Live data from Hacker News

GDPR penalty for passing on of IP address to Google by using Google Fonts

rewis.io

81–90 of 656 posts

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#81
post #23

Earlier quoted context omitted.

Why "what the hell"? This is exactly what happened, and a logical consequence the moment IP addresses are classified as private data. Which it is in a system where it can be used to find the civil identity of the user, which is the case in Germany via Vorratsdatenspeicherung and the rampant misuse of the legal system. Note how the decision contains the question of whether leaking the IP was necessary. They noted it i…

Look and learn from Yubico, they don’t show any YouTube embedded videos until you agree to functional cookies: https://www.yubico.com/?lang=sv

There’s an easier way than that: embed from youtube-nocookie.com. Of course that doesn’t necessarily help with the Munich ruling…

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#82
post #33

Earlier quoted context omitted.

Seems pretty simple to me. I visit not-google.com, then don't load anything from elsewhere without being asked first. It's not too dissimilar to app-level permissions.

The counterargument to this is that you are knowingly using a piece of software that has, and has always had, the default behaviour of autoloading remote resource links it finds in HTML. This ruling could easily get overturned.

Could be but I would not expect it.

If the user visits foo.de they obviously expect that some data is transmitted to foo.de

They also might know that companies use service providers and therefore necessary data might be shared with 3rd party companies (which is fine according to the GDPR).

However the user can also expect that that a) foo.de minimizes data transmissions and b) 3rd parties conform to the GDPR rules (which Google can't).

If the user is logged in to Google (e.g. for Gmail) Google would be able to connect the user with foo.de with a high likelihood. This in turn might expose the users behaviour to automatic analysis by foreign government agencies without any legal oversight (since the user most likely isn't a US citizen)

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#83
post #23

Earlier quoted context omitted.

Why "what the hell"? This is exactly what happened, and a logical consequence the moment IP addresses are classified as private data. Which it is in a system where it can be used to find the civil identity of the user, which is the case in Germany via Vorratsdatenspeicherung and the rampant misuse of the legal system. Note how the decision contains the question of whether leaking the IP was necessary. They noted it i…

I have to say that this is such an example of new technology being scary but the problems with old technology being ignored. I'm still waiting for the ability to have mail received from someone or a company without giving such parties my name and physical address. This could very easily be implemented in many ways, but somehow does not exist. There is no reason for a mail order company to know my full name and physic…

[deleted]

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#84

Earlier quoted context omitted.

I too was pissed about the popups until I realized it the companies throwing up the popups that are to blame. Hosting all your assets by yourself, on your own servers and doing analytics without sending data to a third party is not a terribly tall order.

that is true but it increases the barrier to entry for those who use google fonts for system resource issues, a lot of people offload because they don’t have the space or money to self host everything one could argue that it is less eco friendly as well given how much space is going to be used repeating the same file on a multitude of servers

An interesting question. Someone should do a environment cost impact on self hosting fonts (and other resources) vs client having to make lot's of requests to various hosts for those resources.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#85

Can you someone translate? Does this mean that hot linking any static media or asset from a third party is against the law unless explicit approval from the user is first received?

No. (Contrary to the sibling comment).

If you have agreements in place with third party data processors to protect user privacy, this ruling does not prevent you from hot linking third party assets under that agreement. In effect, the third party acts as part of your infrastructure - just like you may already use a third party hosting provider, cloud database provider, auth provider, logging service, etc.

The GDPR constrains how PII is stored and processed. It doesn't stop you from using third party providers, but it does make you responsible for ensuring user privacy is protected, by delegation through binding privacy agreements and sufficient diligence.

Those types of agreements are already common. For example, if you're hosting on AWS providing service to users covered by GDPR, you should already have such an agreement. It's pretty straightforward. https://aws.amazon.com/compliance/gdpr-center/

Therefore if AWS offered a generic, third party font hosting or embedded video hosting service, you could hot link to that no problem.

Same with Cloudflare, Google Cloud, etc. as long as they provide the necessary agreements with you.

The problem with Google Fonts is there is no such agreement in place, you can't trust Google to not profile users statistically via font requests, and even if Google says they won't do that, you can't trust that their servers in the US won't be tapped by US authorities to monitor request logs, etc.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#86
post #25

Earlier quoted context omitted.

1) Your IP address is considered personal data, as it can be used to identify you. In general, everyone can see and agree with this. Only if you're the sole user of that IP, which is e.g. not the case in a family.

I stand corrected - not everyone can agree! In reality, as a service provider, you have no ability to determine if the client IP belongs to an individual or not - so you have no choice but to assume it does identify an individual.

This is ludicrous. Nginx logs are regulated now? What if you just want to make a static website and get on with your life?

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#87

Earlier quoted context omitted.

The browser can be set to dissallow third party resources

Keyword: per default . It's an opt-out, GDPR requires an opt-in.

People who created the browser are not processing any data when you use the browser, so GDPR hardly applies. They need to be careful with bug reports, but that's it.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#88
District courts are notoriously terrible. Judges are overworked. They are incentivized for dealing with cases as quickly as possible. As a judge, you actually get penalized for handling cases diligently. Many judges can’t even touch type, so even when they do go through the motions of doing legal research, they type in a few crude keywords, skim the first results presented by the algorithm, and then call it a day.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#89
post #64

Earlier quoted context omitted.

Yeah, the plaintiff's browser made the request after all, no?

The plaintiff's browser did what the defendant's code ordered it to do. If the defendant's code violated GPDR (which seems to be the court's conclusion) by sending the plaintiff's browser somewhere, it's a defendant's problem, not plaintiff's.

Yeah, that's exactly the agency argument. It's not as if the plaintiff's browser is actually under control of the defendant, a user agent is not forced to follow the instructions that are contained in a website it requested on behalf of its user.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#90
post #23

So an HTTP GET request to another domain (fonts.googleapis.com) "leaked" website visitor's IP address to Google. What the hell? Google Translate: https://rewis-io.translate.goog/urteile/urteil/lhm-20-01-202... > The defendant is sentenced to pay the plaintiff €100.00 > The plaintiff has a claim against the defendant to refrain from passing on the plaintiff's IP addresses to Google under Section 823 (1) in conjunction…

Why "what the hell"? This is exactly what happened, and a logical consequence the moment IP addresses are classified as private data. Which it is in a system where it can be used to find the civil identity of the user, which is the case in Germany via Vorratsdatenspeicherung and the rampant misuse of the legal system. Note how the decision contains the question of whether leaking the IP was necessary. They noted it i…

> if there is no way to embed Youtube videos without leaking the address

But there is. Where does it stop being reasonable? When you have to host your own video delivery infrastructure?

Post reply on HN