The ICO found that the search engine was too vague when describing how it uses personal data gathered from its web services and products.
Whilst conducting its own investigation, the ICO has worked with other European Data Protection Authorities, as part of the Article 29 working party.
Steve Eckersley, Head of Enforcement at the ICO, said:
“This undertaking marks a significant step forward following a long investigation and extensive dialogue. Google’s commitment today to make these necessary changes will improve the information UK consumers receive when using their online services and products.
“Whilst our investigation concluded that this case hasn’t resulted in substantial damage and distress to consumers, it is still important for organisations to properly understand the impact of their actions and the requirement to comply with data protection law. Ensuring that personal data is processed fairly and transparently is a key requirement of the Act.
"This investigation has identified some important learning points not only for Google, but also for all organisations operating online, particularly when they seek to combine and use data across services. It is vital that there is clear and effective information available to enable users to understand the implications of their data being combined. The detailed agreement Google has signed setting out its commitments will ensure that.”
The ICO has already worked with Google to ensure a significant number of changes to the policy. The search engine must now make the agreed further changes by 30 June 2015 and take further steps over the next two years.
The ICO plans to update its Privacy Notices Code Practice later 2015 to provide organisations with further guidance about how to provide effective privacy information, particularly in online and mobile environments.
24 January 2012
Google announces it will merge a number of its privacy policies to create one policy for all its products and services on 1 March 2012.
2 February 2012
1 March 2012
16 October 2012
26 February 2013
19 March 2013
Google meets with representatives of the taskforce and sets out some measures which it will implement further to the original recommendations of the Article 29 Working Party.
4 July 2013
6 December 2013
23 September 2014
Article 29 Working Party writes to Google setting out a number of recommendations which have been agreed by the European data protection authorities, including the ICO,
2 December 2014
Google responds to the Article 29 Working Party recommendations setting out a number of improvements aimed at addressing the Working Party’s concerns.
21 January 2015
Following a period of dialogue and engagement with the ICO Google agrees to sign an undertaking committing to all the changes suggested by 30 June 2015, with ongoing commitments for the next two years.
Notes to Editors
- The Information Commissioner’s Office upholds information rights in the public interest, promoting openness by public bodies and data privacy for individuals.
- The ICO has specific responsibilities set out in the Data Protection Act 1998, the Freedom of Information Act 2000, Environmental Information Regulations 2004 and Privacy and Electronic Communications Regulations 2003.
- The ICO is on Twitter, Facebook and LinkedIn. Read more in the ICO blog and e-newsletter.Our Press Office page provides more information for journalists.
- Anyone who processes personal information must comply with eight principles of the Data Protection Act, which make sure that personal information is:
- Fairly and lawfully processed
- Processed for limited purposes
- Adequate, relevant and not excessive
- Accurate and up to date
- Not kept for longer than is necessary
- Processed in line with your rights
- Not transferred to other countries without adequate protection
- Civil Monetary Penalties (CMPs) are subject to a right of appeal to the (First-tier Tribunal) General Regulatory Chamber against the imposition of the monetary penalty and/or the amount of the penalty specified in the monetary penalty notice.
- Any monetary penalty is paid into the Treasury’s Consolidated Fund and is not kept by the Information Commissioner’s Office (ICO).