As a Deutscher this sounds completely nuts. Correct me if I'm wrong but any not 100% technically necessary third party request is considered illegally leaking personal data?! Or do I 'just' have to inform the users that their fonts, images and other data that could be stored in source but is not? In the case of fonts I'm pretty sure they get cached in the browser, so bundling them with the source just doesn't make se…
1. In Germany an IP address is considered PI under GDPR because it is easily associated to a natural person.
2. Google is open about the fact that they log IP address with Google Font request activity, which includes the page you are on.
3. GDPR requires justification by necessity to collect and/or send PI to a 3rd party without consent.
4. No consent was given.
5. It is not necessary in this case because it is possible to use Google Fonts in other ways that don't send PI to Google, without significant burden.
I'm not a lawyer but I am responsible for GDPR compliance at a German startup.
edit: typo