Privacy

Google fined $40M+ for misleading location-tracking settings on Android

Comment

Image Credits: Leon Neal / Getty Images

Google has been sanctioned A$60 million (around $40 million+) in Australia over Android settings it had applied, dating back around five years, which were found — in a 2021 court ruling — to have mislead consumers about its location data collection.

Australia’s Competition & Consumer Commission (ACCC) instigated proceedings against Google and its Australia subsidiary back in October 2019, going on to take the tech giant to court for making misleading representations to consumers about the collection and use of their personal location data on Android phones, between January 2017 and December 2018.

In April 2021 the court found Google had breached Australia’s Consumer Law when it represented to some Android users that the “Location History” setting was the only Google account setting affecting whether it collected, kept and used personally identifiable data about their location.

In actuality, another setting — called ‘Web & App Activity’ — also enabled Google to grab Android users’ location data and this was turned on by default, as the ACCC noted in a press release today. Aka, a classic dark pattern. (Actually Google deployed nested dark patterns, plural, as we detail below.)

Google misled consumers over location data settings, Australia court finds

The regulator estimates that users of around 1.3 million Google accounts in Australia may have viewed a screen found by the Court to have breached the Consumer Law.

“This significant penalty imposed by the Court today sends a strong message to digital platforms and other businesses, large and small, that they must not mislead consumers about how their data is being collected and used,” said ACCC chair, Gina Cass-Gottlieb, in a statement.

“Google, one of the world’s largest companies, was able to keep the location data collected through the ‘Web & App Activity’ setting and that retained data could be used by Google to target ads to some consumers, even if those consumers had the ‘Location History’ setting turned off.”

“Personal location data is sensitive and important to some consumers, and some of the users who saw the representations may have made different choices about the collection, storage and use of their location data if the misleading representations had not been made by Google,” she added.

Per the ACCC, Google took steps to correct the contravening conduct by 20 December 2018, meaning consumers in the country were no longer shown the misleading screens.

At the time of the court ruling last year, Google said it disagreed with the findings and that it was considering an appeal. But, in the event, it decided to take the lumps.

(These are not as painful as they might have been if the infringements had occurred more recently: The ACCC notes that the majority of the sanctioned conduct occurred prior to September 2018 which is before the maximum penalty for breaches of the Consumer Law was substantially increased — from $1.1 million per breach to — since then — the higher of $10 million, 3x the value of any benefit obtained or, if the value cannot be determined, 10% of turnover.)

The Court has also ordered Google to ensure its policies include a commitment to compliance, and requirements that it train certain staff about the country’s Consumer Law, as well as to pay a contribution to the ACCC’s costs.

Google was contacted for comment on the sanction. A company spokesperson sent us this statement:

We can confirm that we’ve agreed to settle the matter concerning historical conduct from 2017-2018. We’ve invested heavily in making location information simple to manage and easy to understand with industry-first tools like auto-delete controls, while significantly minimising the amount of data stored. As we’ve demonstrated, we’re committed to making ongoing updates that give users control and transparency, while providing the most helpful products possible.

Dark patterns inside dark patterns

The ACCC’s press release includes some screengrabs showing Google notifications to Android users that the court found to be misleading — which includes three versions of Google’s Web & Activity setting screen shown to consumers setting up a Google account on their device that do not mention the word “location” at all.

Instead, on one — which appeared between April 30, 2018 and December 19 2018 — Google instructs consumers that the setting “saves your searches, Chrome browsing history and activity from sites and apps that use Google services”, before nudging them to retain a pre-selected option to “save my Web & Activity to my Google account” (aka, opt into Google’s tracking) by suggesting: “This gives you better search results, suggestions and personalisation across Google services.” But nowhere does it explain that the user is agreeing to be location tracked.

If Android users chose to try to turn off “Location History” — i.e. via a totally separate setting that did not actually enable them to prevent Google’s location tracking — they could also be shown a confusing pop-up querying their decision to “Pause Location History?”, as Google put it, warning them the decision would “limit functionality of some Google products over time”.

