GDPR penalty for passing on of IP address to Google by using Google Fonts
rewis.io
rewis.io
Google Translate: https://rewis-io.translate.goog/urteile/urteil/lhm-20-01-202...
> The defendant is sentenced to pay the plaintiff €100.00
> The plaintiff has a claim against the defendant to refrain from passing on the plaintiff's IP addresses to Google under Section 823 (1) in conjunction with Section 1004 of the German Civil Code.
> It is undisputed that the plaintiff's IP address was forwarded to Google when the plaintiff visited the defendant's website.
Note how the decision contains the question of whether leaking the IP was necessary. They noted it is not necessary to serve the fonts via Google, it can happen without leaking the IP (I assume they mean self-hosting):
> Google Fonts kann durch die Beklagte auch genutzt werden, ohne dass beim Aufruf der Webseite eine Verbindung zu einem Google-Server hergestellt wird und eine Übertragung der IP-Adresse der Webseitennutzer an Google stattfindet.
translated:
> Google fonts can be used by the defendant in a different way, so that a connection to the website does not make a connection to the Google server, thus without transmitting the IP address of the website visitor to Google.
Which is good news! It is a totally consistent decision with the current privacy rules and best practices: Do not save or leak private data if not necessary, always minimize data exposure as much as possible. The as much as possible part is very important - if there is no way to embed Youtube videos without leaking the address, then that's still possible to do. Sounds fair to me.
For example, say I want to embed an instagram post on my website. You could argue that I should talk to the person who took the picture and get a license for the image so that I can host i on my own domain rather than loading the content for instagram. In practice this is obviously much, much more cumbersome than embedding the IG post and so would result in huge changes how websites work (by vastly reducing any externally loaded content).
In a similar vein, you could argue that serving cached content from another host is not strictly necessary. Why not just run your own caching servers? It's probably worse in most ways (my cache server << cloudflare's cache server), but if minimising the amount of content loaded from external hosts is your aim then it is feasible.
The part that is tricky, is where we offload additional burden of knowledge and responsibility to the website providers.
When it is on the user to figure out whether they are allowed to use a product – and that means in fact any product – that one of the biggest companies in the world is allowed to offer in my country legally, we are in trouble.
Law is complex. Tech is complicated. Most people are not law or tech experts. Getting sound advice on both is expensive, and the trend to increasingly need more of both is worrisome.
This seems neither fair nor reasonable to me. Or particularly democratic.
I'm still waiting for the ability to have mail received from someone or a company without giving such parties my name and physical address. This could very easily be implemented in many ways, but somehow does not exist.
There is no reason for a mail order company to know my full name and physical address to deliver anything to do, and I feel this sis far more compromising than an i.p. address.
Not quite? Wouldn't the users browser have sent its own IP address to Google? That's different that "forwarding" it, and it may not even be enough for Google to connect the user to that site.
Or proxying. Or proxying with caching, which is kind of part way between self-hosting and proxying. :)
But there is. Where does it stop being reasonable? When you have to host your own video delivery infrastructure?
https://allaboutberlin.com/guides/abmahnung-creative-commons
That copyright example by the way, that applies everywhere.
> September 21: After months of silence, we have received another letter from Kanzlei Schröder. This time, they threaten to take us to court unless we pay 400€ by October 1. We decided to pay. That was our last interaction with Kanzlei Schröder.
The government has the absolute authority to regulate you into a corner, if need be, to protect its people from predation by powerful interests. That's what governments are for.
https://doctorow.medium.com/a-bug-in-early-creative-commons-...
(action still required: authors need to update to CC 4.0 or later)
It has a very chilling effect on innovation no doubt.
The worst you could do to a lawyer is that maybe you could embarrass them about their lack of network engineering knowledge, but they in turn can extract real money from you through various means.
Also defending oneself results in involving a different lawyer enriching lawyers as a whole anyways.
Just don't do it but serve your stuff from your domain.
> It is undisputed that the plaintiff's IP address was forwarded to Google when the plaintiff visited the defendant's website.
In this context, "It is undisputed" does not mean "It is a truth universally acknowledged by everyone", but rather "there is no dispute between the defendant and the plaintiff that this happened; in the light of that non-disagreement, the court is not required to decide whether that happened or not, and will accept that as a fact".
So in this case, the defendant (as well as the plaintiff, of course) agreed that "the plaintiff's IP address was forwarded to Google when the plaintiff visited the defendant's website". If there was a place to bring forward this "agency argument", this was the place; however the defendant seems to have chosen not to bring it forward.
It may be because the defendant's lawyers are unprofessional and forgot; it may also be because they are professional and so they knew this argument would not hold.
