Privacy

Google fined $40M+ for misleading location-tracking settings on Android

Comment

Image Credits: Leon Neal / Getty Images

Google has been sanctioned A$60 million (around $40 million+) in Australia over Android settings it had applied, dating back around five years, which were found — in a 2021 court ruling — to have mislead consumers about its location data collection.

Australia’s Competition & Consumer Commission (ACCC) instigated proceedings against Google and its Australia subsidiary back in October 2019, going on to take the tech giant to court for making misleading representations to consumers about the collection and use of their personal location data on Android phones, between January 2017 and December 2018.

In April 2021 the court found Google had breached Australia’s Consumer Law when it represented to some Android users that the “Location History” setting was the only Google account setting affecting whether it collected, kept and used personally identifiable data about their location.

In actuality, another setting — called ‘Web & App Activity’ — also enabled Google to grab Android users’ location data and this was turned on by default, as the ACCC noted in a press release today. Aka, a classic dark pattern. (Actually Google deployed nested dark patterns, plural, as we detail below.)

Google misled consumers over location data settings, Australia court finds

The regulator estimates that users of around 1.3 million Google accounts in Australia may have viewed a screen found by the Court to have breached the Consumer Law.

“This significant penalty imposed by the Court today sends a strong message to digital platforms and other businesses, large and small, that they must not mislead consumers about how their data is being collected and used,” said ACCC chair, Gina Cass-Gottlieb, in a statement.

“Google, one of the world’s largest companies, was able to keep the location data collected through the ‘Web & App Activity’ setting and that retained data could be used by Google to target ads to some consumers, even if those consumers had the ‘Location History’ setting turned off.”

“Personal location data is sensitive and important to some consumers, and some of the users who saw the representations may have made different choices about the collection, storage and use of their location data if the misleading representations had not been made by Google,” she added.

Per the ACCC, Google took steps to correct the contravening conduct by 20 December 2018, meaning consumers in the country were no longer shown the misleading screens.

At the time of the court ruling last year, Google said it disagreed with the findings and that it was considering an appeal. But, in the event, it decided to take the lumps.

(These are not as painful as they might have been if the infringements had occurred more recently: The ACCC notes that the majority of the sanctioned conduct occurred prior to September 2018 which is before the maximum penalty for breaches of the Consumer Law was substantially increased — from $1.1 million per breach to — since then — the higher of $10 million, 3x the value of any benefit obtained or, if the value cannot be determined, 10% of turnover.)

The Court has also ordered Google to ensure its policies include a commitment to compliance, and requirements that it train certain staff about the country’s Consumer Law, as well as to pay a contribution to the ACCC’s costs.

Google was contacted for comment on the sanction. A company spokesperson sent us this statement:

We can confirm that we’ve agreed to settle the matter concerning historical conduct from 2017-2018. We’ve invested heavily in making location information simple to manage and easy to understand with industry-first tools like auto-delete controls, while significantly minimising the amount of data stored. As we’ve demonstrated, we’re committed to making ongoing updates that give users control and transparency, while providing the most helpful products possible.

Dark patterns inside dark patterns

The ACCC’s press release includes some screengrabs showing Google notifications to Android users that the court found to be misleading — which includes three versions of Google’s Web & Activity setting screen shown to consumers setting up a Google account on their device that do not mention the word “location” at all.

Instead, on one — which appeared between April 30, 2018 and December 19 2018 — Google instructs consumers that the setting “saves your searches, Chrome browsing history and activity from sites and apps that use Google services”, before nudging them to retain a pre-selected option to “save my Web & Activity to my Google account” (aka, opt into Google’s tracking) by suggesting: “This gives you better search results, suggestions and personalisation across Google services.” But nowhere does it explain that the user is agreeing to be location tracked.

If Android users chose to try to turn off “Location History” — i.e. via a totally separate setting that did not actually enable them to prevent Google’s location tracking — they could also be shown a confusing pop-up querying their decision to “Pause Location History?”, as Google put it, warning them the decision would “limit functionality of some Google products over time”.

