Don’t do SECURITY. Do business SECURELY.

Google admits Street View cars collected Wi-Fi payload data

Google admitted its Street View cars had mistakenly collected data sent over open Wi-Fi networks, triggering investigations worldwide.

Google admitted that its Street View cars had been collecting samples of payload data from open, non-password-protected Wi-Fi networks, not just network names and hardware addresses. The disclosure followed a request from the Hamburg data protection authority to audit the data the cars had gathered.

What happened

  • Google said code written in 2006 for an experimental Wi-Fi project had been included in Street View software without project leaders’ knowledge.
  • The cars had been collecting the data for several years across many countries before the admission.
  • Google grounded the Street View cars, segregated the data, and said it would stop collecting Wi-Fi data with them.
  • Data protection regulators in Europe and elsewhere opened investigations, and it later emerged that some collected data included emails, URLs, and passwords.

Why it mattered

The episode became a defining example of how an engineering decision can create a large-scale privacy breach, and it drove years of regulatory action against Google in several countries.

Lessons for organisations

Review new data collection at the design stage with a data protection impact assessment, and apply data minimisation so systems only collect what the stated purpose needs. Code review and change control should catch features that quietly gather personal data.

Sources: TechCrunch, The Register

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with a link to our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights