Google admitted that its Street View cars had been collecting samples of payload data from open, non-password-protected Wi-Fi networks, not just network names and hardware addresses. The disclosure followed a request from the Hamburg data protection authority to audit the data the cars had gathered.
What happened
- Google said code written in 2006 for an experimental Wi-Fi project had been included in Street View software without project leaders’ knowledge.
- The cars had been collecting the data for several years across many countries before the admission.
- Google grounded the Street View cars, segregated the data, and said it would stop collecting Wi-Fi data with them.
- Data protection regulators in Europe and elsewhere opened investigations, and it later emerged that some collected data included emails, URLs, and passwords.
Why it mattered
The episode became a defining example of how an engineering decision can create a large-scale privacy breach, and it drove years of regulatory action against Google in several countries.
Lessons for organisations
Review new data collection at the design stage with a data protection impact assessment, and apply data minimisation so systems only collect what the stated purpose needs. Code review and change control should catch features that quietly gather personal data.
Sources: TechCrunch, The Register
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.