Live data from Hacker News

GDPR penalty for passing on of IP address to Google by using Google Fonts

rewis.io

531–540 of 656 posts

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#531
post #317

Earlier quoted context omitted.

It seems pretty reasonable to me. 1. In Germany an IP address is considered PI under GDPR because it is easily associated to a natural person. 2. Google is open about the fact that they log IP address with Google Font request activity, which includes the page you are on. 3. GDPR requires justification by necessity to collect and/or send PI to a 3rd party without consent. 4. No consent was given. 5. It is not necessar…

By that logic you must self-host any landing page, otherwise you are leaking IP addresses to whoever is hosting your website.

We have a contract with our hosting provider that specifies what data they may collect, the limited purposes for which they can use it, and when it must be deleted.

This is called a Data Processing Agreement and is also part of GDPR compliance.

We have the same thing in place with all 3rd party vendors.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#532
post #262

Earlier quoted context omitted.

This case is about IP address exposure, not cookies. This would still happen. So everyone showing youtube videos would be affected unless users also start agreeing to IP exposure… this could probably be avoided by extending the sites terms.

I think these are the wrong solutions. What they're trying to do is to desperately hold on to doing "business as usual". Just now with a CYA fig leaf, and do I detect a hint of possibly a dash of malicious compliance? What the EU actually wants to accomplish is to set a standard where people do business in a different (safer/higher quality/more ethical) way[1]; which many believe is both better for consumers and for…

Sounds like ipv8 is needed to address this. :D

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#533
post #262

Earlier quoted context omitted.

This case is about IP address exposure, not cookies. This would still happen. So everyone showing youtube videos would be affected unless users also start agreeing to IP exposure… this could probably be avoided by extending the sites terms.

> So everyone showing youtube videos would be affected unless users also start agreeing to IP exposure Yes, and that's a good thing! A web page should only communicate with the server i've reached, there should be zero third-party involved unless i explicitly consent. That for example tag can use an arbitrary URL is explained by the fact that back in the day storage/bandwidth was expensive. The same is true for video…

Are you sure about the „explicitly“ part? I think it in certain cases, implicit consent should be enough, e.g. when a payment processor is contacted from a website. Even if you were running your own payment gateway, the user of your shop should be aware that the website will have to share information with their bank or credit card company. I think sharing data with third parties should not be easier than offline, but also not harder. Or do you sign a consent form each time you swipe your CC?

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#534
post #525

Earlier quoted context omitted.

I think these are the wrong solutions. What they're trying to do is to desperately hold on to doing "business as usual". Just now with a CYA fig leaf, and do I detect a hint of possibly a dash of malicious compliance? What the EU actually wants to accomplish is to set a standard where people do business in a different (safer/higher quality/more ethical) way[1]; which many believe is both better for consumers and for…

Strong disagree. This is more to me like Germany having jack all of a tech sector and trying their hardest to drag the rest of the world to their level.

This is a policy that is EU wide.

Why single out Germany? Do you have experience doing business there?

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#535
post #533

Earlier quoted context omitted.

> So everyone showing youtube videos would be affected unless users also start agreeing to IP exposure Yes, and that's a good thing! A web page should only communicate with the server i've reached, there should be zero third-party involved unless i explicitly consent. That for example tag can use an arbitrary URL is explained by the fact that back in the day storage/bandwidth was expensive. The same is true for video…

Are you sure about the „explicitly“ part? I think it in certain cases, implicit consent should be enough, e.g. when a payment processor is contacted from a website. Even if you were running your own payment gateway, the user of your shop should be aware that the website will have to share information with their bank or credit card company. I think sharing data with third parties should not be easier than offline, but…

The GDPR does not require consent for everything. It allows processing data that’s required to provide the desired functionality and payment processors would be covered (IANAL, to take with a grain of salt) You’d still need to mention that in the pages privacy policy, but other than that you should be fine, as long as you have the proper paperwork in place (DPA,…) and the payment processor is themselves GDPR compliant.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#536
post #102

Earlier quoted context omitted.

> not forced to follow the instructions Again, you're talking about an opt-out. GPDR (the law) requires an opt-in.

> Again, you're talking about an opt-out. GPDR (the law) requires an opt-in. It is opt-in. You decided to use a browser that implements the full HTML spec. Just use a basic browser.

"Your honor, the victims of my ransomware attack decided to use a modern CPU to run my code. The attack would not have succeeded have the victims used Z-80, so there's no one to blame but the victims themselves."

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#537
post #95

Earlier quoted context omitted.

I think there is not. You are not allowed to download the video and host it yourself, that would be a copyright violation. Am I missing a legally valid way?

Okay but let’s say you have permission to host the content — e.g: you actually own the video. Do you still think it’s reasonable that it should be a legal requirement that to embed a video on your web page you must develop your own video delivery infrastructure?

You pay for that content delivery by selling the users data to Google. Do you think that is fair that the user should pay for your video hosting with his data? If the user wants to see the video, sure, but that hasn't been made clear yet at this stage.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#538
post #128
post #101

Earlier quoted context omitted.

The website tried to rely on legitimate interest as the legal basis for processing the data, and that precisely requires a balancing test between the interests of the website host and the interests of the data subject. If you want to make sure that you're not getting the balancing test wrong, you can always go for the legal basis of last resort: consent. Just ask the user whether you can load content from Instagram a…

> In fact, since in parallel to the question of your legal basis under GDPR, you also have to comply with the cookie provision from the e-Privacy Directive, where there is no "legitimate interest" exception to the requirement to ask for consent, you will have to ask for consent anyway (as Instagram embeds place cookies). I don't think that's true. The cookie provision is misunderstood when you think you have to ask f…

Careful. That is an 100% unofficial site. It is not chartered or funded by the EU. The linked article is from “Richie Koch”an editor working on human rights stories who wrote the article on behalf of Proton VPN, which runs the GDPR.eu site as a content marketing scheme. The linked article is not the law and not official guidance, though it provides a reasonably good summary.

Everything sqrt2 says in the comments is entirely correct, as far as I can tell.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#539

Earlier quoted context omitted.

>> This is exactly what happened... Not quite? Wouldn't the users browser have sent its own IP address to Google? That's different that "forwarding" it, and it may not even be enough for Google to connect the user to that site.

Yes, but the website ordered your browser to contact Google without informing you, for no obvious purpose. That's not exactly how consent works.

1) google won't know what site told the browser to do that.

2) this is probably more of a browser issue than a site issue.

3) the reason browsers dont complain about content coming from different domains is because the entire ad industry depends on that behavior. That may need to stop ;-)

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#540

Can you someone translate? Does this mean that hot linking any static media or asset from a third party is against the law unless explicit approval from the user is first received?

No. This means that embedding any resource from a non-GDPR destination URL is a violation of GDPR law unless explicit opt-in approval from the user is first received. If you are subject to GDPR law, then the above applies to all sites owned and operated by you and your subsidiaries. If you are not subject to GDPR law, then the above does not apply. Resources could be hosted by http:, https:, ftp:, or any other protoc…

> the user has a right to legal protection if they are a citizen of a GDPR-protected country and are residing in a GDPR-bound country, regardless of what their IP address is.

Nit pick: GDPR is written in terms of people "in the Union", not citizens.

Post reply on HN