Google’s ‘deceptive’ account sign-up process targeted with GDPR complaints

Comment

Google bans hundreds of Kenya-focused loan apps from Play Store
Image Credits: Pavlo Gonchar/SOPA Images/LightRocket / Getty Images

Consumer rights groups in Europe have filed a new series of privacy complaints against Google — accusing the advertising giant of deceptive design around the account creation process that they say steers users into agreeing to extensive and invasive processing of their data.

The tech giant profiles account holders for ad targeting purposes — apparently relying on user consent as its legal basis. But the EU’s flagship data protection law, the General Data Protection Regulation (GDPR), bakes in a requirement for privacy by design and default, as well as setting clear conditions around how consent must be gathered for it to be lawful.

Hence the consumer groups’ beef — if deceptive design by Google is tricking users into accepting its tracking.

They argue the design choices the tech giant deploys around account creation make it far easier for users to agree to Google’s processing of their information to target them with “personalized” ads than to deny consent to its profiling of them for behavioral advertising.

The Web Foundation is taking on deceptive design

Fast track to being tracked

The complaints highlight how more privacy-friendly options — described by Google as “manual personalization” — require users to take five steps and ten clicks (“grappling with information that is unclear, incomplete, and misleading,” as they put it); whereas it offers a one-click “Express personalisation” option that activates all the tracking, making it terrible for privacy.

They also point out that Google does not provide consumers with the option to turn all tracking “off” in one click, further noting that Google requires account creation to use certain of its own products, such as when setting up an Android smartphone.

In other cases, users may voluntarily create a Google account — but, either way, the tech giant still presents skewed options nudging consumers to agree to its tracking of them.

“Regardless of the path the consumer chooses, Google’s data processing is un-transparent and unfair, with consumers’ personal data being used for purposes which are vague and far reaching,” the complainants also argue in a press release.

The series of GDPR complaints are being coordinated by members group BEUC, aka the European Consumer Organisation.

Per BEUC, complaints have been filed to data protection agencies across EU Member States and markets, including by its member organizations in France, the Czech Republic, Norway, Greece and Slovenia.

It also notes that its German member, the vzbv, has written a warning letter to Google — ahead of potentially filing a civil lawsuit — while consumer groups in the Netherlands, Denmark and Sweden have written to their national DPAs to alert them to the practices.

Commenting on the action in a statement, Ursula Pachl, deputy DG of BEUC, said:

“Contrary to what Google claims about protecting consumers’ privacy, tens of millions of Europeans have been placed on a fast track to surveillance when they signed up to a Google account. It takes one simple step to let Google monitor and exploit everything you do. If you want to benefit from privacy-friendly settings, you must navigate through a longer process and a mix of unclear and misleading options. In short, when you create a Google account, you are subjected to surveillance by design and by default. Instead, privacy protection should be the default and easiest choice for consumers.”

A Google spokesman responded to the complaints with this statement:

“We know that consumer trust depends on honesty and transparency — which is why we’ve staked our future success on building ever simpler, more accessible controls and giving people clearer choices. And, just as important, doing more with less data.

*We welcome the opportunity to engage on this important topic with Europe’s consumer advocates and regulators. People should be able to understand how data is generated from their use of internet services. If they don’t like it, they should be able to do something about it.”

The company spokesman also argued that different options it presents when someone is creating a new Google account are “clearly labeled and designed to be simple to understand”. “We have based them on extensive research efforts and guidance from DPAs [data protection authorities] and feedback from testers. We are committed to ensuring these choices are clear and simple,” he added.

We asked Google which DPAs’ advice have fed into the design it uses for account creation.

Its spokesman told us: “We applied a layered approach to transparency in line with guidance from the EDPB [European Data Protection Board]: the guidance recognises that ‘layered and granular information can be an appropriate way to deal with the two-fold obligation of being precise and complete on the one hand and understandable on the other hand’.”

Repeat offender

This is not the first privacy-related complaint EU consumer rights have made about Google’s practices. They also raised a complaint focused on its collection of location data back in 2018 — but it took until February 2020 for Google’s lead EU data supervisor, Ireland’s Data Protection Commission (DPC), to start an inquiry. And, more than 2 years later, that data probe remains ongoing.

Back in May, the DPC’s deputy commissioner, Graham Doyle, told TechCrunch it was expecting to submit a draft decision on the Google location data inquiry to other DPAs for review “over the coming months.” However, if there is disagreement over Ireland’s approach, it could add many more months before agreement on a final consensus decision is reached. So a resolution of that long-running complaint may still not arrive this year.

