Google’s ‘deceptive’ account sign-up process targeted with GDPR complaints

Comment

Google bans hundreds of Kenya-focused loan apps from Play Store
Image Credits: Pavlo Gonchar/SOPA Images/LightRocket / Getty Images

Consumer rights groups in Europe have filed a new series of privacy complaints against Google — accusing the advertising giant of deceptive design around the account creation process that they say steers users into agreeing to extensive and invasive processing of their data.

The tech giant profiles account holders for ad targeting purposes — apparently relying on user consent as its legal basis. But the EU’s flagship data protection law, the General Data Protection Regulation (GDPR), bakes in a requirement for privacy by design and default, as well as setting clear conditions around how consent must be gathered for it to be lawful.

Hence the consumer groups’ beef — if deceptive design by Google is tricking users into accepting its tracking.

They argue the design choices the tech giant deploys around account creation make it far easier for users to agree to Google’s processing of their information to target them with “personalized” ads than to deny consent to its profiling of them for behavioral advertising.

The Web Foundation is taking on deceptive design

Fast track to being tracked

The complaints highlight how more privacy-friendly options — described by Google as “manual personalization” — require users to take five steps and ten clicks (“grappling with information that is unclear, incomplete, and misleading,” as they put it); whereas it offers a one-click “Express personalisation” option that activates all the tracking, making it terrible for privacy.

They also point out that Google does not provide consumers with the option to turn all tracking “off” in one click, further noting that Google requires account creation to use certain of its own products, such as when setting up an Android smartphone.

In other cases, users may voluntarily create a Google account — but, either way, the tech giant still presents skewed options nudging consumers to agree to its tracking of them.

“Regardless of the path the consumer chooses, Google’s data processing is un-transparent and unfair, with consumers’ personal data being used for purposes which are vague and far reaching,” the complainants also argue in a press release.

The series of GDPR complaints are being coordinated by members group BEUC, aka the European Consumer Organisation.

Per BEUC, complaints have been filed to data protection agencies across EU Member States and markets, including by its member organizations in France, the Czech Republic, Norway, Greece and Slovenia.

It also notes that its German member, the vzbv, has written a warning letter to Google — ahead of potentially filing a civil lawsuit — while consumer groups in the Netherlands, Denmark and Sweden have written to their national DPAs to alert them to the practices.

Commenting on the action in a statement, Ursula Pachl, deputy DG of BEUC, said:

“Contrary to what Google claims about protecting consumers’ privacy, tens of millions of Europeans have been placed on a fast track to surveillance when they signed up to a Google account. It takes one simple step to let Google monitor and exploit everything you do. If you want to benefit from privacy-friendly settings, you must navigate through a longer process and a mix of unclear and misleading options. In short, when you create a Google account, you are subjected to surveillance by design and by default. Instead, privacy protection should be the default and easiest choice for consumers.”

A Google spokesman responded to the complaints with this statement:

“We know that consumer trust depends on honesty and transparency — which is why we’ve staked our future success on building ever simpler, more accessible controls and giving people clearer choices. And, just as important, doing more with less data.

*We welcome the opportunity to engage on this important topic with Europe’s consumer advocates and regulators. People should be able to understand how data is generated from their use of internet services. If they don’t like it, they should be able to do something about it.”

The company spokesman also argued that different options it presents when someone is creating a new Google account are “clearly labeled and designed to be simple to understand”. “We have based them on extensive research efforts and guidance from DPAs [data protection authorities] and feedback from testers. We are committed to ensuring these choices are clear and simple,” he added.

We asked Google which DPAs’ advice have fed into the design it uses for account creation.

Its spokesman told us: “We applied a layered approach to transparency in line with guidance from the EDPB [European Data Protection Board]: the guidance recognises that ‘layered and granular information can be an appropriate way to deal with the two-fold obligation of being precise and complete on the one hand and understandable on the other hand’.”

Repeat offender

This is not the first privacy-related complaint EU consumer rights have made about Google’s practices. They also raised a complaint focused on its collection of location data back in 2018 — but it took until February 2020 for Google’s lead EU data supervisor, Ireland’s Data Protection Commission (DPC), to start an inquiry. And, more than 2 years later, that data probe remains ongoing.

Back in May, the DPC’s deputy commissioner, Graham Doyle, told TechCrunch it was expecting to submit a draft decision on the Google location data inquiry to other DPAs for review “over the coming months.” However, if there is disagreement over Ireland’s approach, it could add many more months before agreement on a final consensus decision is reached. So a resolution of that long-running complaint may still not arrive this year.

