within six months.
Google said in a statement that “this case centres around historical policies that have since been updated. From 2019 onwards, we’ve significantly evolved our practices and launched robust tools that make managing location data simple.”