The DPC also still hasn’t issued decisions on other long-running GDPR complaints against Google. Such as a major complaint about its adtech, which it began investigating in May 2019 — and is now being sued over for inaction.

Another complaint — against’s Google use of so-called forced consent on its Android mobile platform — dates back to May 2018, although it’s not clear if the DPC ever opened an inquiry in that case. France’s data protection watchdog, the CNIL, proceeded to investigate — and fined Google $57 million back in January 2019 over breaches of transparency and consent attached to how it operates Android. (The CNIL decided it had competence in that case since Android-related decisions were likely taken in the U.S., rather than in Dublin, where Google’s regional HQ is based.)

But Ireland has yet to issue a single GDPR decision against Google.

BEUC is not hiding its frustration at the DPC’s lack of enforcement over complaints against the tech giant.

“Google is a repeat offender,” said Pachl. “It is more than three years since we filed complaints against Google’s location-tracking practices and the Irish DPC in charge has still not issued a decision on the case. Meanwhile Google’s practices have not changed in essence. The tech giant still carries out continuous tracking and profiling of consumers and its practices set the tone for the rest of the market.”

“We need swift action from the authorities because having one of the biggest players ignoring the GDPR is unacceptable,” she added. “This case is of strategic importance for which cooperation among data protection authorities across the EU must be prioritised and supported by the European Data Protection Board.”

Issues around Google’s tracking of account users is separate to the advertising giant’s cookie-based tracking — where it deploys technologies to track users across third-party websites and apps.

The latter process has been the subject of other EU complaints that have led to some enforcements in recent years, with France’s data protection watchdog hitting Google with fines approaching $300 million for cookies tracking-related breaches under the bloc’s ePrivacy Directive — after which Google made some changes to the cookie consent banner it shows web users in Europe.

Strategic complaint

Pachl’s remark about the Google account sign-up complaint being of “strategic importance” refers to BEUC’s expectation that the case will trigger the launch of a procedure under the GDPR’s cooperation mechanism (i.e., Article 60), which it hopes will function more smoothly than it has been since 2018, when the Google location data complaint was filed.

The reason BEUC is hoping for smoother sailing now is because of an agreement EU DPAs reached in April — aka the “Vienna declaration” — when they committed to enhance their enforcement cooperation on cross-border GDPR cases of “strategic importance.”

A complaint against a tech giant like Google clearly hits that bar. But the older Google location data complaint has been saddled with a number of cooperation-related issues that have contributed to slowing down investigation and delaying a decision in that case.

Discussing what changes BEUC hopes to see being applied by regulators in tackling this fresh cross-border Google complaint, David Martin Ruiz, team leader for digital policy at the organization, told us: “We expect that the treatment of the complaints is prioritised as it touches upon practices by a major market player in the surveillance economy which affect millions of Europeans. The first time it took around 6 months just to name the lead authority. Also, we expect better, closer cooperation among the authorities, for example in terms of checking the admissibility of the complaints, and that this is done only once by the authority which receives the complaints. Of course, we expect that closer cooperation and strategic prioritisation by the authorities involved leads to a swift, comprehensive investigation of the complaints and efficient enforcement.”

Still, Ruiz declined to offer a prediction for how much faster the revised cooperation procedure will be able to deliver enforcement against Google, saying: “It is hard to put a concrete number on this but we certainly hope it takes less than the one that is ongoing, and we are not here 3 years from now still waiting for a draft decision.”

The European Commission, which has also been critical of adtech giants’ approach to compliance with EU privacy laws, recently defended slower regulatory enforcements in these major, cross-border cases.

In a letter to the European ombudsperson — which has been looking into the EU executive’s monitoring of the GDPR following complaints about the Commission’s own oversight of the regulation — justice commissioner, Didier Reynders, likened the level of complexity involved in these big investigations to antitrust cases, writing:

” … it is important to make a distinction between cases which are relatively straightforward and do not require extensive investigations and cases which require complex legal and economic assessment or pose novel issues. Those complex cases, for instance those touching on issues relating to the business model of big tech multinational companies, might require several months or years of investigations, similarly to what happens for competition law investigations. This is particularly relevant for Ireland since many of such companies have their main establishment in this Member State.”

