Live data from Hacker News

GDPR penalty for passing on of IP address to Google by using Google Fonts

rewis.io

491–500 of 656 posts

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#491

Earlier quoted context omitted.

You could just link to YouTube and not embed the video. I think the important part is that this is an issue, only because companies like have had a surprising hard time not misusing every single bit of information sent their way. The result is that companies have forced governments to step in and now they are overregulating.

But if you link and your browser preloads links to speed up browsing, then your IP address would still be leaked.

If you specify preload=yes or other take any steps whatsoever to promote preloading of the (non-GDPR) YouTube link, then you would definitely be responsible for the user’s IP leaking to a non-GDPR site, and risk owing fines under GDPR.

If you do not request preload behavior, then you’re just linking another site on the web, and users are considered to understand that links go to other sites, and that’s acceptable. A theoretical GDPR complaint would find that the user agent was responsible for the behavior, not you as site operator.

(I am not your lawyer, this is not legal advice.)

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#492

Earlier quoted context omitted.

I see quite a few web pages in Germany that do not load JavaScript or any other content from YouTube,Twitter, Facebook until you explicitly opt in. Basically, the content is replaced by a placeholder saying “click here to load external content from.” - it’s technically not very hard to do so, and I quite like it. I don’t need to be tracked by any of those entities everywhere I go. Tracking and creating profiles is on…

> it’s technically not very hard to do so, and I quite like it For the average user, it's yet another thing to click without thinking, just to be able to visit a page. > Consent is required before exposing the IP address and is must be explicitly given There's the crux of the problem, it's difficult to know what to consent for without first displaying the website, so you implicitly give consent for "just the bare min…

> > it’s technically not very hard to do so, and I quite like it

> For the average user, it's yet another thing to click without thinking, just to be able to visit a page.

And yet, they’re still protected: They’ll click on the video when they want to watch the video, load the like button when they want to like, the tweet button when they want to tweet. And all the other times when they visit a website that offers any of this functionality, no data is transmitted to YouTube, Facebook, Twitter.

> This sounds great, but is both an absolute nightmare for website developers (it's not very easy to do, with how the internet was designed, inline scripts, fonts, CDN stylesheets

There is no need to ask for consent for every Stylesheet you load from a CDN. You’re allowed to use cloudflare, cloudfront, fastly,… - they’ll all provide the required DPA that allows you to use them without consent. You need to be careful when it comes to things like like-buttons etc. that get loaded from places that use them to create user profiles for non-consenting users. Yes, that’s hard. But the culprits are the entities that siphon up every bit of data. Direct your ire there.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#493

Earlier quoted context omitted.

There’s an easier way than that: embed from youtube-nocookie.com. Of course that doesn’t necessarily help with the Munich ruling…

IP information will still be sent to Google, and a notice would have to put up before. Easiest way to deal with this is to self-host the videos. Most people over-estimate how popular their websites are, and for the ones who don't, getting a dedicated instance with unmetered bandwidth is trivial to get and setup for video-hosting.

It is not in any way trivial to self-host video these days.

In the past when video was a novelty and no one had any real expectation of performance or quality, it didn’t matter much because expectations were low.

But so much work has been done since on reliability/performance/network efficiency and very few products can provide that. Without that work, people will think your player is broken, you will waste mobile traffic, etc. Even Reddit can’t get it right and they are a top 10 website.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#494
post #331

Earlier quoted context omitted.

Using a third party is not illegal in itself. But you need an agreement with the third party as to how they will store/process any user data they collect. This is fairly fundamental under GDPR. It's the 'data controller'/'data processor' split. I suspect (but IANAL of course) that most CDNs would fail here, because the blanket agreements they offer are basically worthless. But it's easy to imagine a CDN that has a di…

How can a CDN fail to retain an IP address, at least for the purposes of knowing where to send the response? The ruling doesn't say that Google stored the IP, causing the issue, but merely that the user's IP showed up in a packet sent to Google.

Storing an IP address in RAM until you have sent the response is _obviously_ a technically necessary use of personal data.

But who knows what else google does? The "privacy info" for site owners using google fonts says nothing about what they use any collected data for.

When you share personal data about your visitors with a data processor, you need an agreement that specifies how that data is treated.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#495
post #109

The ruling says the website owner illegally shared the user’s IP address with Google. AFAIK, this is an incorrect interpret of events. The website merely tells the user’s browser that the content is intended to be displayed using a font that, if not installed on the user’s computer, can be downloaded from Google’s server. It is the the user’s browser that initiates a request to Google’s server. A request by the websi…

GDPR specifies otherwise than your interpretation, logical as yours may be from a technical standpoint.

The site operator chose an optional way to embed fonts in a way that divulges PII to a non-GDPR destination. As there is no legal or technical requirement to embed Google Fonts, the site operator is therefore liable.

If use of Google Fonts was mandatory for the web to function, then the site operator would not have been found liable. It is not: they can be mirrored locally, or simply not used, and the web as viewed from the user’s perspective will continue to function just fine. (IANYL, etc.)

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#496

Earlier quoted context omitted.

Yes, but the website ordered your browser to contact Google without informing you, for no obvious purpose. That's not exactly how consent works.

The web site did no such thing -- it served up a document that contained the reference. It is the end user that CHOSE to delegate interpretation of that document to a web browser (ad a counter example, look at how RMS browses the web). Yes this is less practical. But since the decision only deals with what is "possible", then logically it should be fully consistent. Now from a practical standpoint, I'd like to see a…

We had two: https://en.m.wikipedia.org/wiki/P3P, https://en.m.wikipedia.org/wiki/Do_Not_Track

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#497

Earlier quoted context omitted.