It’s hard to know what even the point of this was, since the setting did not empower consumers to entirely prevent Google snooping on their location, so probably it was mostly there to spread FUD.

The text in this notification concludes with a further confusing line — telling the user to “remember, pausing this setting doesn’t delete any previous activity” — and pointing them to yet more settings where Google suggests they could “view and manage this information in your Location History map”. This was presumably intended to send them down a pointless rabbit hole — while drawing their attention away from the Web & Activity setting where Google had hidden another location tracking setting.

Other versions of the Web & Activity setting which the court found misleading Android users between early 2017 and late 2018 include one which contains a full five possible actions a user could take — a surfeit of choice obviously intended to bamboozle them into leaving the ‘on’ setting as is, since it’s so drastically unclear what anything else available on the screen means.

“If you use more than one account at the same time, some data may get saved in your default account. Learn more at support.google.com,” runs one prominent piece of cryptic Google small print — without actually hyperlinking the URL in question to send the consumer to where they might actually ‘learn more’ (or, well, quickly realize there is nothing much to learn and certainly no ‘off’ switch there).

This chunk of small print mostly appears intended to shield consumers from reading the actual description of the Web & Activity setting’s function — a setting which, remember, is defaulted to ‘on’ — since this very salient information is buried below it (and above a more eye-catching tick-box). But even here Google is not clear: Again, it does not use the word ‘location’ at all; there’s only an indirect reference to “Maps” buried in a list that foregrounds ‘faster searches’ and ‘customized experiences’ to nudge consumers to agree.

By using the name of its popular Maps product as a stand in for location Google appears to be suggesting that Android users need this setting to be on if they want to use Maps — rather than making it plain that the setting refers to its ability to track their location.

The same setting screen also includes a pre-ticked check-box next to yet more text that states: “Include Chrome browsing history and activity from websites and apps that use Google services” — so Google is seemingly unbundling tracking settings, presumably as a back-up in case one of these pre-checked settings gets unchecked, meaning it can at least grab data via the other.

After that there’s more small print, lodged under the bland rubric “data from this device”, which reads: “Control reporting of App Activity from this device”. However this text is not instantly visually linked to any setting the user is able to interact with — so anyone glancing at it might assume it’s not pointing them to an option at all and skip over it.

Airgapped below, towards the very bottom of the screen, is a hyperlinked option to “MANAGE ACTIVITY”. This text is bolder — being in ALL CAPS. So does draw the eye. Yet what even is this? Why does the user have to wade into fresh Google submenu hell to try to turn off tracking, as this option seems to be implying? Surely they can just toggle the ‘on’ switch at the top of the settings screen to do that…

Of course everything baked into this dark pattern layer cake is pushing the consumer far away from any understanding of what’s actually going on with their data in order that they give up and leave the default tracking on. Truly a masterclass in deceptive manipulative design.

Screengrab: ACCC

A big reboot?

While Google’s statement today on the ACCC sanction seeks to imply that all misleading location tracking stuff is in the past, the company is facing an ongoing investigation into the same practices in the European Union — open since February 2020 — where it could be on the hook for a more sizeable fine if it’s found to have infringed the bloc’s General Data Protection Regulation (as penalties can scale as high as 4% of global annual turnover).

Consumer watchdogs in the EU actually filed complaints about Google’s deceptive location tracking back in November 2018. So Google will still be able to claim it’s moved on — whatever the outcome.

A draft decision by Ireland’s DPA, which is leading the investigation, is expected this year — although a final decision could be pushed into 2023 since it must be reviewed by the bloc’s network of DPAs and agreement reached on any enforcement.

But there’s more — earlier this summer, European consumer rights groups filed a new series of complaints against Google — accusing the advertising giant of deceptive design around the account creation process that they say steers users into agreeing to extensive and invasive processing of their data.

The complaints highlight how many more ‘clicks’ are required by Google to let users opt out of its tracking vs handling it the keys to their data… so plus ça change right?

The plodding pace of European privacy law enforcement suggests Google can expect several years’ grace before any corrective orders land — leaving consumers exposed in the meanwhile.