P.S. see also https://news.ycombinator.com/item?id=30139489
If I visit example.com I am not to guess what 3rd parties it uses.
Not only from your own domain, but from your own servers. If you still server-side send the IP to Google servers, it's still sharing of personal data with a 3rd party.
I wonder how this works when you rent servers from VPS providers. If you host data on their servers, does it mean you share it with them? What if this data is behind a root password? What if it's encrypted?
This ruling could easily get overturned.
Actually, most people don’t actually know that. And why would they? Why should they get bogged down in such technical minutiae? Why require users to play tedious uBlock whack-a-mole of enabling resources from external domains until the website starts working in order to have any semblance of privacy?
Just because something is common doesn’t make it right.
So you could conclude that my program can do whatever it wants within those constraints, and it's your problem as a user if it does something you don't like.
But I don't think it is fair to expect normal people to analyze a program for malicious behavior before running it. And I don't see how it is relevant whether that program is a compiled binary or a spaghetti blob of html, css, javascript, and web assembly. Also it is not clear that such analysis is permitted by the draconian copyright laws.
Am I? Maybe I am, because I have worked as a web developer, but most people don't really have this knowledge.
And even if they suddenly start having the knowledge, what is their choice? Stop using the web for good?
Instead of blaming the user for not having technical means and personal rules to apply privacy best practices, the site creator has to offer options to review the situation _before_ letting loose all the trackers and third party carnival.
And it makes sense to me. If tomorrow a site decide to get their favicon from microsoft‘s new marketing service, it would be unreasonable to expect the users to know to block that.
If the user visits foo.de they obviously expect that some data is transmitted to foo.de
They also might know that companies use service providers and therefore necessary data might be shared with 3rd party companies (which is fine according to the GDPR).
However the user can also expect that that a) foo.de minimizes data transmissions and b) 3rd parties conform to the GDPR rules (which Google can't).
If the user is logged in to Google (e.g. for Gmail) Google would be able to connect the user with foo.de with a high likelihood. This in turn might expose the users behaviour to automatic analysis by foreign government agencies without any legal oversight (since the user most likely isn't a US citizen)
GDPR is going to manage to make the internet unusable. Who would've thought it was going to be bureaucrats the ones to kill the web!
- With Google Fonts, to track the identity of users AND the real popularity of websites,
- With Google DNS 8.8.8.8, to track everyone’s DNS resolutions,
- With Google Analytics, to track who sees what, even if they only display masked IPs to the owner of the GA profile,
- Etc with Google Maps, emails, they don’t provide those services for free, they can track everyone’s profile, down to their obedience to Covid rules.
I wouldn’t be surprised if Germany bans more aspects of using Google’s free services.
The sharing with ruters etc. is required to operate the service (website). Using a Google CDN for fonts isn't (required for operating a website).
The ruling explicitly points that out.
Furthermore DNS is handled by the contract you signed with you ISP or you explicitly changing it. Same for some other parts.
Where is exactly is the line for needed for operating a website and being optional?
What if you create your website in wix.com, the data from your domain will be shared with them AND it is needed for this data to be shared for operating the website.
EDIT: To make it clear, I always recommend self-hosting fonts and agree that Google CDN fonts should be avoided. But even if you self-host the fonts, those are still hosted on a server that is very unlikely to be your basement.
Remember that your user agent is sent as well.
In Firefox 96 network requests to 3rd parties (in this case Google) still seem to include the 1st-party hostname as REFERER header.
And for someone with masses of extra data like Google it is enough to identify who is doing the browsing, so this isn't some crazy overreach.
In the end, the w3c standards define, that browsers execute the commands they receive from the server and in this case, the server tells the browser to download the font. So the site-owner configures his website in a way, that this site instructs browser to share the IP address.
If this ruling is upheld, either (a) browsers need to immediately stop interpreting these commands, instead providing user prompts for _each offsite load event_, or (b) a very large swath of websites are all open to the same legal issue. As a small example, the Aesop wine company site (https://www.aesopwines.com/), made with Squarespace, uses typekit, squarespace, and google CDN loads. They're subject to the same ruling, right? And so on, and so on...
I'm no expert in the matter, but this seems a little convoluted to me? To me, the server does not issue instructions, per se, it returns a declarative text/binary response that describes the sturcture of the website, it is then up to the browser, that the user installed and chooses to use and may configure (and possibly configure to leak their data, even if spec-adhering behaviour of rendering the webpage should not), to attempt to understand the document and retrieve any other resources that may assist displaying the content correctly.