The DPC also still hasn’t issued decisions on other long-running GDPR complaints against Google. Such as a major complaint about its adtech, which it began investigating in May 2019 — and is now being sued over for inaction.

Another complaint — against’s Google use of so-called forced consent on its Android mobile platform — dates back to May 2018, although it’s not clear if the DPC ever opened an inquiry in that case. France’s data protection watchdog, the CNIL, proceeded to investigate — and fined Google $57 million back in January 2019 over breaches of transparency and consent attached to how it operates Android. (The CNIL decided it had competence in that case since Android-related decisions were likely taken in the U.S., rather than in Dublin, where Google’s regional HQ is based.)

But Ireland has yet to issue a single GDPR decision against Google.

BEUC is not hiding its frustration at the DPC’s lack of enforcement over complaints against the tech giant.

“Google is a repeat offender,” said Pachl. “It is more than three years since we filed complaints against Google’s location-tracking practices and the Irish DPC in charge has still not issued a decision on the case. Meanwhile Google’s practices have not changed in essence. The tech giant still carries out continuous tracking and profiling of consumers and its practices set the tone for the rest of the market.”

“We need swift action from the authorities because having one of the biggest players ignoring the GDPR is unacceptable,” she added. “This case is of strategic importance for which cooperation among data protection authorities across the EU must be prioritised and supported by the European Data Protection Board.”

Issues around Google’s tracking of account users is separate to the advertising giant’s cookie-based tracking — where it deploys technologies to track users across third-party websites and apps.

The latter process has been the subject of other EU complaints that have led to some enforcements in recent years, with France’s data protection watchdog hitting Google with fines approaching $300 million for cookies tracking-related breaches under the bloc’s ePrivacy Directive — after which Google made some changes to the cookie consent banner it shows web users in Europe.

Strategic complaint

Pachl’s remark about the Google account sign-up complaint being of “strategic importance” refers to BEUC’s expectation that the case will trigger the launch of a procedure under the GDPR’s cooperation mechanism (i.e., Article 60), which it hopes will function more smoothly than it has been since 2018, when the Google location data complaint was filed.

The reason BEUC is hoping for smoother sailing now is because of an agreement EU DPAs reached in April — aka the “Vienna declaration” — when they committed to enhance their enforcement cooperation on cross-border GDPR cases of “strategic importance.”

A complaint against a tech giant like Google clearly hits that bar. But the older Google location data complaint has been saddled with a number of cooperation-related issues that have contributed to slowing down investigation and delaying a decision in that case.

Discussing what changes BEUC hopes to see being applied by regulators in tackling this fresh cross-border Google complaint, David Martin Ruiz, team leader for digital policy at the organization, told us: “We expect that the treatment of the complaints is prioritised as it touches upon practices by a major market player in the surveillance economy which affect millions of Europeans. The first time it took around 6 months just to name the lead authority. Also, we expect better, closer cooperation among the authorities, for example in terms of checking the admissibility of the complaints, and that this is done only once by the authority which receives the complaints. Of course, we expect that closer cooperation and strategic prioritisation by the authorities involved leads to a swift, comprehensive investigation of the complaints and efficient enforcement.”

Still, Ruiz declined to offer a prediction for how much faster the revised cooperation procedure will be able to deliver enforcement against Google, saying: “It is hard to put a concrete number on this but we certainly hope it takes less than the one that is ongoing, and we are not here 3 years from now still waiting for a draft decision.”

The European Commission, which has also been critical of adtech giants’ approach to compliance with EU privacy laws, recently defended slower regulatory enforcements in these major, cross-border cases.

In a letter to the European ombudsperson — which has been looking into the EU executive’s monitoring of the GDPR following complaints about the Commission’s own oversight of the regulation — justice commissioner, Didier Reynders, likened the level of complexity involved in these big investigations to antitrust cases, writing:

” … it is important to make a distinction between cases which are relatively straightforward and do not require extensive investigations and cases which require complex legal and economic assessment or pose novel issues. Those complex cases, for instance those touching on issues relating to the business model of big tech multinational companies, might require several months or years of investigations, similarly to what happens for competition law investigations. This is particularly relevant for Ireland since many of such companies have their main establishment in this Member State.”

