Live data from Hacker News

GDPR penalty for passing on of IP address to Google by using Google Fonts

rewis.io

601–610 of 656 posts

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#601
post #593

Earlier quoted context omitted.

> You’ll soon have to fill out a form as if undergoing surgery just to visit a website This is entirely a fault of the site owners. > These judges do not know what they do They proved again and again that they know what they are doing.

Yeah, the GDPR has done a lot of good already. The lawmakers clearly knew what they were doing.

Unironically yes.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#602
post #577

Earlier quoted context omitted.

The technical implementation details don't matter. What matters is that the IP will be shared with Google as consequence of visiting the site as long as the user didn't take additional actions and without the user having took additional actions which made that happen.

This will also happen if I place a link on my site that does not clearly warn the user that it leads to a non EU website. User clicks it, and his IP address gets disclosed. Really, if you participate in the World Wide Web, of course your computer’s address will be visible to others, and you can not always control it. Like driving on the Autobahn. People will be able to see you. It’s part of life.

GDPR differentiates between functional necessary and non-functional necessary parts.

And again technical nit-picking do not matter, but user intend does.

Similar that side you link to would also need to be GDPR compliant (or not provide service in EU countries).

The problem with google fonts is that the side which loads them agrees in your stead without your permission to google collecting your data and using it for non essential use cases.

While when you navigate to an side, it must not collect data beside purely functional data until you agree to it. (and yes collecting IP address can be purely functional, depending on what you do with it and if you delete it in time. E.g. for security logs and DDoS protection it can be purely functional. (if some conditions are meet)).

Be aware what counts as "neccessary"/"purely functional"(1) is not always fully clear.

(1): Not necessary the wording used by the law.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#603
post #414

Earlier quoted context omitted.

How does this not reduce to hitting any server not owned by you is leaking your IP address? If I host my website behind Google Cloud CDN they have logs of the visitors IP. If I host my site on S3 they log the IP. Does this mean that a visitor must insteract only with services that I own until I can get concent to use "unnecessary" third party services? I think it is pretty significant if "necessary" is reduced to "co…

That‘s what it reduces to, yes, and german courts seem set on actually creating precedents [0] for that dreadful situation. [0] https://www.taylorwessing.com/en/insights-and-events/insight...

The core issue with the linked situations is that the US Cloud Act applies, which means that US governmental agencies can request access to i.e. traffic logs, without a court order for mass surveillance.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#604

Earlier quoted context omitted.

By sharing data until public relations make change necessary https://www.theverge.com/2021/9/11/22668734/google-user-data...

If China can mandate Google to do something like that and having Google submit to it, effectively escaping US jurisdiction for this part of the world, why wouldn't it work in the EU applied to a completely different set of goals?

US jurisdiction doesn't even protect its own citizens against their government requesting data from google about them, why would it protect those of Hong Kong from their ... oh wait i get it

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#605

Earlier quoted context omitted.

If the CDN abides by GDPR laws and doesn't process user data then it is fine. But if the CDN you use process user data for its own gain rather than just serve the request then that goes against GDPR. It is your responsibility as a developer to ensure the services you use follow these laws. If you don't have a contract stating that the other part will honor GDPR then we will assume that the other part will misuse all…

Does Google CDN not abide GDPR?

It does not, because of the Cloud Act and related american mass surveillance laws

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#606
post #64

Earlier quoted context omitted.

The plaintiff's browser did what the defendant's code ordered it to do. If the defendant's code violated GPDR (which seems to be the court's conclusion) by sending the plaintiff's browser somewhere, it's a defendant's problem, not plaintiff's.

Yeah, that's exactly the agency argument. It's not as if the plaintiff's browser is actually under control of the defendant, a user agent is not forced to follow the instructions that are contained in a website it requested on behalf of its user.

> a user agent is not forced to follow the instructions

Luckily! A large german media corporation called "Springer" has for years, and is still, unsuccessfully trying to get the courts and politicians to rule that users can not manipulate web content and must run it as intended, as changing it would violate copyright and is a sabotage of their program. And i bet they aren't the only ones globally. Also: how many devices are locked down and can only run code as it is provided by trusted third parties? Try installing an ad-blocker on a smart-tv or a playstation.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#607
post #414

Earlier quoted context omitted.

