Google’s practice of combining personal data from its many different online services violates Dutch data protection law, the country’s privacy watchdog said on Thursday after a seven-month investigation.The Dutch Data Protection Authority, or DPA, asked Google to attend a meeting to discuss its concerns, after which it would decide whether to take any action against the cloud services, Internet search and advertising giant, which could include fines.
http://uk.reuters.com/article/2013/11/28/uk-dutch-google-privacy-idUKBRE9AR0KK20131128Also see:Google’s Privacy Policy Violates Dutch Data Protection Law, Dutch DPA Says [IDG]
Google’s practice of combining personal data from different Google services violates the Dutch data protection act, the Dutch data protection authority (DPA) said Thursday. But Google will not face any enforcement actions for now.In March 2012, Google introduced a new privacy policy that allows Google to share personal data across all its products and services. However, Google made the changes without having adequately informed users, and without asking for their consent, the Dutch DPA said in a news release.
www.computerworld.co.nz/article/533100/google_privacy_policy_violates_dutch_data_protection_law_dutch_dpa_says/
www.cio.com/article/743862/Google_39_s_Privacy_Policy_Violates_Dutch_Data_Protection_Law_Dutch_DPA_SaysDutch DPA: privacy policy Google in breach of data protection law [news release]
The combining of personal data by Google since the introduction of its new privacy policy on 1 March 2012 is in breach of the Dutch data protection act. This is the conclusion of the investigation by the Dutch data protection authority [College bescherming persoonsgegevens]. Google combines the personal data from internet users that are collected by all kinds of different Google services, without adequately informing the users in advance and without asking for their consent. The investigation shows that Google does not properly inform users which personal data the company collects and combines, and for what purposes. “Google spins an invisible web of our personal data, without our consent. And that is forbidden by law”, says the chairman of the Dutch data protection authority, Jacob Kohnstamm.The Dutch DPA has invited Google to attend a hearing, after which the authority will decide whether it will take enforcement measures.With its services, Google reaches almost every person in the Netherlands with internet access. It is almost impossible not to use Google services on the Internet. Many internet users use the search engine Search, the videoservice YouTube or the webmail Gmail. In the Report, three types of users of Google services are distinguished: people with a Google account, people without a Google account that use the open services of Google such as Search and YouTube, and people that do not use Google. Google also collects data about this last group of users, when they for example visit one of the more than 2 million websites worldwide with Google advertising cookies.The investigation shows that Google combines personal data relating to internet users that the company obtains from different services. Google does this, amongst others, for the purposes of displaying personalised ads and to personalise services such as YouTube and Search. Some of these data are of a sensitive nature, such as payment information, location data and information on surfing behaviour across multiple websites. Data about search queries, location data and video’s watched can be combined, while the different services serve entirely different purposes from the point of view of users. Google does not adequately inform users about the combining of their personal data from all these different services. On top of that, Google does not offer users any (prior) options to consent to or reject the examined data processing activities. The consent, required by law, for the combining of personal data from different Google services cannot be obtained by accepting general (privacy) terms of service.In January 2012, Google announced that by 1 March 2012 the new privacy policy would apply to all users worldwide. The French data protection authority (CNIL) then initiated an investigation on behalf of all European data protection authorities (united in the Article 29 Working Party). This resulted in findings, that have been published in October 2012. After this initial investigation (with reference to the European Privacydirective), six national privacy authorities, in France, Germany (Hamburg), the UK, Italy, Spain and the Netherlands have decided to initiate national investigations, based on their own national laws.
http://www.dutchdpa.nl/Pages/pb_20131128-google-privacypolicy.aspx