Germany orders Google to stop illegal user data processing

Google has refused to substantially improve user controls, the government says

As part of an EU-wide crackdown on Google's data collection practices, Germany has ordered the company to change its user data processing, which is in violation of the country's laws.

Google violates the German Federal Telemedia Act and the Federal Data Protection Act when it collects and combines user data, the Hamburg Commissioner of Data Protection and Freedom of Information (HmbBfDI) said Tuesday. "According to the view of the data protection authority the ongoing practice of user profiling affects the privacy of Google users far beyond the admissible degree," it said.

Google was ordered to take the necessary technical and organizational measures to guarantee its users can decide on their own if, and to what extent, their data is used for profiling.

The German order follows fines imposed on Google by several European data protection authorities which found Google's 2012 changes to its privacy policy breached EU rules.

In various meetings with the authority, "Google has not been willing to abide to the legally binding rules and refused to substantially improve the users controls," said Hamburg Data Protection Commissioner Johannes Caspar. "So we had to compel Google to do so by an administrative order." The order was issued last week.

A Google spokesman said the company had engaged fully with the Hamburg Data Protection Authority throughout the process to explain its privacy policy and how it allows Google to create simpler, more effective services. "Were now studying their order to determine next steps," he said.

According to the authority, Google can, for instance, compile detailed travel profiles by evaluating user location data. It can also detect specific interests and preferences by evaluating search engine use and infer a user's financial status. Moreover, Google can also infer a user's whereabouts and other habits, as well as relationships, sexual orientation and relationship status, the authority said.

Google uses this information to build "meaningful and nearly comprehensive personal records," with no justification in either German or European law for such extensive profiling, it said.

The German decision also follows privacy recommendations from the Article 29 Working Party, an umbrella group for European data protection authorities. They suggested Google should personalize its privacy policy for each user and make it easier to find and understand in order to comply with EU law.

Loek is Amsterdam Correspondent and covers online privacy, intellectual property, open-source and online payment issues for the IDG News Service. Follow him on Twitter at @loekessers or email tips and comments to loek_essers@idg.com

Related:
ITWorld DealPost: The best in tech deals and discounts.
Shop Tech Products at Amazon