How does this not reduce to hitting any server not owned by you is leaking your IP address? If I host my website behind Google Cloud CDN they have logs of the visitors IP. If I host my site on S3 they log the IP. Does this mean that a visitor must insteract only with services that I own until I can get concent to use "unnecessary" third party services? I think it is pretty significant if "necessary" is reduced to "co…

That‘s what it reduces to, yes, and german courts seem set on actually creating precedents [0] for that dreadful situation. [0] https://www.taylorwessing.com/en/insights-and-events/insight...

[deleted]

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#608
There is a serious problem with the ongoing balkanization of the internet. EU nations are almost at the point where they rule that european corporations must provide pages in a way that respects european citizen rights and follows european laws.

Outrageous!

And yes that means they can not integrate services from surveillance states like the USA or China without asking the user first, as the EU government thinks only their agencies should be allowed to run mass surveillance against their citizens without consent.

And the EU is not the only one who thinks like that. Pretty soon services controlled by foreign powers will be unacceptable in most of the world. Currently in the USA this is limited to hosting government and military secrets on foreign systems, but i bet if some chinese network would start to creep all over the civilian american web, reporting back to their ministry of national security, the rules would change quickly. For now the USA uses its position to spy on everyone, and i don't mean "nations" or "governments", i mean everyone. American patriots don't see a problem with that, but we know what you do in Utah, and it's a crime against humanity.

For the multinational corporations this whole situation of GDPR-vs-CloudAct means massive restructuring, splitting into smaller entities that service regional markets and moving the top level corporate group somewhere with minimal regulation to minimize conflicts. And such legal splits rupture their core business, at some point they can't have chinese hardware in us datacenters being administrated by indian technicians providing services to russian tourists in brazil anymore.

Maybe this is the last battle the nation states fight with the global corporations and it instead breaks nationalism in favor of streamlining compliance and getting shit done. I can only hope that the global rules emerging say no to mass surveillance and yes to data privacy, but abusing human rights has always meant power and profits, and so i fear the future is dystopian.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#609

Earlier quoted context omitted.

> it’s technically not very hard to do so, and I quite like it For the average user, it's yet another thing to click without thinking, just to be able to visit a page. > Consent is required before exposing the IP address and is must be explicitly given There's the crux of the problem, it's difficult to know what to consent for without first displaying the website, so you implicitly give consent for "just the bare min…

> > it’s technically not very hard to do so, and I quite like it > For the average user, it's yet another thing to click without thinking, just to be able to visit a page. And yet, they’re still protected: They’ll click on the video when they want to watch the video, load the like button when they want to like, the tweet button when they want to tweet. And all the other times when they visit a website that offers any…

> There is no need to ask for consent for every Stylesheet you load from a CDN. You’re allowed to use cloudflare, cloudfront, fastly,… - they’ll all provide the required DPA that allows you to use them without consent.

And Google doesn't? (Honest questions)

On first look serving a font from Google and a stylesheet from Cloudflare seem very, very similar things.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#610

Earlier quoted context omitted.

This is exactly the entitlement your comment parent was on about. A third party should not have active insight into the first party's business like that - or their customers'. GDPR is a very welcome step forward in this regard, and I hope that more of such will come.

The sort of logic imputed by the GPDR would put an end to mailing parcels too. You could drive across town to deliver the package, you didn't need it delivered via the post. After all, every package shipped in the mail involves a third party who knows the sender and recipient's address and name. Best get to banning that sort of potential skulduggery ASAP! This is really an idiotic law in that it punishes the symptom…

No, the mailing parcels are fine. As long as they have proper employees that deliver the packages, and not a third party that does deliver, but also collects everyone's name, address, package sizes and estimated values, and projects household income, advertising cohort and then sells this to yet another third party. See the difference?

Regarding the instrinic part of the internet argument, that's just an appeal to nature. Naturally the internet is such and such, and therefore it's good (and also currently widespread). That's not a reason why that should be. We forbid plenty of such intrinsicly human things by law, because that's how ~the ruling class can stay in power~ lots of people can live together in relative safety. For example hurting someone else is perfectly natural, I think. I think it happened lots of times before it became a sort of law to not do that. And of course it happens now in many direct and indirect ways, because people want to express, for example, just how angry they are at another. Yet I don't see how we shouldn't restrict this very intrinsic thing.

Also, but this is just conjecture, I think this application of GDPR would allow third party requests IF they are not logged for example. Because then the data collection doesn't happen. In TFA, the third party is Google, and that might be the thing that makes the difference.

Post reply on HN