UK: Google Wi-Fi collection violated data protection laws
IDG News Service - The U.K.'s data protection watchdog said today that Google violated the law with its Street View Wi-Fi collection program, but it is letting the company off with a warning and not imposing a fine.
The latest development marks a change in position for the Information Commissioner's Office (ICO), which said earlier this year that Google only appeared to have breached data protection requirements. It declined to take further action after Google agreed to delete the data.
Google said in May that it had collected information on unencrypted Wi-Fi routers, including fragments of data transmitted by those routers. The purpose of the data collection -- which occurred as its Street View imagery vehicles were cruising streets in many countries -- was to improve a geo-location database for location-based mobile applications.
Google denied the data could be traced back to an individual. But the company said on Oct. 22 that an examination of the data by seven external regulators have now shown that in some instances entire e-mails and URLs were collected along with some passwords.
Earlier this year officials from the ICO who viewed a sample of the collected data apparently missed the fact that some of it could be traced back to specific people. They concluded "that the data as fragmentary and was unlikely to constitute personal data" and declined to take further action.
ICO officials looked at parts of the data that was provided by Google and also did their own random sampling, but did not find information that constituted personal data, according to an ICO spokesman.
It is not known which regulatory agency in the 30 countries examining the Street View data discovered the full e-mails and passwords, although it should eventually be revealed, the ICO spokesman said.
The ICO declined to impose a fine, saying that the majority of the data was collected by Google prior to April 6, the day the agency gained the power to fine organizations that break the Data Protection Act of 1998 up to £500,000 ($800,000).
"Monetary penalties can only be served when a strict set of criteria is satisfied, including that the breach was likely to cause substantial harm or substantial distress -- this alone would be very hard to prove in this case," according to an ICO statement.
To satisfy the ICO, Google will be subject to an audit within nine months by the ICO and must sign a document saying they will face further action unless the company takes steps to ensure data is protected.
The ICO has mandated that the company must put programs in place to train employees on data protection and the law, train engineers on the handling of data and start a security awareness program, among other requirements.
The Wi-Fi collection program remains under investigation by agencies in several countries. In Germany, Hamburg's Data Protection Authority (DPA) and the city's prosecutor's office continue to examine the data and whether collecting it broke German laws.
Last month, Spain's Data Protection Agency said it is investigating Google for up to five infractions of its laws over the collection of Wi-Fi data, for which the company could face more than $417,000 in fines. In August, South Korean police raided Google's offices and launched an investigation into unauthorized data collection and illegal wiretapping.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Practice Management: Double Billing Rate and Improve Patient Services
- Would you like to double your billing rate and achieve faster payment for services?
Download this customer success story to see how One Health... - Mission Critical Data Explosion and Customer Case Study
- Would you like to double your tier 1 storage capacity while simultaneously reducing your storage footprint?
Download this customer success story to see how... - Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
- Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
- Database Activity Monitoring Is Evolving
- Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.
- Establishing a Strategy for Database Security is No Longer Optional
- The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three... All Gov't Legislation/Regulation White Papers
- Distributed Database Security with Real-time Monitoring
- View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
- InfoSphere Warehouse Packs Demo
- These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
- Delivery Management -- Extending Lifecycle Management
- Date: Wednesday, June 20, 2012, 1:00 PM EDT
Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,... - Leverage automation today to reduce IT complexity
- Date: Tuesday, June 5, 2012, 2:00 PM EDT
Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific... - Redefine Expectations in the Data Center
- Need to do more with less? Watch this video to learn how HP ProLiant Gen8 servers can help your business deploy servers three... All Gov't Legislation/Regulation Webcasts