The "annoying" popups is also how you end up with businesses like plausible analytics that provide analytics, but don't require the popup, because they dont store the information that causes the popup to be required. So, working as intended I think.

Have you browsed the internet recently? We were better off 15 years ago

We were not better off 15 years ago. We were just blissfully unaware of the problem of large-scale PII collection that was already metastasizing in the shadows.

Imagine a kind of decision square. Rows are "consciously" and "unconsciously", Columns are PII collection, and privacy (no PII collection) .

This gives us a list of 4 possible scenarios (from least to most desirable). 1. unconscious privacy, 2. unconscious PII collection , 3. conscious PII collection, 4. conscious privacy

In detail (least to most desirable situation)

Box 1: Early internet everyone had unconscious privacy. No one was collecting PII, and no one was aware of it.

Box 2: Early 21st century, people started collecting PII at an ever increasing (and frankly alarming) rate. You may have encountered tall tales where people got sent baby advertisements before they themselves even knew they were pregnant.

Box 3: The goal of the GDPR, shine a light on the situation and make everyone conscious that there is a problem; and unveil the extent.

Box 4 (future): fix the underlying problem.

GDPR already addresses box 4 a little bit. Just by shining a light on these practices, some of the slightly shady bits at the edges are already solved.

Now that the situation is visible and known, we can take further political steps at mitigation.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#498

Earlier quoted context omitted.

This ruling will 100% be upheld in the higher courts. The website is arguing that they have a legitimate interest in downloading fonts from Google in client browser, but as the court correctly states the website can provide these fonts directly. There is no reason to infringe on the user privacy, so there is no legitimate interest. And therefore use of Google fonts was without a legal basis. BTW - The website could h…

I'm not a layer (web dev in my spare time), but how far does "provide more directly" go? A private ISP? There's no limit, only what seems to be considered by the courts as "reasonable". Then again, that is how law is interpreted most of the time, no?

When you do anything with personal data in the EU you have to have a legal basis.

There are 6 and only 6 possible legal basis: https://gdpr-info.eu/art-6-gdpr/

But most businesses will be choosing from:

- the data subject has given consent to the processing of his or her personal data for one or more specific purposes;

- processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;

- processing is necessary for compliance with a legal obligation to which the controller is subject;

- processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

You can do basically anything with things like IP addresses as long as you have valid consent from the client i.e. they need to actually know, or at at least be able to learn, what you are doing with their data and decide that it is ok. So, no guessing here, just be transparent, and assume no consent by default.

In case of ISP they have to process your personal data because it is necessary for the performance of a contract of providing the internet service. Also, no guessing here.

The legitimate interest clause is a "catch all" clause for anything that legislator did not think about, so it is very vague by design. You do not want to choose this as a legal basis for data processing if you do not want to deal with legal uncertainty. But if you do choose it, you should have strong arguments that you really need this legal basis.

If similar companies to yours are able to do exactly the same thing in a way that is less impactful on privacy then you can expect that courts will not grant you a legitimate interest.

You can also do legal tests do determine whether you have a legitimate interest:

- The purpose test (identify the legitimate interest);

- The necessity test (consider if the processing is necessary); and

- The balancing test (consider the individual’s interests).

See more detail here: https://ico.org.uk/for-organisations/guide-to-data-protectio...

Also, based on my observation if you are not doing anything really egregious and you are willing to cooperate with data protection agencies (DPA) you do not have to worry about anything. If DPA decides you are doing something wrong they will tell you about it. And if you just adjust, like start to host fonts on your servers, they will let it slide or give you a small slap on the wrists. The really high fines are reserved for malicious conduct or gross incompetence with actual harm already done to people.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#499
post #470

Earlier quoted context omitted.

If you've ever had the pleasure of dealing with the licensing nightmare of foundries, it's quite easy to see that a small group within google had enough and started the project. We've literally spend tens of thousands of dollars on our font archive, but decided that we can't continue to use these fonts on projects anymore, due to "we can change the licence at any time" clauses and rent seeking behaviour, that is eeri…

But there is nothing that prevents anybody to build a similar product but charging a fee for it. The payment being "user data" is the problem. Not the product in and of itself. If you are in the EU such a platform would probably need to be GDPR compliant. I'm sure there is a opportunity for a font market that fulfills your needs. It might not be easy but eventually studios like you will probably have to charge client…

With all due respect, your response doesn't make much sense.

Google fonts is primarily a github repo with specifically licenced fonts. Google paid a lot of the artists and foundries behind these fonts for an open licence.

Therefor there is no need to build a "similar product", when the existing one is alrady free as in free beer, without any hidden data-/ad-funding.

We are are primarily a PRINT-MEDIA shop. Non of GDPR applies to this, non of our customers or customer clients pay for anything with their data, because paper doesn't have an uplink. Yet the google font project is as much key to our survival as sci-hub is for the scientific community.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#500

Reductio ad absurdum: if serving fonts from Google is “unnecessary” and leaks information, so would be using any CDN service to deliver any content.

Using a CDN service operated by a non-GDPR business such as Cloudflare, Google, Amazon, or Akamai could potentially be confirmed to be a violation of GDPR, yes, if the CDN-hosted resources are used without opt-in. I’m eagerly awaiting the first complaint on these grounds to be reviewed and judged, now that the GDPR treaty with the United States has lapsed. It doesn’t matter where the CDN’s servers are; without the US having signed a treaty into law, each of their businesses are subject to compulsion by various US authorities to dishonor their commitments to the GDPR.
Post reply on HN