Story image

Expert comment: Google fined US$57mil for GDPR breaches

22 Jan 2019

EU’s data privacy regulation, the General Data Protection Regulation (GDPR), has drawn first blood to the tune of €50mil.

French data privacy agency, the National Data Protection Commission (CNIL), has imposed the fine against Google for “lack of transparency, inadequate information, and lack of valid consent regarding ad personalisation”.

The committee examining the breaches found two types of breaches of the GDPR – a violation of the obligations of transparency and information and a violation of the obligation to have a legal basis for ads personalisation processing.

Violation of the obligations of transparency and information

The committee found that

  • The information provided by Google is not easily accessible for users  
  • Essential information (data processing purposes, data storage periods, categories of personal data used for ad personalisation) is disseminated across several documents and complicated to obtain    
  • Some information is not always clear nor comprehensive  
  • It is difficult for the user to fully understand the extent of the processing operations carried out by Google across its multitude of services and the way the data is processed and combined

Violation of the obligation to have a legal basis for ads personalisation processing

The committee found that

  • Google obtains a user’s consent to processing data for ad personalisation, but the consent is not validly obtained for two reasons

  • The first being that the users’ consent is not sufficiently informed, with the information being fragmented and not enabling users to be aware of their extent.

  • The collected consent is neither “specific” or “unambiguous” as required by the GDPR.

Experts say this is a clear signal that regulators will be enforcing the GDPR regulations and compliance is mandatory.

Proofpoint cybersecurity strategy SVP Ryan Kalember says, “This GDPR fine brings to light some vital lessons for other businesses observing this crisis from a distance.

“By becoming the highest-fined company since GDPR came into force, Google is now the black-and-white case study of ‘what could happen’ in the event of non-compliance.

“In a privacy-first world, companies must build a people-centric compliance strategy, which can only start by getting visibility into highly regulated data, the systems that process that data and identifying who within your business has access to that data.

“Many organisations are still unsure whether their GDPR compliance strategy is 100 percent fit for purpose, but this incident signals that long gone are the days where privacy can be relegated to an IT or compliance effort: the magnitude of this fine clearly shows this is a business issue.

“Compliance professionals now have a use case to take to the board to secure any funding and resources they need to become GDPR compliant if their organisation isn’t today.”

Varonis sales engineering director Matt Lock says, “The new fine facing Google will quickly dispel any lingering doubts that the EU would go easy on companies found in violation of the GDPR.

“The news should be hitting companies like a cold shower. It’s not a stretch to say that a proverbial storm is gathering as privacy groups rally to their cause and seek to uphold major global companies as examples of lax privacy controls.

“The news should serve as an impetus to organisations that have yet to prioritise their GDPR compliance programmes and hoped to simply fly under the radar– their luck may be running out soon.”

Gartner recognizes Huawei's data center networking expertise
The Gartner Peer Insights Customers’ Choice analyzes more than 200,000 reviews across more than 300 markets posted to Gartner Peer Insights. 
How Huawei aims to enhance IP networks
'We believe that the intelligent IP networks built with the four-engine series products can continuously empower users with business intelligence."
Partnership brings next-gen edge internet services to Chicago
The edge solutions will primarily be delivered through New Continuum’s West Chicago NAP data center, which is also a convergence point for optical and logical networks.
Earth Day 2019: How tech firms can support our planet's wellbeing
Six industry experts explain how they - and other tech organisations - can positively contribute to the wellbeing of our earth.
University of Kansas becomes lead agency for Kansas State Data Center program
The University of Kansas’ Institute for Policy and Social Research (IPSR) is now the lead agency for Kansas' State Data Center Program.
Dell EMC’s six server market trends
As the evolution of cloud-based computing continues, it is important to know what’s ahead to stay ahead of the market.
Park Place Technologies hires new EMEA managing director
Post-warranty data centre maintenance company Park Place Technologies has recruited Sean Sears as its new managing director for Europe, the Middle East and Africa.
Huawei FusionServer Pro built for 'intelligent transformation'
The next generation X86 servers draw on an intelligent acceleration engine, an intelligent management ending, and intelligent data center solutions for ‘diverse’ scenarios as transformation shifts from digital to intelligent.