|
|
|
|
|
by asdfasgasdgasdg
1726 days ago
|
|
Is that true? From what I can find the total amount of their fines is not more than $100M, which is less than I would expect given their size if they were conducting willful ongoing violations. And neither of the two biggest cases involved willful data retention like this: one was about cookie consent and one was about right to be forgotten. |
|
However, several DPAs and local governments have reviewed Google software for their own GDPR compliance. Several of those findings are available online. These findings don't result in fines, because it's not technically an investigation of Google. But it does involve a thorough investigation of the legal issues of using Google's services, and the results are illuminating.
For example, below is a link to a report the Dutch DPA complied on whether Dutch government agencies can use Google Workspace (formerly GSuite). The conclusion is that Google's privacy protection are catastrophically terribad (for a paid product!). It requires linking to a personal account, purposes of processing are not defined, there's definitely processing going on that's not covered by the contract, etc. Google's linking to personal data in a way that cannot be disabled by administrators means they are a Joint Controller instead of a Processor, and it's not possible for them to comply with various obligations because they're too vague about the purposes of processing.
https://www.rijksoverheid.nl/binaries/rijksoverheid/document...
Again, doesn't result in a fine, because they're not be investigated for violations. Someone is just asking "can we use a Google product?" But the results of that research indicate some deep structural problems.
Also that fine that France issued, where they somehow avoided invoking GDPR directly? Still the third-largest GPDR fine on record. So your expectations for fine amounts are a bit off.
https://www.enforcementtracker.com