French Data Protection Authority Levies Record Fine Against Google
Time 2 Minute Read

On March 21, 2011, the French Data Protection Authority (the “CNIL”) published its decision to fine Google €100,000 for violating the French Data Protection Act.

In 2009, the CNIL inspected Google’s geolocation service (“Street View”), which revealed that Google had collected huge quantities of undeclared personal data (e.g., navigation data, email content, logins and passwords) through Wi-Fi connections accessed by its Street View cars.  Google responded that the personal data had been collected by mistake, and promised to stop the Wi-Fi data collection.

In May 2010, the CNIL ordered Google to cease the breach within a specified time limit.  In particular, the CNIL asked Google to register all of its data processing activities (including Google Latitude) with the CNIL, to cease covert and unlawful collections of all personal data by Street View vehicles, and to disclose to the CNIL a copy of all personal data the vehicles had collected via Wi-Fi connections.

On March 17, 2011, the CNIL’s sanction committee imposed a €100,000 fine on Google on the grounds that the company had failed to comply with these conditions and had therefore violated the French Data Protection Act.  In particular, the CNIL ruled that Google continued to collect personal data via smartphones connected to Latitude, without the users’ knowledge.  The CNIL also ruled that Google Latitude is subject to French law since Google uses equipment (e.g., Google Street View cars, end user terminals, Wi-Fi connections) on French territory, and this activity must therefore be registered with the CNIL.

This decision constitutes a record fine against a data controller and sends a clear signal that the CNIL intends to toughen controls over data processing activities taking place on French soil.

The CNIL’s decision is available on the CNIL’s website.

You May Also Be Interested In

Time 2 Minute Read

On April 1, 2026, the U.S. Court of Appeals for the Seventh Circuit held that the 2024 amendment to Illinois’ Biometric Information Privacy Act, limiting damages, applies retroactively to pending cases.

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 3 Minute Read

The results are in: attorneys are filing more employment law cases in court.  Indeed, year-end reporting from legal databases like LexMachina confirm that the pace of filing new employment discrimination cases reached its highest level in 2025, surpassing 20,000 new filings nationwide.  Though overtime and minimum wage lawsuits under the Fair Labor Standards Act (FLSA) have continued to decline since 2015, discrimination cases under laws like Title VII of the Civil Rights Act of 1964 and the Americans with Disabilities Act are on the rise.

Time 2 Minute Read

On March 5, 2026, the California Privacy Protection Agency announced that the agency had reached a settlement with Ford Motor Company resolving an enforcement action against the company that alleged noncompliance with the California Consumer Privacy Act’s opt-out of sale/sharing rights.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page