Feeds

France gives Google three month DATA PRIVACY DEADLINE

Liberté, egalité, intimité

Choosing a cloud hosting partner with confidence

Data authorities have ruled that Google has breached the French Data Protection Act, and the huge advertising firm has been ordered to comply with the law within three months or else face sanctions.

Data watchdogs in the UK, Spain, Germany, Italy, and the Netherlands have also launched enforcement actions against Google today, France's Commission Nationale de l’Informatique et des Libertés (CNIL) said.

The French regulator was tasked by Brussels' Article 29 Working Party with investigating Google's controversial privacy policy changes in March 2012. In April this year it found that the ad giant had not implemented any "significant compliance measures."

In the UK, the Information Commissioner's Office is looking at whether Google's rejigged privacy policy is compliant with the Data Protection Act 1998.

The Brit watchdog will be firing off a letter to the company soon, the CNIL said. The ICO, which is led by Commissioner Christopher Graham - who is vice chair of the Article 29 Working Party - did not immediately respond to The Register's request for comment at time of writing.

Google was told in a formal notice from the CNIL that it has until September to implement the following changes to its service:

  • Define specified and explicit purposes to allow users to understand practically the processing of their personal data;
  • Inform users by application of the provisions of Article 32 of the French Data Protection Act, in particular with regard to the purposes pursued by the controller of the processing implemented;
  • Define retention periods for the personal data processed that do not exceed the period necessary for the purposes for which they are collected;
  • Not proceed, without legal basis, with the potentially unlimited combination of users’ data;
  • Fairly collect and process passive users’ data, in particular with regard to data collected using the 'Doubleclick' and 'Analytics' cookies, '+1' buttons or any other Google service available on the visited page;
  • Inform users and then obtain their consent in particular before storing cookies in their terminal.

Data protection authorities in some of the other countries mentioned by the CNIL are way ahead of the ICO.

In Spain, the DPA has opened a sanction procedure against Google for the infringement of key principles of the Spanish Data Protection law.

While Hamburg's Commissioner in Germany will shortly hold a formal hearing that may lead to the release of an administrative order demanding that Google implements measures which comply with the country's DP legislation.

The Dutch data protection regulator is set to issue a confidential report of a preliminary investigation and will ask Google to respond to its findings. Depending on the outcome of those discussions, the DPA could then issue sanctions.

The Italian data watchdog, meanwhile, is seeking clarification from Google after it opened a formal inquiry proceeding last month. It will shortly be looking at the findings of its probe, which could lead to possible enforcement measures that may include sanctions under the country's data protection law, the CNIL said.

Google, however, failed to see what all the fuss was about.

“Our privacy policy respects European law and allows us to create simpler, more effective services. We have engaged fully with the authorities involved throughout this process, and we’ll continue to do so going forward," the company told the Register. ®

Security for virtualized datacentres

More from The Register

next story
The 'fun-nification' of computer education – good idea?
Compulsory code schools, luvvies love it, but what about Maths and Physics?
Ex-US Navy fighter pilot MIT prof: Drones beat humans - I should know
'Missy' Cummings on UAVs, smartcars and dying from boredom
Facebook, Apple: LADIES! Why not FREEZE your EGGS? It's on the company!
No biological clockwatching when you work in Silicon Valley
Happiness economics is bollocks. Oh, UK.gov just adopted it? Er ...
Opportunity doesn't knock; it costs us instead
'Cowardly, venomous trolls' threatened with TWO-YEAR sentences for menacing posts
UK government: 'Taking a stand against a baying cyber-mob'
Sysadmin with EBOLA? Gartner's issued advice to debug your biz
Start hoarding cleaning supplies, analyst firm says, and assume your team will scatter
Doctor Who's Flatline: Cool monsters, yes, but utterly limp subplots
We know what the Doctor does, stop going on about it already
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.