Responding to Reynders’ point, Ruiz told TechCrunch: “We agree and understand that these are complex issues and the authorities need time to build strong cases. However, we have seen problems that go beyond the time it takes to investigate these cases (e.g., a DPA narrowing down the scope of complaints when deciding to open their own investigation). Moreover, a lot of the big complaints that are taking years are actually not normal complaints, in the sense that they come already backed with a lot of legal analysis and factual evidence, aiming to facilitate the tasks of the DPAs. Also, of course, the time it takes to resolve these cases is also an illustration of deeper issues, like a lack of sufficient resources. Hopefully, strengthened cooperation and strategic prioritisation, as per the Vienna declaration, will help reduce the time it takes to investigate these cases. Complexity and the time it takes to investigate cannot be an excuse for inaction.”

BEUC isn’t calling for major revisions to GDPR to solve the problem of timely enforcement against Big Tech. But it is pushing for DPAs to make a whole series of process changes, individually and collectively, in order to address issues like the bottleneck of cases linked to the regulation’s one-stop-shop/lead data supervisor structure, which has enabled the problem of forum shopping.

“In a nutshell, regarding Big Tech, the first step is to stop the ‘bottleneck,’” he said. “Basically, DPAs, in particular one DPA which has oversight over many of the Big Tech companies, needs to deliver decisions on the open cases. And both the lead DPA, and the rest of the DPAs in the EDPB, need to be strict and ambitious in their interpretation and application of the rules. Also, if the lead DPA is not delivering the decisions, the others must make full use of their powers and take urgent measures. There needs to be a clear signal to Big Tech that window dressing and cosmetic transparency measures won’t do anymore. There are some fundamental issues in their core business practices that must be addressed, because they run contrary to the very essence of the GDPR.”

“Of course it is a concern that enforcement does not move as fast as market practices, and companies are changing things all the time. It is very important to underline that a company tweaking and correcting something should not erase past infringements and leave them unpunished, especially if they have been going on for years and they have affected millions of people. Otherwise, it is a very dangerous signal we are sending to companies,” he added. “We would be telling them ‘it is ok to infringe the GDPR as long as you are not caught, and if you are caught, just fix it quickly and there will be no consequences.’ This is the opposite of what should happen. Infringements must have consequences. Otherwise there is no justice, and no deterrent effects.”

This report was updated with responses from Google

Google’s location tracking finally under formal probe in Europe

GDPR enforcement must level up to catch big tech, report warns

More TechCrunch

The prospects for troubled banking-as-a-service startup Synapse have gone from bad to worse this week after a United States Trustee filed an emergency motion on Wednesday.  The trustee is asking…

A US Trustee wants troubled fintech Synapse to be liquidated via Chapter 7 bankruptcy, cites ‘gross mismanagement’

U.K.-based Seraphim Space is spinning up its 13th accelerator program, with nine participating companies working on a range of tech from propulsion to in-space manufacturing and space situational awareness. The…

Seraphim’s latest space accelerator welcomes nine companies

OpenAI has reached a deal with Reddit to use the social news site’s data for training AI models. In a blog post on OpenAI’s press relations site, the company said…

OpenAI inks deal to train AI on Reddit data

X users will now be able to discover posts from new Communities that are trending directly from an Explore tab within the section.

X pushes more users to Communities

For Mark Zuckerberg’s 40th birthday, his wife got him a photoshoot. Zuckerberg gives the camera a sly smile as he sits amid a carefully crafted re-creation of his childhood bedroom.…

Mark Zuckerberg’s makeover: Midlife crisis or carefully crafted rebrand?

Strava announced a slew of features, including AI to weed out leaderboard cheats, a new ‘family’ subscription plan, dark mode and more.

Strava taps AI to weed out leaderboard cheats, unveils ‘family’ plan, dark mode and more

We all fall down sometimes. Astronauts are no exception. You need to be in peak physical condition for space travel, but bulky space suits and lower gravity levels can be…

Astronauts fall over. Robotic limbs can help them back up.

Microsoft will launch its custom Cobalt 100 chips to customers as a public preview at its Build conference next week, TechCrunch has learned. In an analyst briefing ahead of Build,…

Microsoft’s custom Cobalt chips will come to Azure next week

What a wild week for transportation news! It was a smorgasbord of news that seemed to touch every sector and theme in transportation.

