Live data from Hacker News

GDPR penalty for passing on of IP address to Google by using Google Fonts

rewis.io

581–590 of 656 posts

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#581

Earlier quoted context omitted.

Depending on the circumstances, telling people to jump from the bridge can be a crime.

Ok, don't jump from a bridge. Take off your clothes, and go to your neighbors, I'm asking you right now. Are you going to comply?

Another thing came to mind.

Let's say you know I'm the kind of person to easily give people money. I just got my paycheck, and you knowing this, you ask me to give you the money. I'll give you the money because that's the kind of person I am. But then I'm left with no money for the month, and all of its consequences.

Who do you think would carry the blame in this situation?

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#582

Earlier quoted context omitted.

You are extremely naive if you believe Google can't infer anything if the referer is missing. An IP + user-agent combination (both of which are sent) is enough to uniquely identify a typical home user with high certainty unless they're behind a carrier-grade NAT and use a very popular browser.

Let's assume Google can identify the user but doesn't get a referrer. So what? The only information Google receives is that some user visited some unknown website at a particular time. How exactly would that lead to Google increasing its profits?

They know users activity hours better that way. At scale that is valuable data.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#583
post #433

Earlier quoted context omitted.

Sorry, I don't mean to play the devil's advocate, this has already gone way off-topic so take what I say with a pinch of salt. But technically, the IP is not strictly necessary? I can imagine a feasable future where it could be replaced with an anonymised IP from a larger pool generated by your ISP, with TLS for the payload. This could be solved at the internet infrastructure layer, and not required by to be solved b…

> I can imagine a feasable future where it could be replaced with an anonymised IP from a larger pool generated by your ISP, with TLS for the payload. This is already a thing with NAT and Carrier-Grade NAT. However if the IP + port + time trio, coupled with other information (such as browser, stack, timezone, behavior) can be used to de-anonymise the user, this also instantly becomes PII. > This could be solved at th…

Identifiability for IP addresses uses an even lower standard. The GDPR says that for something to be truly anonymous, there must not be any “reasonably likely” means for identification, even with the help of third parties, even when relying on additional information. There has of course been litigation about this, in the form of the Breyer v Bundesrepublik Deutschland case. It was based on the GDPR's predecessor law, but it used virtually identical phrasing so the conclusion still holds.

The European Court of Justice constructed a hypothetical scenario to show that identification can reasonably be likely. Let's say the website was attacked by a hacker. In a logfile, you find the attacker's IP address and want to prosecute them. So you report the incident to whatever authority is responsible for such incidents, which then gets a court order so that the attacker's ISP discloses information about the IP address. As long as the ISP knows to whom that IP was allocated at the time, there is now a reasonably likely chain of events that leads to identification of the person behind the IP address.

In this case about Google Fonts, the court says that it's sufficient if the website operator or Google have the “abstract means” for identification, not whether they actually did this for this plaintiff's specific IP address.

A solution would be if the EU forbids ISPs from keeping such logs, but given repeated attempts at mass data retention laws for national security purposes and pressure from the IP industry^W^W film and music industry for copyright infringement prosecution purposes, that doesn't seem likely.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#584
post #522

Earlier quoted context omitted.

Perfect than you can just continue to use Google Fonts as is. I suppose Google does not pay artists and foundries out of the goodness of their hearts. They pay them to earn money through user data. If this is illegal a different service will turn up eventually.

I don't understand where you get this whole "service" idea from, but it clearly shows that you've never actually interacted with google fonts in any way. Any different "service", would have the EXACT SAME ISSUE: Hot-linking leaks user IP-Data to whoever hosts the hot-linked content. If you use the google fonts home page _as designed by google_ it already makes you download the fonts to self-host them along with your…

No hotlinking fonts is okay if you have a valid data processing agreement with the service.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#587

Can you someone translate? Does this mean that hot linking any static media or asset from a third party is against the law unless explicit approval from the user is first received?

If there are different means to host the asset and the hot linking would transfer data out of the EU (in particular to the US and to a giant marketing company) that might be problematic.

Traffic inside or outside EU is marginal. It's just illegal from the start. You need prior informed consent and it must be optional.

If it is not technically necessary. And a CDN rarely is. I can show you some sites that do without.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#588
post #455
post #369

Earlier quoted context omitted.

Not a lawyer, but to my knowledge, GDPR does not care if something technically "can be blocked" with some effort. It cares if there was clear, voluntary consent to share a particular bit of data - which wasn't the case here.

Then GDPR should blame the browser vendors for shipping with JS execution enabled by default and demand that JS execution for all browsers be turned off by default. To repaint the stories spun by the grand parents: If I hold up a dagger and announce the fact, why would you run into the dagger anyway without protection? Put on some armor, dude. The client browser had all the information it needed to not make the reque…

No, this is not how informed consent works.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#589
post #354

Earlier quoted context omitted.

So does this mean assets hosted by CDNs are illegal now? Since it doesn't ask the user's permission to direct the browser to another site to download said assets? And what if they're already cached in the browser. Distinction? Seems like laws don't understand how tech works...

Exactly! You’ll soon have to fill out a form as if undergoing surgery just to visit a website. (And, of course, were all gonna click “Accept all”, just as we do with cookie warnings and Apple TOS.) These judges do not know what they do. They only care about getting the case off their desk, clinging to the first semi plausible argument that allows them to do so. If you look for vision, guidance or responsibility for s…

> You’ll soon have to fill out a form as if undergoing surgery just to visit a website

This is entirely a fault of the site owners.

> These judges do not know what they do

They proved again and again that they know what they are doing.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#590
post #529

Earlier quoted context omitted.

This ruling will 100% be upheld in the higher courts. The website is arguing that they have a legitimate interest in downloading fonts from Google in client browser, but as the court correctly states the website can provide these fonts directly. There is no reason to infringe on the user privacy, so there is no legitimate interest. And therefore use of Google fonts was without a legal basis. BTW - The website could h…

> The website is arguing that they have a legitimate interest in downloading fonts from Google in client browser, but as the court correctly states the website can provide these fonts directly. There is no reason to infringe on the user privacy, so there is no legitimate interest. And therefore use of Google fonts was without a legal basis. Would the same argument apply to using Strip or Paypal to accept credit card…

This clearly falls into Art. 6 GDPR paragraph 1, point b) :

Processing shall be lawful only if and to the extent that at least one of the following applies:

b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;

This legal basis is a lot more clear and a lot less stringent than point f) legitimate interest as it does not explicitly require you to establish "legitimacy" and balance it against vague "interests or fundamental rights and freedoms of the data subject".

f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

See: https://gdpr-info.eu/art-6-gdpr/

Post reply on HN