It’s hard to know what even the point of this was, since the setting did not empower consumers to entirely prevent Google snooping on their location, so probably it was mostly there to spread FUD.

The text in this notification concludes with a further confusing line — telling the user to “remember, pausing this setting doesn’t delete any previous activity” — and pointing them to yet more settings where Google suggests they could “view and manage this information in your Location History map”. This was presumably intended to send them down a pointless rabbit hole — while drawing their attention away from the Web & Activity setting where Google had hidden another location tracking setting.

Other versions of the Web & Activity setting which the court found misleading Android users between early 2017 and late 2018 include one which contains a full five possible actions a user could take — a surfeit of choice obviously intended to bamboozle them into leaving the ‘on’ setting as is, since it’s so drastically unclear what anything else available on the screen means.

“If you use more than one account at the same time, some data may get saved in your default account. Learn more at support.google.com,” runs one prominent piece of cryptic Google small print — without actually hyperlinking the URL in question to send the consumer to where they might actually ‘learn more’ (or, well, quickly realize there is nothing much to learn and certainly no ‘off’ switch there).

This chunk of small print mostly appears intended to shield consumers from reading the actual description of the Web & Activity setting’s function — a setting which, remember, is defaulted to ‘on’ — since this very salient information is buried below it (and above a more eye-catching tick-box). But even here Google is not clear: Again, it does not use the word ‘location’ at all; there’s only an indirect reference to “Maps” buried in a list that foregrounds ‘faster searches’ and ‘customized experiences’ to nudge consumers to agree.

By using the name of its popular Maps product as a stand in for location Google appears to be suggesting that Android users need this setting to be on if they want to use Maps — rather than making it plain that the setting refers to its ability to track their location.

The same setting screen also includes a pre-ticked check-box next to yet more text that states: “Include Chrome browsing history and activity from websites and apps that use Google services” — so Google is seemingly unbundling tracking settings, presumably as a back-up in case one of these pre-checked settings gets unchecked, meaning it can at least grab data via the other.

After that there’s more small print, lodged under the bland rubric “data from this device”, which reads: “Control reporting of App Activity from this device”. However this text is not instantly visually linked to any setting the user is able to interact with — so anyone glancing at it might assume it’s not pointing them to an option at all and skip over it.

Airgapped below, towards the very bottom of the screen, is a hyperlinked option to “MANAGE ACTIVITY”. This text is bolder — being in ALL CAPS. So does draw the eye. Yet what even is this? Why does the user have to wade into fresh Google submenu hell to try to turn off tracking, as this option seems to be implying? Surely they can just toggle the ‘on’ switch at the top of the settings screen to do that…

Of course everything baked into this dark pattern layer cake is pushing the consumer far away from any understanding of what’s actually going on with their data in order that they give up and leave the default tracking on. Truly a masterclass in deceptive manipulative design.

Screengrab: ACCC

A big reboot?

While Google’s statement today on the ACCC sanction seeks to imply that all misleading location tracking stuff is in the past, the company is facing an ongoing investigation into the same practices in the European Union — open since February 2020 — where it could be on the hook for a more sizeable fine if it’s found to have infringed the bloc’s General Data Protection Regulation (as penalties can scale as high as 4% of global annual turnover).

Consumer watchdogs in the EU actually filed complaints about Google’s deceptive location tracking back in November 2018. So Google will still be able to claim it’s moved on — whatever the outcome.

A draft decision by Ireland’s DPA, which is leading the investigation, is expected this year — although a final decision could be pushed into 2023 since it must be reviewed by the bloc’s network of DPAs and agreement reached on any enforcement.

But there’s more — earlier this summer, European consumer rights groups filed a new series of complaints against Google — accusing the advertising giant of deceptive design around the account creation process that they say steers users into agreeing to extensive and invasive processing of their data.

The complaints highlight how many more ‘clicks’ are required by Google to let users opt out of its tracking vs handling it the keys to their data… so plus ça change right?

The plodding pace of European privacy law enforcement suggests Google can expect several years’ grace before any corrective orders land — leaving consumers exposed in the meanwhile.

