Earlier quoted context omitted.
Why "what the hell"? This is exactly what happened, and a logical consequence the moment IP addresses are classified as private data. Which it is in a system where it can be used to find the civil identity of the user, which is the case in Germany via Vorratsdatenspeicherung and the rampant misuse of the legal system. Note how the decision contains the question of whether leaking the IP was necessary. They noted it i…
Look and learn from Yubico, they don’t show any YouTube embedded videos until you agree to functional cookies: https://www.yubico.com/?lang=sv
GDPR penalty for passing on of IP address to Google by using Google Fonts
81–90 of 656 posts
Re: GDPR penalty for passing on of IP address to Google by using Google Fonts
#82Earlier quoted context omitted.
Seems pretty simple to me. I visit not-google.com, then don't load anything from elsewhere without being asked first. It's not too dissimilar to app-level permissions.
The counterargument to this is that you are knowingly using a piece of software that has, and has always had, the default behaviour of autoloading remote resource links it finds in HTML. This ruling could easily get overturned.
If the user visits foo.de they obviously expect that some data is transmitted to foo.de
They also might know that companies use service providers and therefore necessary data might be shared with 3rd party companies (which is fine according to the GDPR).
However the user can also expect that that a) foo.de minimizes data transmissions and b) 3rd parties conform to the GDPR rules (which Google can't).
If the user is logged in to Google (e.g. for Gmail) Google would be able to connect the user with foo.de with a high likelihood. This in turn might expose the users behaviour to automatic analysis by foreign government agencies without any legal oversight (since the user most likely isn't a US citizen)
Re: GDPR penalty for passing on of IP address to Google by using Google Fonts
#83Earlier quoted context omitted.
Why "what the hell"? This is exactly what happened, and a logical consequence the moment IP addresses are classified as private data. Which it is in a system where it can be used to find the civil identity of the user, which is the case in Germany via Vorratsdatenspeicherung and the rampant misuse of the legal system. Note how the decision contains the question of whether leaking the IP was necessary. They noted it i…
I have to say that this is such an example of new technology being scary but the problems with old technology being ignored. I'm still waiting for the ability to have mail received from someone or a company without giving such parties my name and physical address. This could very easily be implemented in many ways, but somehow does not exist. There is no reason for a mail order company to know my full name and physic…
Re: GDPR penalty for passing on of IP address to Google by using Google Fonts
#84Earlier quoted context omitted.
I too was pissed about the popups until I realized it the companies throwing up the popups that are to blame. Hosting all your assets by yourself, on your own servers and doing analytics without sending data to a third party is not a terribly tall order.
that is true but it increases the barrier to entry for those who use google fonts for system resource issues, a lot of people offload because they don’t have the space or money to self host everything one could argue that it is less eco friendly as well given how much space is going to be used repeating the same file on a multitude of servers
Re: GDPR penalty for passing on of IP address to Google by using Google Fonts
#85Can you someone translate? Does this mean that hot linking any static media or asset from a third party is against the law unless explicit approval from the user is first received?
If you have agreements in place with third party data processors to protect user privacy, this ruling does not prevent you from hot linking third party assets under that agreement. In effect, the third party acts as part of your infrastructure - just like you may already use a third party hosting provider, cloud database provider, auth provider, logging service, etc.
The GDPR constrains how PII is stored and processed. It doesn't stop you from using third party providers, but it does make you responsible for ensuring user privacy is protected, by delegation through binding privacy agreements and sufficient diligence.
Those types of agreements are already common. For example, if you're hosting on AWS providing service to users covered by GDPR, you should already have such an agreement. It's pretty straightforward. https://aws.amazon.com/compliance/gdpr-center/
Therefore if AWS offered a generic, third party font hosting or embedded video hosting service, you could hot link to that no problem.
Same with Cloudflare, Google Cloud, etc. as long as they provide the necessary agreements with you.
The problem with Google Fonts is there is no such agreement in place, you can't trust Google to not profile users statistically via font requests, and even if Google says they won't do that, you can't trust that their servers in the US won't be tapped by US authorities to monitor request logs, etc.
Re: GDPR penalty for passing on of IP address to Google by using Google Fonts
#86Earlier quoted context omitted.
1) Your IP address is considered personal data, as it can be used to identify you. In general, everyone can see and agree with this. Only if you're the sole user of that IP, which is e.g. not the case in a family.
I stand corrected - not everyone can agree! In reality, as a service provider, you have no ability to determine if the client IP belongs to an individual or not - so you have no choice but to assume it does identify an individual.
Re: GDPR penalty for passing on of IP address to Google by using Google Fonts
#87Earlier quoted context omitted.
The browser can be set to dissallow third party resources
Keyword: per default . It's an opt-out, GDPR requires an opt-in.
Re: GDPR penalty for passing on of IP address to Google by using Google Fonts
#88Re: GDPR penalty for passing on of IP address to Google by using Google Fonts
#89Earlier quoted context omitted.
Yeah, the plaintiff's browser made the request after all, no?
The plaintiff's browser did what the defendant's code ordered it to do. If the defendant's code violated GPDR (which seems to be the court's conclusion) by sending the plaintiff's browser somewhere, it's a defendant's problem, not plaintiff's.
Re: GDPR penalty for passing on of IP address to Google by using Google Fonts
#90So an HTTP GET request to another domain (fonts.googleapis.com) "leaked" website visitor's IP address to Google. What the hell? Google Translate: https://rewis-io.translate.goog/urteile/urteil/lhm-20-01-202... > The defendant is sentenced to pay the plaintiff €100.00 > The plaintiff has a claim against the defendant to refrain from passing on the plaintiff's IP addresses to Google under Section 823 (1) in conjunction…
Why "what the hell"? This is exactly what happened, and a logical consequence the moment IP addresses are classified as private data. Which it is in a system where it can be used to find the civil identity of the user, which is the case in Germany via Vorratsdatenspeicherung and the rampant misuse of the legal system. Note how the decision contains the question of whether leaking the IP was necessary. They noted it i…
But there is. Where does it stop being reasonable? When you have to host your own video delivery infrastructure?