
The Irish regulator sanctions the American giant for the use of its users' geolocation data.
Google has been fined €403 million by the Irish data protection regulator for breaching the GDPR over the use of geolocation data.
AI-generated summary
The investigation began in February 2020 after complaints from European consumers regarding compliance with the GDPR.
The American giant Google was fined 403 million euros on Monday by the Irish data protection regulator for violating European rules (GDPR) on the use of its users' geolocation data.
This is the fourth largest fine ever imposed by the Irish Data Protection Commission (DPC), which supervises Google at the European level, because the group's European headquarters is in Dublin.
Geolocation data can “improve the usefulness of online services, but it can also reveal a significant amount of information about a person, including inherently private information,” noted Graham Doyle, Commissioner at the DPC, quoted in a press release.
“Due to Google’s failings,” users “could be unaware that their location was being used, for example, to influence them through advertisements or to infer their interests, and could lose control of their personal data,” he stressed.
The investigation, opened in February 2020 following complaints filed by several European consumer defense organizations, targets a period between 2018 and 2020.
It concerns compliance with the GDPR (European data protection regulation) of the “Web and application activity”, “Location history” and “Location accuracy” functionalities.
“This case concerns historical rules which have since been updated,” responded a Google spokesperson.
“Starting in 2019, we significantly evolved our practices and launched robust tools that simplify the management of location data,” he added.
Google is currently the subject of three other DPC investigations, “all at an advanced stage”, according to the organization.
The heaviest fine decided by the DPC affected Meta in 2023: 1.2 billion euros concerning the transfer of data to the United States, despite fears of surveillance at the time by American services.

British Prime Minister Andy Burnham announced Tuesday at the UN his intention to initiate the development of artificial intelligence security standards under the aegis of the G20 during the British presidency in 2027, despite opposition from the United States which sees it as a loss of sovereignty. He also discussed a US-UK partnership to use AI against cyberattacks targeting key infrastructure.

Anthropic has chosen consulting firm Accenture as an independent assessor of the security of its artificial intelligence models, marking a self-regulatory move in a largely deregulated sector.

Google revealed that its artificial intelligence carried out cyberattacks and guessed identifiers, affecting three different organizations, which it informed of the breaches without disclosing their names.

More than 20 countries called for restrictive security measures in the face of the rapid development of artificial intelligence, citing safety and security risks, at the UN General Assembly in New York, notably in reference to the Hugging Face data hack in July.

According to CNN, the US military considered boarding a Chinese ship in the Middle East after an AI generated a false intelligence report, before changing its mind. Furthermore, Meta is working on facial recognition glasses which are worrying regulators and the public.

The United States has proposed to China the creation of a dialogue mechanism on artificial intelligence, according to Treasury Secretary Scott Bessent, a few days before the summit between Donald Trump and Xi Jinping in Washington. This initiative aims to establish a common vision on the objectives and threats linked to AI, in a context of technological rivalry and trade tensions, particularly concerning rare earths and relations with Iran.