On the other hand, if one was to send CPU instructions back to the user, I guess it's also there choice to execute them...? Also, it's not possible to determine which resources are for display purposes (fonts), and which are for tracking purposes, the browser will blindly have to retrieve the resource, so websites have a certain responsibility to issue privacy-respecting "instructions".
I'm trying to argue both sides here, I still believe that the user chooses voluntarily to use the browser, visit the webpage and therefore parse the document and initiate any subsequent requests that the document proposes, on the other hand, this is beyond most people, they just want to view a frickin' website, so perhaps the lives of web developers should be made harder to make the lives of the average Joe, who is not an IT expert, a little easier? The architecture of the web is inherently not privacy-respecting, in order to save bandwidth (and for sake of simplicity), we only send fragments and let the browser choose what else it needs, which can be tracked.
It's like walking in a park. You choose to show your face to people, we've come to just accept the fact that by the laws of nature, we cannot prevent other people from seeing our face (unless you use a mask, but then you make them very uneasy), we leak data that others can remember and use to identify us later.
I wouldn't say so. By making use of the Google Fonts service, the website owner set up a scenario where the browser would then share the user's IP with Google. That's the default behavior of most browser setups. It's as good as sharing with Google directly, no? I feel like the scenario is similar to setting up a trap. Technically the victim activates the mechanism, but surely the one who sets the trap carries the blame?
Well said. Law is not a programming language, the fact that the website didn't _technically_ share the IP, but did it through the browser, is not relevant.
There was no trap, in my opinion, document clearly specifies that an additional resource, here a font, will help the website look as intended by the designer. It's visible and its effects are well known (it's part of a well understood specification) and can be blocked. Websites have a responsibility, absolutely, but this is just feels like going too far...
I'm curious to know whether DNS and your IP being in the the header of packets travelling through various different countries that can be sniffed is also considered as unwilful data sharing?
The website is arguing that they have a legitimate interest in downloading fonts from Google in client browser, but as the court correctly states the website can provide these fonts directly. There is no reason to infringe on the user privacy, so there is no legitimate interest. And therefore use of Google fonts was without a legal basis.
BTW - The website could have used a different legal basis out of 6 available, like consent. See: https://gdpr-info.eu/art-6-gdpr/
> I'm curious to know whether DNS and your IP being in the the header of packets travelling through various different countries that can be sniffed is also considered as unwilful data sharing?
Unless there is another way to achieve the same purpose there is a legitimate interest in processing that data for the purposes expected by the client i.e. providing internet service.
It wouldn't break the internet. The internet was fine when the vast majority of sites hosted all their own content and didn't ask your browser to load crap from dozens of domains. It wasn't even that long ago. Honestly I think it was better.
Right now you're right, the internet works this way. But that doesn't make it right, or fair, or anything, it just is. And it's also no reason it couldn't work in a different way.
The IP has to be there for the return TCP packet, so under GDPR this falls under "strictly necessary" information.
If someone sniffs you, they now have your PII. They can't do anything with it that is not "strictly necessary" without your consent, otherwise they're also on violation of GDPR.
The only people trying to "break the internet through fear" are the doomsayers.
By that logic, any and all tracking pixels, javascript, iframes, etc would be regulatory no man's land, because all of those are technically just "intents" the server signals.
Nevertheless, users are seldomly in a position to decide whether or not those intents are followed (and site owners can get quite mad if a user instructed their browser to "decline" such an intent e.g. through an ad blocker). All of that makes it reasonable to treat those intents as commands.
"Your honor, I merely told the gun to strike the firing pin. Without a round chambered in, the gun wouldn't have done anything."
Can it? Is this within the range what Google is allowed to do in the EU right now?
Because, if that is the case and we also wanted to stop that, wouldn't it be a lot more reasonable to just... forbid Google from doing that, instead of slapping every confused wordpress hack in the EU with a fine?
It doesn't matter what the promise.
They could sell their software stack to an independent European partner over whom they don't have any control and who doesn't transmit data back to the US.
Google's current GDPR consent screen is not compliant. It provides an easy "accept" option but no easy decline option, which is against the regulation.
Given they are already breaking the law and successfully getting away with it (otherwise they'd stop), why would they not break it here?
In fact, it doesn't even have to be malicious; the data can accidentally be fed into a dataset that's used for ad targeting - maybe it was set up that way a decade ago, nobody knows about it and it isn't entirely obvious considering the entire targeting machine is a black box with thousands of parameters so it's impossible to definitely prove what data was used to target a particular ad.
But if the website uses a URL that is unique for that site, or even for each user, that is absolutely something I'd hold the website owner responsible for.
Chrome sends a unique ID when accessing (only!) google servers, in the form of X-client-data HTTP header, uniquely identifying the user, and the site he is browsing (via referrer). It's a goldmine.