But there’s some harder reform on the horizon: EU lawmakers recently agreed to include a ban on online platforms designing and deploying deceptive/manipulative and/or confusing interfaces in a forthcoming flagship update to the bloc’s digital rulebook.

The Digital Services Act (DSA) is generally intended to dial up responsibility and accountability around digital services by steering governance.

On dark patterns, much will hinge on the specifics of the DSA text, and its interpretation, clearly — and there may still be wiggle room for powerful platforms to find ways to use sharkish practices to rob consumers of their rights and agency. But a key feature of the law is it entails an active role for the European Commission in enforcement (against larger platforms — so called VLOPs).

This includes empowering the EU’s executive to step in and issue guidance on best practice in areas like interface design. Combined with a new ability to bare teeth at repeat offenders — as it gets empowered to hit VLOPs with beefy fines if they break the DSA’s rules — so some of the EU’s consumer-focused regulation could, suddenly, get rather harder to ignore. (The DSA will start applying from next year.)

Penalties for breaches of the DSA can scale up to 6% of global annual turnover. So the cost and risk of stealing people’s data are certainly rising. Whether it’ll be enough to give tracking giants pause for thought — or, what’s really needed, force meaningful reform of privacy-hostile business models — remains to be seen.

Google’s ‘deceptive’ account sign-up process targeted with GDPR complaints

Europe seals a deal on tighter rules for digital services

More TechCrunch

Featured Article

A comprehensive list of 2024 tech layoffs

The tech layoff wave is still going strong in 2024. Following significant workforce reductions in 2022 and 2023, this year has already seen 60,000 job cuts across 254 companies, according to independent layoffs tracker Layoffs.fyi. Companies like Tesla, Amazon, Google, TikTok, Snap and Microsoft have conducted sizable layoffs in the…

3 hours ago
A comprehensive list of 2024 tech layoffs

Featured Article

What to expect from WWDC 2024: iOS 18, macOS 15 and so much AI

Apple is hoping to make WWDC 2024 memorable as it finally spells out its generative AI plans.

3 hours ago
What to expect from WWDC 2024: iOS 18, macOS 15 and so much AI

We just announced the breakout session winners last week. Now meet the roundtable sessions that really “rounded” out the competition for this year’s Disrupt 2024 audience choice program. With five…

The votes are in: Meet the Disrupt 2024 audience choice roundtable winners

The malicious attack appears to have involved malware transmitted through TikTok’s DMs.

TikTok acknowledges exploit targeting high-profile accounts

It’s unusual for three major AI providers to all be down at the same time, which could signal a broader infrastructure issues or internet-scale problem.

AI apocalypse? ChatGPT, Claude and Perplexity all went down at the same time

Welcome to TechCrunch Fintech! This week, we’re looking at LoanSnap’s woes, Nubank’s and Monzo’s positive milestones, a plethora of fintech fundraises and more! To get a roundup of TechCrunch’s biggest…

A look at LoanSnap’s troubles and which neobanks are having a moment

Databricks, the analytics and AI giant, has acquired data management company Tabular for an undisclosed sum. (CNBC reports that Databricks paid over $1 billion.) According to Tabular co-founder Ryan Blue,…

Databricks acquires Tabular to build a common data lakehouse standard

ChatGPT, OpenAI’s text-generating AI chatbot, has taken the world by storm. What started as a tool to hyper-charge productivity through writing essays and code with short text prompts has evolved…

ChatGPT: Everything you need to know about the AI-powered chatbot

The next few weeks could be pivotal for Worldcoin, the controversial eyeball-scanning crypto venture co-founded by OpenAI’s Sam Altman, whose operations remain almost entirely shuttered in the European Union following…

Worldcoin faces pivotal EU privacy decision within weeks

OpenAI’s chatbot ChatGPT has been down for several users across the globe for the last few hours.

