The DPC examined three Google features active between May 2018 and February 2020: Web & App Activity, Location History, and Location Accuracy. It found that Google processed location data through Web & App Activity and Location History without meeting GDPR requirements, and failed to demonstrate compliance when processing data through Location Accuracy.
"Individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data," said Deputy Commissioner Graham Doyle. "The retention of users' location data for longer than necessary aggravated this loss of control."
The regulator alleges Google failed to meet transparency obligations for all three features and retained location data from Web & App Activity and Location History longer than necessary. The DPC has ordered Google to bring its processing into compliance within six months.
In a statement to BleepingComputer, a Google spokesperson said the case "centers around historical policies that have since been updated." The company noted it has added tools letting users set automatic deletion timelines for location data, and that Google Maps Timeline information is now stored on devices with data automatically removed after three months. Google also said it does not save precise device location in Web & App Activity, only an estimated general area.
The DPC has not yet published its full decision but said it will do so in the future.