But there’s some harder reform on the horizon: EU lawmakers recently agreed to include a ban on online platforms designing and deploying deceptive/manipulative and/or confusing interfaces in a forthcoming flagship update to the bloc’s digital rulebook.

The Digital Services Act (DSA) is generally intended to dial up responsibility and accountability around digital services by steering governance.

On dark patterns, much will hinge on the specifics of the DSA text, and its interpretation, clearly — and there may still be wiggle room for powerful platforms to find ways to use sharkish practices to rob consumers of their rights and agency. But a key feature of the law is it entails an active role for the European Commission in enforcement (against larger platforms — so called VLOPs).

This includes empowering the EU’s executive to step in and issue guidance on best practice in areas like interface design. Combined with a new ability to bare teeth at repeat offenders — as it gets empowered to hit VLOPs with beefy fines if they break the DSA’s rules — so some of the EU’s consumer-focused regulation could, suddenly, get rather harder to ignore. (The DSA will start applying from next year.)

Penalties for breaches of the DSA can scale up to 6% of global annual turnover. So the cost and risk of stealing people’s data are certainly rising. Whether it’ll be enough to give tracking giants pause for thought — or, what’s really needed, force meaningful reform of privacy-hostile business models — remains to be seen.

Google’s ‘deceptive’ account sign-up process targeted with GDPR complaints

Europe seals a deal on tighter rules for digital services

More TechCrunch

Jasper Health, a cancer care platform startup, laid off a substantial part of its workforce, TechCrunch has learned.

General Catalyst-backed Jasper Health lays off staff

Live Nation says its Ticketmaster subsidiary was hacked. A hacker claims to be selling 560 million customer records.

Live Nation confirms Ticketmaster was hacked, says personal information stolen in data breach

Featured Article

Inside EV startup Fisker’s collapse: how the company crumbled under its founders’ whims

An autonomous pod. A solid-state battery-powered sports car. An electric pickup truck. A convertible grand tourer EV with up to 600 miles of range. A “fully connected mobility device” for young urban innovators to be built by Foxconn and priced under $30,000. The next Popemobile. Over the past eight years, famed vehicle designer Henrik Fisker…

14 hours ago
Inside EV startup Fisker’s collapse: how the company crumbled under its founders’ whims

Late Friday afternoon, a time window companies usually reserve for unflattering disclosures, AI startup Hugging Face said that its security team earlier this week detected “unauthorized access” to Spaces, Hugging…

Hugging Face says it detected ‘unauthorized access’ to its AI model hosting platform

Featured Article

Hacked, leaked, exposed: Why you should never use stalkerware apps

Using stalkerware is creepy, unethical, potentially illegal, and puts your data and that of your loved ones in danger.

15 hours ago
Hacked, leaked, exposed: Why you should never use stalkerware apps

The design brief was simple: each grind and dry cycle had to be completed before breakfast. Here’s how Mill made it happen.

Mill’s redesigned food waste bin really is faster and quieter than before

Google is embarrassed about its AI Overviews, too. After a deluge of dunks and memes over the past week, which cracked on the poor quality and outright misinformation that arose…

Google admits its AI Overviews need work, but we’re all helping it beta test

Welcome to Startups Weekly — Haje‘s weekly recap of everything you can’t miss from the world of startups. Sign up here to get it in your inbox every Friday. In…

Startups Weekly: Musk raises $6B for AI and the fintech dominoes are falling

The product, which ZeroMark calls a “fire control system,” has two components: a small computer that has sensors, like lidar and electro-optical, and a motorized buttstock.

a16z-backed ZeroMark wants to give soldiers guns that don’t miss against drones

The RAW Dating App aims to shake up the dating scheme by shedding the fake, TikTok-ified, heavily filtered photos and replacing them with a more genuine, unvarnished experience. The app…

Pitch Deck Teardown: RAW Dating App’s $3M angel deck

Yes, we’re calling it “ThreadsDeck” now. At least that’s the tag many are using to describe the new user interface for Instagram’s X competitor, Threads, which resembles the column-based format…