Tesla keeps cutting jobs and the feds probe Waymo

Sony Music Group has sent letters to more than 700 tech companies and music streaming services to warn them not to use its music to train AI without explicit permission.…

Sony Music warns tech companies over ‘unauthorized’ use of its content to train AI

Winston Chi, Butter’s founder and CEO, told TechCrunch that “most parties, including our investors and us, are making money” from the exit.

GrubMarket buys Butter to give its food distribution tech an AI boost

The investor lawsuit is related to Bolt securing a $30 million personal loan to Ryan Breslow, which was later defaulted on.

Bolt founder Ryan Breslow wants to settle an investor lawsuit by returning $37 million worth of shares

Meta, the parent company of Facebook, launched an enterprise version of the prominent social network in 2015. It always seemed like a stretch for a company built on a consumer…

With the end of Workplace, it’s fair to wonder if Meta was ever serious about the enterprise

X, formerly Twitter, turned TweetDeck into X Pro and pushed it behind a paywall. But there is a new column-based social media tool in town, and it’s from Instagram Threads.…

Meta Threads is testing pinned columns on the web, similar to the old TweetDeck

As part of 2024’s Accessibility Awareness Day, Google is showing off some updates to Android that should be useful to folks with mobility or vision impairments. Project Gameface allows gamers…

Google expands hands-free and eyes-free interfaces on Android

A hacker listed the data allegedly breached from Samco on a known cybercrime forum.

Hacker claims theft of India’s Samco account data

A top European privacy watchdog is investigating following the recent breaches of Dell customers’ personal information, TechCrunch has learned.  Ireland’s Data Protection Commission (DPC) deputy commissioner Graham Doyle confirmed to…

Ireland privacy watchdog confirms Dell data breach investigation

Ampere and Qualcomm aren’t the most obvious of partners. Both, after all, offer Arm-based chips for running data center servers (though Qualcomm’s largest market remains mobile). But as the two…

Ampere teams up with Qualcomm to launch an Arm-based AI server

At Google’s I/O developer conference, the company made its case to developers — and to some extent, consumers — why its bets on AI are ahead of rivals. At the…

Google I/O was an AI evolution, not a revolution

TechCrunch Disrupt has always been the ultimate convergence point for all things startup and tech. In the bustling world of innovation, it serves as the “big top” tent, where entrepreneurs,…

Meet the Magnificent Six: A tour of the stages at Disrupt 2024

There’s apparently a lot of demand for an on-demand handyperson. Khosla Ventures and Pear VC have just tripled down on their investment in Honey Homes, which offers up a dedicated…

Khosla Ventures, Pear VC triple down on Honey Homes, a smart way to hire a handyman

TikTok is testing the ability for users to upload 60-minute videos, the company confirmed to TechCrunch on Thursday. The feature is available to a limited group of users in select…

TikTok tests 60-minute video uploads as it continues to take on YouTube

Flock Safety is a multibillion-dollar startup that’s got eyes everywhere. As of Wednesday, with the company’s new Solar Condor cameras, those eyes are solar-powered and use wireless 5G networks to…

Flock Safety’s solar-powered cameras could make surveillance more widespread

Since he was very young, Bar Mor knew that he would inevitably do something with real estate. His family was involved in all types of real estate projects, from ground-up…

Agora raises $34M Series B to keep building the Carta for real estate

Poshmark, the social commerce site that lets people buy and sell new and used items to each other, launched a paid marketing tool on Thursday, giving sellers the ability to…

Poshmark’s ‘Promoted Closet’ tool lets sellers boost all their listings at once

Google is launching a Gemini add-on for educational institutes through Google Workspace.

Google adds Gemini to its Education suite

More money for the generative AI boom: Y Combinator-backed developer infrastructure startup Recall.ai announced Thursday it has raised a $10 million Series A funding round, bringing its total raised to over…

YC-backed Recall.ai gets $10M Series A to help companies use virtual meeting data

Engineers Adam Keating and Jeremy Andrews were tired of using spreadsheets and screenshots to collab with teammates — so they launched a startup, CoLab, to build a better way. The…

CoLab’s collaborative tools for engineers line up $21M in new funding

Reddit announced on Wednesday that it is reintroducing its awards system after shutting down the program last year. The company said that most of the mechanisms related to awards will…

Reddit reintroduces its awards system

Sigma Computing, a startup building a range of data analytics and business intelligence tools, has raised $200 million in a fresh VC round.

Sigma is building a suite of collaborative data analytics tools