X-client-data: CIS2yQEIprbJAZjBtskBCKmdygEI8J/KAQjLrsoBCL2wygEI97TKAQiVtcoBCO21ygEYq6TKARjWscoB
Also, it would seem to me that the responsibility for such behavior lies with Google and Google Chrome more than it does with individual webmasters.
Seems like laws don't understand how tech works...
It is a common misconception that CDN objects are cached. They are not: https://httptoolkit.tech/blog/public-cdn-risks/
You’ll soon have to fill out a form as if undergoing surgery just to visit a website. (And, of course, were all gonna click “Accept all”, just as we do with cookie warnings and Apple TOS.)
These judges do not know what they do. They only care about getting the case off their desk, clinging to the first semi plausible argument that allows them to do so. If you look for vision, guidance or responsibility for shaping the future I which we want to live, look elsewhere.
That's pretty much the definition of a law. Laws are written for people, by people. Not for computers.
This is sadly an unintended consequence of a very broad interpretation of GDPR, where an IP address is deemed as personally identifiable information.
If someone wanted to take this to absurd levels, similar argument, as has been made by this court, could be used to make the entire Internet illegal under GDPR - sending a packet exposes personal information of the sender to various third parties (routers of various ISPs) that the sender didn't consent to. And given that the recipient (service provider, website, whatever) could have arranged for having the data transferred on a floppy disk or by a pigeon instead ...
It is not only GDPR that suffers from this - e.g. in Austria it is illegal to drive with a dashcam because their court has ruled that a dashcam amounts to recording someone without their consent - and if you do so, it exposes you to a 20k€ fine!
Outside Munich, it gets even worse as you venture deep into beer county where people who can reformat Windows are admired as the next Linus Torvalds and competition consists of people with varying degrees of beginner-level knowledge competing against each other.
Merkel once said that the internet is a new territory for all of us... I am surprised the court even understood half of this.
(Also, no cars. For calling a Ford Model T an “automobile” if it still needs a human driver is misleading to consumers, according to, again, the Munich district court.)
This is incorrect. The font is downloaded regardless of whether a font with the same name is installed on the system.
The only exception is when you specify a local() function in @font-face [0], but almost nobody does that.
[0]: https://developer.mozilla.org/en-US/docs/Web/CSS/@font-face#...
Manipulating a system so that it gives up information that wasn't intended to be given away, is called hacking.
It's not hacking.
If
1. we accept that Google knowing we visit certain websites can hurt a user
2. one can get punished for not fencing of a construction website because someone could get hurt
then in my mind this is a very obvious digital equivalent.
What matters is that the IP will be shared with Google as consequence of visiting the site as long as the user didn't take additional actions and without the user having took additional actions which made that happen.
Really, if you participate in the World Wide Web, of course your computer’s address will be visible to others, and you can not always control it. Like driving on the Autobahn. People will be able to see you. It’s part of life.
The ruling is actually quite logical. The (convoluted) outcome is that the IP is leaked and it should take any tech person about 5 minutes to realise this.
The whole business of littering the web with cookie consent forms is as far from a sensible technical solution to the problem as can be imagined. The people who invented the web and who designed browsers have had at least the aspiration to build a system that’s going to work as a whole. Courts and lawmakers, in the other hand, have no such vision.
> The transfer of the user's IP address in the above-mentioned manner and the associated encroachment on general personal rights
Furthermore, the court is correct in stating that:
> The use of font services such as Google Fonts cannot be based on Article 6 Paragraph 1 S.1 lit. f GDPR, since the use of fonts is also possible without the visitor having to connect to Google servers.
Let's not be naive, we all know the purpose of Google offering these fonts for free via their CDN. As the author of a website, I think it's completely sensible that you should be responsible for the decision of embedding these fonts from Google rather than just serving them yourself: you are, in fact, "leaking" the IP addresses of your visitors to Google without their consent.
This is in my mind just another one of those things that have been considered completely normal for a long time, but really shouldn't. A bit like how literally everyone used Google Analytics 15 years ago without really thinking about what that meant for the ethical processing of personal data.
However, what strikes me is that the court hasn’t even seen this problem at all. Your train of thought - that the request was issued from the user’s browser, but that the site owner was essentially in control because he essentially tricked the user into sharing his information with Google without being asked - is just not being discussed at all.
It might be very well that the end result is just. But then it would be a case of the blind chicken finding a grain.
The site operator chose an optional way to embed fonts in a way that divulges PII to a non-GDPR destination. As there is no legal or technical requirement to embed Google Fonts, the site operator is therefore liable.