OpenAI fixes the issue that caused ChatGPT outage for several hours

True Fit, the AI-powered size-and-fit personalization tool, has offered its size recommendation solution to thousands of retailers for nearly 20 years. Now, the company is venturing into the generative AI…

True Fit leverages generative AI to help online shoppers find clothes that fit

Audio streaming service TuneIn is teaming up with Discord to bring free live radio to the platform. This is TuneIn’s first collaboration with a social platform and one that is…

Discord and TuneIn partner to bring live radio to the social platform

The early victors in the AI gold rush are selling the picks and shovels needed to develop and apply artificial intelligence. Just take a look at data-labeling startup Scale AI…

Scale AI founder Alexandr Wang is coming to Disrupt 2024

Try to imagine the number of parts that go into making a rocket engine. Now imagine requesting and comparing quotes for each of those parts, getting approvals to purchase the…

Engineer brothers found Forge to modernize hardware procurement

Raspberry Pi has released a $70 AI extension kit with a neural network inference accelerator that can be used for local inferencing, for the Raspberry Pi 5.

Raspberry Pi partners with Hailo for its AI extension kit

When Stacklet’s founders, Travis Stanfield and Kapil Thangavelu, came out of Capital One in 2020 to launch their startup, most companies weren’t all that concerned with constraining cloud costs. But…

Stacklet sees demand grow as companies take cloud cost control more seriously

Fivetran’s Managed Data Lake Service aims to remove the repetitive work of managing data lakes.

Fivetran launches a managed data lake service

Lance Riedel and Nigel Daley both spent decades in search discovery, but it was while working at Pinterest that they began trying to understand how to use search engines to…

How a couple of former Pinterest search experts caught Biz Stone’s attention

GetWhy helps businesses carry out market studies and extract insights from video-based interviews using AI.

GetWhy, a market research AI platform that extracts insights from video interviews, raises $34.5M

AI-powered virtual physical therapy platform Sword Health has seen its valuation soar 50% to $3 billion.

Sword Health raises $130M and its valuation soars to $3B

Jeffrey Katzenberg and Sujay Jaswa, along with three general partners, manage $1.5 billion in assets today through their Build, Venture and Seed strategies.

WndrCo officially gets into venture capital with fresh $460M across two funds

The startup targets the middle ground between platforms that offer rigid templates, and those that facilitate a full-control approach.

Storyblok raises $80M to add more AI to its ‘headless’ CMS aimed at non-technical people

The startup has been pursuing a ground-up redesign of a well-understood technology.

‘Star Wars’ lasers and waterfalls of molten salt: How Xcimer plans to make fusion power happen

Sēkr, a startup that offers a mobile app for outdoor enthusiasts and campers, is launching a new AI tool for planning road trips. The new tool, called Copilot, is available…

Travel app Sēkr can plan your next road trip with its new AI tool

Microsoft’s education-focused flavor of its cloud productivity suite, Microsoft 365 Education, is facing investigation in the European Union. Privacy rights nonprofit noyb has just lodged two complaints with Austria’s data…

Microsoft hit with EU privacy complaints over schools’ use of 365 Education suite

Since the shock of Russia’s 2022 invasion of Ukraine, solar energy has been having a moment in Europe. Electricity prices have been going up while the investment required to get…

Samara is accelerating the energy transition in Spain one solar panel at a time

Featured Article

DEI backlash: Stay up-to-date on the latest legal and corporate challenges

It’s clear that this year will be a turning point for DEI.

1 day ago
DEI backlash: Stay up-to-date on the latest legal and corporate challenges

The keynote will be focused on Apple’s software offerings and the developers that power them, including the latest versions of iOS, iPadOS, macOS, tvOS, visionOS and watchOS.

Watch Apple kick off WWDC 2024 right here

Hello and welcome back to TechCrunch Space. Unfortunately, Boeing’s Starliner launch was delayed yet again, this time due to issues with one of the three redundant computers used by United…

TechCrunch Space: China’s victory

The court ruling said that Fearless Fund’s Strivers Grant likely violates the Civil Rights Act of 1866, which bans the use of race in contracts.

An appeals court rules that VC Fearless Fund cannot issue grants to Black women, but the fight continues