Responding to Reynders’ point, Ruiz told TechCrunch: “We agree and understand that these are complex issues and the authorities need time to build strong cases. However, we have seen problems that go beyond the time it takes to investigate these cases (e.g., a DPA narrowing down the scope of complaints when deciding to open their own investigation). Moreover, a lot of the big complaints that are taking years are actually not normal complaints, in the sense that they come already backed with a lot of legal analysis and factual evidence, aiming to facilitate the tasks of the DPAs. Also, of course, the time it takes to resolve these cases is also an illustration of deeper issues, like a lack of sufficient resources. Hopefully, strengthened cooperation and strategic prioritisation, as per the Vienna declaration, will help reduce the time it takes to investigate these cases. Complexity and the time it takes to investigate cannot be an excuse for inaction.”

BEUC isn’t calling for major revisions to GDPR to solve the problem of timely enforcement against Big Tech. But it is pushing for DPAs to make a whole series of process changes, individually and collectively, in order to address issues like the bottleneck of cases linked to the regulation’s one-stop-shop/lead data supervisor structure, which has enabled the problem of forum shopping.

“In a nutshell, regarding Big Tech, the first step is to stop the ‘bottleneck,’” he said. “Basically, DPAs, in particular one DPA which has oversight over many of the Big Tech companies, needs to deliver decisions on the open cases. And both the lead DPA, and the rest of the DPAs in the EDPB, need to be strict and ambitious in their interpretation and application of the rules. Also, if the lead DPA is not delivering the decisions, the others must make full use of their powers and take urgent measures. There needs to be a clear signal to Big Tech that window dressing and cosmetic transparency measures won’t do anymore. There are some fundamental issues in their core business practices that must be addressed, because they run contrary to the very essence of the GDPR.”

“Of course it is a concern that enforcement does not move as fast as market practices, and companies are changing things all the time. It is very important to underline that a company tweaking and correcting something should not erase past infringements and leave them unpunished, especially if they have been going on for years and they have affected millions of people. Otherwise, it is a very dangerous signal we are sending to companies,” he added. “We would be telling them ‘it is ok to infringe the GDPR as long as you are not caught, and if you are caught, just fix it quickly and there will be no consequences.’ This is the opposite of what should happen. Infringements must have consequences. Otherwise there is no justice, and no deterrent effects.”

This report was updated with responses from Google

Google’s location tracking finally under formal probe in Europe

GDPR enforcement must level up to catch big tech, report warns

More TechCrunch

While funding for Italian startups has been growing, the country still ranks eighth in Europe by VC investment, according to Dealroom. Newly created Italian Founders Fund (IFF) hopes to help…

With €50 million to invest, Italian Founders Fund looks for entrepreneurs with global ambitions

William A. Anders, the astronaut behind perhaps the single most iconic photo of our planet, has died at the age of 90. On Friday morning, Anders was piloting a small…

William Anders, astronaut who took the famous ‘Earthrise’ photo, dies at 90

You’re running out of time to join the Startup Battlefield 200, our curated showcase of top startups from around the world and across multiple industries. This elite cohort — 200…

Startup Battlefield 200 applications close tomorrow

New York’s state legislature has passed a bill that would prohibit social media companies from showing so-called “addictive feeds” to children under 18, unless they obtain parental consent. The Stop…

New York moves to limit kids’ access to ‘addictive feeds’

Dogs are the most popular pet in the U.S.: 65.1 million households have one, according to the American Pet Products Association. But while cats are not far off, with 46.5…

Cat-sitting startup Meowtel clawed its way to profitability despite trouble raising from dog-focused VCs

Anterior, a company that uses AI to expedite health insurance approval for medical procedures, has raised a $20 million Series A round at a $95 million post-money valuation led by…

Anterior grabs $20M from NEA to expedite health insurance approvals with AI

Welcome back to TechCrunch’s Week in Review — TechCrunch’s newsletter recapping the week’s biggest news. Want it in your inbox every Saturday? Sign up here. There’s more bad news for…

How India’s most valuable startup ended up being worth nothing

If death and taxes are inevitable, why are companies so prepared for taxes, but not for death? “I lost both of my parents in college, and it didn’t initially spark…

Bereave wants employers to suck a little less at navigating death

Google and Microsoft have made their developer conferences a showcase of their generative AI chops, and now all eyes are on next week’s Worldwide Developers Conference, which is expected to…

Apple needs to focus on making AI useful, not flashy

AI systems and large language models need to be trained on massive amounts of data to be accurate but they shouldn’t train on data that they don’t have the rights…

Deal Dive: Human Native AI is building the marketplace for AI training licensing deals

Before Wazer came along, “water jet cutting” and “affordable” didn’t belong in the same sentence. That changed in 2016, when the company launched the world’s first desktop water jet cutter,…

Wazer Pro is making desktop water jetting more affordable

Former Autonomy chief executive Mike Lynch issued a statement Thursday following his acquittal of criminal charges, ending a 13-year legal battle with Hewlett-Packard that became one of Silicon Valley’s biggest…

Autonomy’s Mike Lynch acquitted after US fraud trial brought by HP

Featured Article

What Snowflake isn’t saying about its customer data breaches

As another Snowflake customer confirms a data breach, the cloud data company says its position “remains unchanged.”

