Live data from Hacker News

GDPR penalty for passing on of IP address to Google by using Google Fonts

rewis.io

141–150 of 656 posts

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#142
post #80

Earlier quoted context omitted.

that is true but it increases the barrier to entry for those who use google fonts for system resource issues, a lot of people offload because they don’t have the space or money to self host everything one could argue that it is less eco friendly as well given how much space is going to be used repeating the same file on a multitude of servers

A $5 VPS comes with several gigabytes of storage. A standard web font (e.g. Roboto) is ~1MB. Bandwidth is essentially free through CloudFlare. Who doesn't have the space or money to self-host their fonts?

Is it really better to tunnel your whole site through CloudFlare than embed a font from Google, from a privacy perspective?

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#143

Reductio ad absurdum: if serving fonts from Google is “unnecessary” and leaks information, so would be using any CDN service to deliver any content.

It unquestionably leaks information, and it is why projects like Decentraleyes exist.

Whether it is "unnecessary" is the interesting question. For fonts, it's really hard to claim that you couldn't have created the website without Google's fonts CDN.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#144

Earlier quoted context omitted.

Keyword: per default . It's an opt-out, GDPR requires an opt-in.

People who created the browser are not processing any data when you use the browser, so GDPR hardly applies. They need to be careful with bug reports, but that's it.

Of course, I am following the logic where it goes.

Now, why would website operators be considered data processors for providing a link to google fonts to website users ? The website is not leaking the IP, it doesn't need if to display fonts and it doesn't use visitor's IP to display fonts. Ultimately the user of the browser is using his IP to get the fonts and this user is the one responsible for leaking his IP.

The website has delivered an HTML document. It's up to the user to do what he wants with it and follow links or not.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#145
post #34
post #6

german law doesn't really know "precedent cases". However it looks like a whole new industry of lawyers sueing pages embedding stuff could arise...

Leaking customer data to Cloudflare is also a very interesting question here.

What about "leaking" the IP to your server provider and all the networks between your user and site?

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#146
post #109

The ruling says the website owner illegally shared the user’s IP address with Google. AFAIK, this is an incorrect interpret of events. The website merely tells the user’s browser that the content is intended to be displayed using a font that, if not installed on the user’s computer, can be downloaded from Google’s server. It is the the user’s browser that initiates a request to Google’s server. A request by the websi…

The end result is that the fact that you visited this website is passed to Google, and this can then be used for advertising purposes.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#147
post #2

After translating - the violation here is a website included third-party fonts from Google, and the fact that Google would be able to see their IP from the request violates GDPR? Seems as though anybody who uses a CDN or third-party to load _any_ resources will violate GDPR by this measure? Seems like a pretty wide interpretation of this law.

It seems like if there were a data processing agreement with Google that they don’t process the IP for web fonts it would be fine too.

Yes, I also think that.

From this site [0]:

"Virtually every business relies on third parties to process personal data. Whether it’s an email client, a cloud storage service, or website analytics software, you must have a data processing agreement with each of these services to achieve GDPR compliance."

[0]: https://gdpr.eu/what-is-data-processing-agreement/

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#148
post #109

The ruling says the website owner illegally shared the user’s IP address with Google. AFAIK, this is an incorrect interpret of events. The website merely tells the user’s browser that the content is intended to be displayed using a font that, if not installed on the user’s computer, can be downloaded from Google’s server. It is the the user’s browser that initiates a request to Google’s server. A request by the websi…

Using this logic I can send full fingerprinting data as long as I do it from the front-end? I mean courts are not that dumb, it's still the website owner which decides what is done.

The website owner decides what's asked to be done. The browser is still owned by the end-user can choose to make the request. This is why ad-blocking is fundamentally required.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#149
post #98

So an HTTP GET request to another domain (fonts.googleapis.com) "leaked" website visitor's IP address to Google. What the hell? Google Translate: https://rewis-io.translate.goog/urteile/urteil/lhm-20-01-202... > The defendant is sentenced to pay the plaintiff €100.00 > The plaintiff has a claim against the defendant to refrain from passing on the plaintiff's IP addresses to Google under Section 823 (1) in conjunction…

Why do you think google fonts exist? For google to Get visitor IP all over the web without any form of user consent, this is exactly what the gdpr tries to kill.

Nah, it's charity, come on. /s

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#150
post #2

After translating - the violation here is a website included third-party fonts from Google, and the fact that Google would be able to see their IP from the request violates GDPR? Seems as though anybody who uses a CDN or third-party to load _any_ resources will violate GDPR by this measure? Seems like a pretty wide interpretation of this law.

There are some important points to mention: * the court explicitly stated that this case was about transferring personal data (the IP) without prior consent. If the user had consented, there would have been no case. * the court explicitly criticized using google, because google a) is known to collect user information and b) google is a US company and the European courts have found the US is lacking in privacy laws. S…

So, soon on top of all the cookie notices that are already there, we are also going to have to consent initially before anything loads to downloading the javascript from 3rd party to manage all the consents? Lol.... Just what the internet needs...
Post reply on HN