Google Privacy : Latest Enforcement Action

June 19, 2013

On 20 June, the CNIL, the French data protection authority, released details of its latest action against Google over perceived breaches of EU data protection and privacy law.

From February to October 2012, the Article 29 Working Party investigated Google’s privacy policy with the aim of checking whether it met the requirements of the European data protection legislation. On the basis of its findings, published on 16 October 2012, the Working Party asked Google to implement its recommendations within four months.

That period has expired, and the CNIL reports that Google has not implemented any significant compliance measures.

Following new exchanges between Google and a taskforce led by the CNIL, the data protection authorities from France, Germany, Italy, the Netherlands, Spain and the UK have respectively launched enforcement actions against Google. The investigation led by the CNIL has confirmed Google’s breaches of the French Data Protection Act of 6 January 1978, as amended. The CNIL claim is that the Google policy, in practice, prevents individuals from knowing how their personal data may be used and from controlling such use.

According to a press relase from the CNIL (which may have lost a little in translation), the CNIL’s Chair has decided to give formal notice to Google Inc, requiring that, within three months, Google acts to:

·        define specified and explicit purposes to allow users to understand practically the processing of their personal data;

·        inform users by application of the provisions of Article 32 of the French Data Protection Act, in particular with regard to the purposes pursued by the controller of the processing implemented;

·        define retention periods for the personal data processed that do not exceed the period necessary for the purposes for which they are collected;

·        not proceed, without legal basis, with the potentially unlimited combination of users’ data;

·        fairly collect and process passive users’ data, in particular with regard to data collected using the ‘Doubleclick’ and ‘Analytics’ cookies, ‘+1’ buttons or any other Google service available on the visited page;

·        inform users and then obtain their consent in particular before storing cookies in their terminal.

This formal notice does not, says the press release, aim to substitute for Google defining the concrete measures to be implemented, but rather aims to make it reach compliance with the legal principles, without hindering either its business model or its ability to innovate.

If Google Inc. does not comply with this formal notice at the end of the given time-limit, CNIL’s Select Committee (formation restreinte), in charge of sanctioning breaches to the French Data Protection Act, may issue a sanction against the company.

The Data Protection Authorities from Germany, Italy, the Netherlands, Spain and the UK are carrying on their investigations under their respective national procedures and as part of an international administrative cooperation.

The CNIL reports as follows:

·        The Spanish DPA issued Google with a decision to open a sanction procedure for the infringement of key principles of the Spanish Data Protection Law on 20 June.

·        The UK Information Commissioner’s Office is considering whether Google’s updated privacy policy is compliant with the Data Protection Act 1998. ICO will shortly be writing to Google to confirm their preliminary findings.

·        The Data Protection Commissioner of Hamburg has opened a formal procedure against the company. It starts with a formal hearing as required by public administrative law, which may lead to the release of an administrative order requiring Google to implement measures in order to comply with German national data protection legislation.

·        As part of the investigation, the Dutch DPA will first issue a confidential report of preliminary findings, and ask Google to provide its view on the report. The Dutch DPA will use this view in its definite report of findings, after which it may decide to impose a sanction.

·        The Italian Data Protection Authority is awaiting additional clarification from Google Inc. after opening a formal inquiry proceeding at the end of May and will shortly assess the relevant findings to establish possible enforcement measures, including possible sanctions, under the Italian data protection law.