‘ThreadsDeck’ arrived just in time for the Trump verdict

Japanese crypto exchange DMM Bitcoin confirmed on Friday that it had been the victim of a hack resulting in the theft of 4,502.9 bitcoin, or about $305 million.  According to…

Hackers steal $305M from DMM Bitcoin crypto exchange

This is not a drill! Today marks the final day to secure your early-bird tickets for TechCrunch Disrupt 2024 at a significantly reduced rate. At midnight tonight, May 31, ticket…

Disrupt 2024 early-bird prices end at midnight

Instagram is testing a way for creators to experiment with reels without committing to having them displayed on their profiles, giving the social network a possible edge over TikTok and…

Instagram tests ‘trial reels’ that don’t display to a creator’s followers

U.S. federal regulators have requested more information from Zoox, Amazon’s self-driving unit, as part of an investigation into rear-end crash risks posed by unexpected braking. The National Highway Traffic Safety…

Feds tell Zoox to send more info about autonomous vehicles suddenly braking

You thought the hottest rap battle of the summer was between Kendrick Lamar and Drake. You were wrong. It’s between Canva and an enterprise CIO. At its Canva Create event…

Canva’s rap battle is part of a long legacy of Silicon Valley cringe

Voice cloning startup ElevenLabs introduced a new tool for users to generate sound effects through prompts today after announcing the project back in February.

ElevenLabs debuts AI-powered tool to generate sound effects

We caught up with Antler founder and CEO Magnus Grimeland about the startup scene in Asia, the current tech startup trends in the region and investment approaches during the rise…

VC firm Antler’s CEO says Asia presents ‘biggest opportunity’ in the world for growth

Temu is to face Europe’s strictest rules after being designated as a “very large online platform” under the Digital Services Act (DSA).

Chinese e-commerce marketplace Temu faces stricter EU rules as a ‘very large online platform’

Meta has been banned from launching features on Facebook and Instagram that would have collected data on voters in Spain using the social networks ahead of next month’s European Elections.…

Spain bans Meta from launching election features on Facebook, Instagram over privacy fears

Stripe, the world’s most valuable fintech startup, said on Friday that it will temporarily move to an invite-only model for new account sign-ups in India, calling the move “a tough…

Stripe curbs its India ambitions over regulatory situation

The 2024 election is likely to be the first in which faked audio and video of candidates is a serious factor. As campaigns warm up, voters should be aware: voice…

Voice cloning of political figures is still easy as pie

When Alex Ewing was a kid growing up in Purcell, Oklahoma, he knew how close he was to home based on which billboards he could see out the car window.…

OneScreen.ai brings startup ads to billboards and NYC’s subway

SpaceX’s massive Starship rocket could take to the skies for the fourth time on June 5, with the primary objective of evaluating the second stage’s reusable heat shield as the…

SpaceX sent Starship to orbit — the next launch will try to bring it back

Eric Lefkofsky knows the public listing rodeo well and is about to enter it for a fourth time. The serial entrepreneur, whose net worth is estimated at nearly $4 billion,…

Billionaire Groupon founder Eric Lefkofsky is back with another IPO: AI health tech Tempus

TechCrunch Disrupt showcases cutting-edge technology and innovation, and this year’s edition will not disappoint. Among thousands of insightful breakout session submissions for this year’s Audience Choice program, five breakout sessions…

You’ve spoken! Meet the Disrupt 2024 breakout session audience choice winners

Check Point is the latest security vendor to fix a vulnerability in its technology, which it sells to companies to protect their networks.

Zero-day flaw in Check Point VPNs is ‘extremely easy’ to exploit

Though Spotify never shared official numbers, it’s likely that Car Thing underperformed or was just not worth continued investment in today’s tighter economic market.

Spotify offers Car Thing refunds as it faces lawsuit over bricking the streaming device

The studies, by researchers at MIT, Ben-Gurion University, Cambridge and Northeastern, were independently conducted but complement each other well.

Misinformation works, and a handful of social ‘supersharers’ sent 80% of it in 2020

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! Okay, okay…

Tesla shareholder sweepstakes and EV layoffs hit Lucid and Fisker