As part of a settlement with the US District of Columbia, Google has agreed to make a slate of changes to its location tracking practices and pay a fine of $9.5 million. The District of Columbia in January 2022 filed a lawsuit alleging that Google “deceived consumers regarding how their location is tracked and used by the company and [regarding their] ability to protect their privacy by stopping this tracking.”
We sued because Google made it nearly impossible for users to stop their location from being tracked. Now, thanks to this settlement, Google must also make clear to consumers how their location data is collected, stored, and used.
Read the agreement: https://t.co/D6TUaRNDGZ
— AG Karl A. Racine (@AGKarlRacine) December 30, 2022
This settlement is one of the many that Google has reached in recent weeks with regard to its location tracking practices. In November 2022, Google agreed to pay $392 million to settle a lawsuit brought by 40 states, and in December, Google agreed to pay the state of Indiana $20 million. At the heart of these lawsuits are two settings: Location History and Web & Activity. Google suggested to users that turning off the Location History would stop it from collecting users’ location information, but the company continued to collect this information through Web & Activity and other sources. To read more about the allegations, read our summary of the lawsuit.
Why does this matter: These multiple lawsuits against Google were prompted by an Associated Press story in 2018 that revealed the extent of Google’s location tracking practices, including tracking location when users had opted not to be tracked. The agreements reached to settle these lawsuits require Google to give users more genuine control over whether or not they want to share their location and also make clear how their location data is collected, stored, and used.
“Location data is a key part of Google’s digital advertising business. Google uses the personal and behavioral data it collects to build detailed user profiles and target ads on behalf of its advertising customers. Location data is among the most sensitive and valuable personal information Google collects. Even a limited amount of location data can expose a person’s identity and routines and can be used to infer personal details.” — Attorney General of Tennessee
FREE READ of the day by MediaNama: Click here to sign-up for our free-read of the day newsletter delivered daily before 9 AM in your inbox.
What changes must Google make?
- Pop-up and email notifications to users who already have Location History enabled: Google must show a pop-up notification and send an email to users who have Location History or Web & App Activity settings enabled, disclosing to them whether these settings allow Google to collect location information and also instructing them how to disable the setting, delete the data collected and set data retention limits. Location History is a setting that lets Google automatically capture a user’s location information at different points in time from various sources. This data can be presented in a visual format shown on a map.
- Disclosure when users enable any location-related account setting: When a user enables or is prompted to enable any location-related account setting, Google must clearly disclose to the user a hyperlink to the Location Technologies page as well as information related to the source of location information, the purpose for collection, the retention and deletion controls available to users, and whether the setting allows Google to collect location information even when a user is not using a specific Google service. When a user enables or is prompted to enable Location History, Google must disclose ways in which location information previously stored in Location History (that has been de-identified or anonymised) is used.
- Disclosures when users create an account: When a user creates an account with Google, the company must clearly and noticeably disclose information regarding the collection, retention, and use of location information, “including, but not limited to GPS, IP address, DEVICE sensor data, Wi-Fi data, and Bluetooth data, that the USER agrees to prior to creating an account.” Google must also show a hyperlink to the Location Technologies page and an additional dialogue that reveals to users which location-related settings are enabled by default and how to disable these settings. All the above disclosures must be presented in a way that the user cannot avoid.
- Disabling location-related settings or deleting location information should be easy: Google must give users the ability to disable a location-related account setting or delete location information “stored by that setting in a single, continuous flow, i.e., without needing to navigate to a separate surface or page.”
- Explicit consent required for sharing precise location information: A user’s precise location information (defined as the latitude and longitude of a user or device) can only be shared with a third-party advertiser with the express affirmative consent from the user.
- Auto deletion of certain location information: Google must automatically delete location information derived from a device or an IP address as part of Web & App Activity within 30 days of collection of such information.
- Deleting Location History of inactive users: Google must automatically delete Location History data for inactive users within 180 days of the user receiving an email notification regarding the same unless the user takes steps to keep their data. An inactive user is defined as a user whose location information was last uploaded more than three years ago.
- Privacy impact assessments of changes: Before materially changing how Location History or Web & App Activity use precise location information, Google must internally assess the privacy impact of that change. The same goes for if and when Google changes how it shares users’ precise location information with third parties. These assessments must be documented in writing within Google.
This post is released under a CC-BY-SA 4.0 license. Please feel free to republish on your site, with attribution and a link. Adaptation and rewriting, though allowed, should be true to the original.
- Deep Dive: Google Sued For Deceptively Collecting User Location Data And Using It For Targeted Ads
- Four-part series: Google Advertising Texas Antitrust Lawsuit
- How Google’s Location Tracking Led To A $42 Million Penalty In Australia
- How Location And Health Data Can Be Misused And What The US Government Is Doing To Protect Users