January 30th 2015
Google has had to sign a formal undertaking to the Information Commissioner's Office (ICO) that it will improve the information it provides to people about how it collects personal data in the UK. This follows concerns around changes to Google's privacy policy.
The ICO found that Google was too vague when describing how it uses personal data gathered from its web services and products.
The search giant introduced a new privacy policy in March 2012 combining some 70 existing policies for various services, but the ICO ruled that the new policy did not include sufficient information for service users as to how and why their personal data was being collected.
Google has now signed an undertaking committing to make further changes to the privacy policy to ensure it meets the requirements of the Data Protection Act (DPA) and to take steps to ensure that future changes to its privacy policy comply, including user testing.
Whilst conducting its own investigation, the ICO has worked with other European Data Protection Authorities, as part of the Article 29 working party.
ICO Head of Enforcement Steve Eckersley commented:
“This undertaking marks a significant step forward following a long investigation and extensive dialogue. Google’s commitment today to make these necessary changes will improve the information UK consumers receive when using their online services and products. “Whilst our investigation concluded that this case hasn’t resulted in substantial damage and distress to consumers, it is still important for organisations to properly understand the impact of their actions and the requirement to comply with data protection law. Ensuring that personal data is processed fairly and transparently is a key requirement of the Act."
Mr Eckersley continued: "This investigation has identified some important learning points not only for Google, but also for all organisations operating online, particularly when they seek to combine and use data across services. It is vital that there is clear and effective information available to enable users to understand the implications of their data being combined. The detailed agreement Google has signed setting out its commitments will ensure that.”
The ICO has already worked with Google to ensure a significant number of changes to the policy. The search engine must now make the agreed further changes by 30 June and take further steps over the next two years.
The ICO plans to update its Privacy Notices Code Practice later 2015 to provide organisations with further guidance about how to provide effective privacy information, particularly in online and mobile environments.