Feeds

France gives Google three month DATA PRIVACY DEADLINE

Liberté, egalité, intimité

High performance access to file storage

Data authorities have ruled that Google has breached the French Data Protection Act, and the huge advertising firm has been ordered to comply with the law within three months or else face sanctions.

Data watchdogs in the UK, Spain, Germany, Italy, and the Netherlands have also launched enforcement actions against Google today, France's Commission Nationale de l’Informatique et des Libertés (CNIL) said.

The French regulator was tasked by Brussels' Article 29 Working Party with investigating Google's controversial privacy policy changes in March 2012. In April this year it found that the ad giant had not implemented any "significant compliance measures."

In the UK, the Information Commissioner's Office is looking at whether Google's rejigged privacy policy is compliant with the Data Protection Act 1998.

The Brit watchdog will be firing off a letter to the company soon, the CNIL said. The ICO, which is led by Commissioner Christopher Graham - who is vice chair of the Article 29 Working Party - did not immediately respond to The Register's request for comment at time of writing.

Google was told in a formal notice from the CNIL that it has until September to implement the following changes to its service:

  • Define specified and explicit purposes to allow users to understand practically the processing of their personal data;
  • Inform users by application of the provisions of Article 32 of the French Data Protection Act, in particular with regard to the purposes pursued by the controller of the processing implemented;
  • Define retention periods for the personal data processed that do not exceed the period necessary for the purposes for which they are collected;
  • Not proceed, without legal basis, with the potentially unlimited combination of users’ data;
  • Fairly collect and process passive users’ data, in particular with regard to data collected using the 'Doubleclick' and 'Analytics' cookies, '+1' buttons or any other Google service available on the visited page;
  • Inform users and then obtain their consent in particular before storing cookies in their terminal.

Data protection authorities in some of the other countries mentioned by the CNIL are way ahead of the ICO.

In Spain, the DPA has opened a sanction procedure against Google for the infringement of key principles of the Spanish Data Protection law.

While Hamburg's Commissioner in Germany will shortly hold a formal hearing that may lead to the release of an administrative order demanding that Google implements measures which comply with the country's DP legislation.

The Dutch data protection regulator is set to issue a confidential report of a preliminary investigation and will ask Google to respond to its findings. Depending on the outcome of those discussions, the DPA could then issue sanctions.

The Italian data watchdog, meanwhile, is seeking clarification from Google after it opened a formal inquiry proceeding last month. It will shortly be looking at the findings of its probe, which could lead to possible enforcement measures that may include sanctions under the country's data protection law, the CNIL said.

Google, however, failed to see what all the fuss was about.

“Our privacy policy respects European law and allows us to create simpler, more effective services. We have engaged fully with the authorities involved throughout this process, and we’ll continue to do so going forward," the company told the Register. ®

Combat fraud and increase customer satisfaction

More from The Register

next story
Putin tells Snowden: Russia conducts no US-style mass surveillance
Gov't is too broke for that, Russian prez says
Record labels sue Pandora over vintage song royalties
Companies want payout on recordings made before 1972
Lavabit loses contempt of court appeal over protecting Snowden, customers
Judges rule complaints about government power are too little, too late
MtGox chief Karpelès refuses to come to US for g-men's grilling
Bitcoin baron says he needs another lawyer for FinCEN chat
Don't let no-hire pact suit witnesses call Steve Jobs a bullyboy, plead Apple and Google
'Irrelevant' character evidence should be excluded – lawyers
Judge halts spread of zombie Nortel patents to Texas in Google trial
Epic Rockstar patent war to be waged in California
EFF: Feds plan to put 52 MILLION FACES into recognition database
System would identify faces as part of biometrics collection
Edward Snowden on his Putin TV appearance: 'Why all the criticism?'
Denies Q&A cameo was meant to slam US, big-up Russia
Ex-Tony Blair adviser is new top boss at UK spy-hive GCHQ
Robert Hannigan to replace Sir Iain Lobban in the autumn
Reprieve for Weev: Court disowns AT&T hacker's conviction
Appeals court strikes down landmark sentence
prev story

Whitepapers

SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.