2 days ago
What Snowflake isn’t saying about its customer data breaches

Investor demand has been so strong for Rippling’s shares that it is letting former employees particpate in its tender offer. With one exception.

Rippling bans former employees who work at competitors like Deel and Workday from its tender offer stock sale

It turns out the space industry has a lot of ideas on how to improve NASA’s $11 billion, 15-year plan to collect and return samples from Mars. Seven of these…

NASA puts $10M down on Mars sample return proposals from Blue Origin, SpaceX and others

Featured Article

In 2024, many Y Combinator startups only want tiny seed rounds — but there’s a catch

When Bowery Capital general partner Loren Straub started talking to a startup from the latest Y Combinator accelerator batch a few months ago, she thought it was strange that the company didn’t have a lead investor for the round it was raising. Even stranger, the founders didn’t seem to be…

3 days ago
In 2024, many Y Combinator startups only want tiny seed rounds — but there’s a catch

The keynote will be focused on Apple’s software offerings and the developers that power them, including the latest versions of iOS, iPadOS, macOS, tvOS, visionOS and watchOS.

Watch Apple kick off WWDC 2024 right here

Welcome to Startups Weekly — Haje’s weekly recap of everything you can’t miss from the world of startups. Anna will be covering for him this week. Sign up here to…

Startups Weekly: Ups, downs, and silver linings

HSBC and BlackRock estimate that the Indian edtech giant Byju’s, once valued at $22 billion, is now worth nothing.

BlackRock has slashed the value of stake in Byju’s, once worth $22 billion, to zero

Apple is set to board the runaway locomotive that is generative AI at next week’s World Wide Developer Conference. Reports thus far have pointed to a partnership with OpenAI that…

Apple’s generative AI offering might not work with the standard iPhone 15

LinkedIn has confirmed it will no longer allow advertisers to target users based on data gleaned from their participation in LinkedIn Groups. The move comes more than three months after…

LinkedIn to limit targeted ads in EU after complaint over sensitive data use

Founders: Need plans this weekend? What better way to spend your time than applying to this year’s Startup Battlefield 200 at TechCrunch Disrupt. With Monday’s deadline looming, this is a…

Startup Battlefield 200 applications due Monday

The company is in the process of building a gigawatt-scale factory in Kentucky to produce its nickel-hydrogen batteries.

Novel battery manufacturer EnerVenue is raising $515M, per filing

Meta is quietly rolling out a new “Communities” feature on Messenger, the company confirmed to TechCrunch. The feature is designed to help organizations, schools and other private groups communicate in…

Meta quietly rolls out Communities on Messenger

Featured Article

Siri and Google Assistant look to generative AI for a new lease on life

Voice assistants in general are having an existential moment, and generative AI is poised to be the logical successor.

3 days ago
Siri and Google Assistant look to generative AI for a new lease on life

Education software provider PowerSchool is being taken private by investment firm Bain Capital in a $5.6 billion deal.

Bain to take K-12 education software provider PowerSchool private in $5.6B deal

Shopify has acquired Threads.com, the Sequoia-backed Slack alternative, Threads said on its website. The companies didn’t disclose the terms of the deal but said that the Threads.com team will join…

Shopify acquires Threads (no, not that one)

Featured Article

Bangladeshi police agents accused of selling citizens’ personal information on Telegram

Two senior police officials in Bangladesh are accused of collecting and selling citizens’ personal information to criminals on Telegram.

3 days ago
Bangladeshi police agents accused of selling citizens’ personal information on Telegram

Carta, a once-high-flying Silicon Valley startup that loudly backed away from one of its businesses earlier this year, is working on a secondary sale that would value the company at…

Carta’s valuation to be cut by $6.5 billion in upcoming secondary sale

Boeing’s Starliner spacecraft has successfully delivered two astronauts to the International Space Station, a key milestone in the aerospace giant’s quest to certify the capsule for regular crewed missions.  Starliner…

Boeing’s Starliner overcomes leaks and engine trouble to dock with ‘the big city in the sky’