If use of Google Fonts was mandatory for the web to function, then the site operator would not have been found liable. It is not: they can be mirrored locally, or simply not used, and the web as viewed from the user’s perspective will continue to function just fine. (IANYL, etc.)
I mean courts are not that dumb, it's still the website owner which decides what is done.
If I ask you to jump from the bridge, and you do, how is it my fault that you chose to comply?
Hosting all your assets by yourself, on your own servers and doing analytics without sending data to a third party is not a terribly tall order.
one could argue that it is less eco friendly as well given how much space is going to be used repeating the same file on a multitude of servers
Frankly, I’ve even found myself doing this without thinking on occasion. The prompts are beyond useless.
(This is assuming you're using uBO, because who the hell isn't these days?)
Twitter is one of those service that just states "we collect data, deal with it when using this website" (which is already not legal) but the thing is, I don't even see this pop-up because uBlock is filtering it out. If Twitter now collects my personal data, it is not only breaking the opt-in component of GDPR but also doesn't even notify me about data collection.
Quite a lot of services have JS-only popups which I also don't see. Do they collect data? I think so. Do they know they are doing it illegally? I would bet quite a bit of money that they never thought about somebody getting past their cookie banner without consenting, so probably no.
Ignorance is a bliss, but if given a choice to not share extra info with random companies, many will in fact take that opportunity.
So a popup warning that your visit to this website will be recorded by Google may be just what the doctored ordered to shake people of their nirvana and make them look at things a bit more closely.
Smart websites would just host the font files on their own domains but I guess the dumber ones will just add Google Fonts and similar to their consent list, yes.
If I host my website behind Google Cloud CDN they have logs of the visitors IP. If I host my site on S3 they log the IP.
Does this mean that a visitor must insteract only with services that I own until I can get concent to use "unnecessary" third party services?
I think it is pretty significant if "necessary" is reduced to "could have don't it without". Because sure I could avoid Google Fonts, but now I need to do splitting and per-browser detection myself. Ok sure, browser font support is pretty consistent these days and I know my site just uses English and emoji in some pages. But now I can't throw that site in cloud storage. I also can't use a VPS because there are traffic logs. So I buy a server in a datacenter. But what if they have some form of traffic logs? I guess my question is where does this definition of "unnecessary" stop.
[0] https://www.taylorwessing.com/en/insights-and-events/insight...
People of course don't mind, reality is often like this too.
[0] https://en.wikipedia.org/wiki/Inline_linking#Controversial_u...
https://developers.google.com/fonts/faq#what_does_using_the_...
It's on the original website to prove that they only use your data for what you asked them to, if you want to do anything else, you need to request informed consent. Using hosted Google fonts is not needed to run the website (as you can also easily embed them without having the user touch Google). And Google will not say they won't do anything with that data, as they would be lying since that's the whole reason google fonts and other free webdev resources by Google exists: to gather as much data about the user it can.
The same does not apply to sideside CDNs.
However, I believe NPM CDNs are the same scenario, so I'd start serving packages from the server as well.
I guess this particular case seems somewhat reasonable, but where is the line.
Also note that Google Fonts is a lot more that just hosting a download. It has different font files for different browsers for max compatibility as well as font splitting so that you aren't downloading too many glyphs and weights that you don't need for this page. Reimplementing Google Fonts isn't trivial.
Whether it is "unnecessary" is the interesting question. For fonts, it's really hard to claim that you couldn't have created the website without Google's fonts CDN.
So perhaps the issue is whether it is necessary/sensible, just for providing a simple font, to contact Google/any cdn.
Spoiler, of course we all know it is not...
translated:
> Google fonts can be used by the defendant in a different way, so that a connection to the website does not make a connection to the Google server, thus without transmitting the IP address of the website visitor to Google.
There is a technical necessity for your hosting provider to see the user's IP.
The GDPR does not require consent for passing on private information when there is a technical or legal necessity, as well as a number of other preconditions.
It looks like the court decided SCCs were not sufficient as Cloudflare is subject to US surveillance laws so they wouldn't be able to provide adequate guarantees.
ELI5: Why does the EU not just prevent Google from using personal data they receive by law in any way they see fit? Would that not be a lot more effective than requiring the millions of small businesses and small web devs to figure it out on their end?
The EU gives companies the option and only requires all this hoopla if you want to use the data for something else than the user requested. The "problem" is that Google does want that, as they are an advertising network, so they give web developers access to their tools but tell you that you have to ask the user for consent. That everyone totally forgets those warnings and somehow forgets that Google is an advertising network is on them, just like it is your responsibility what are random dependencies you download using whatever dependency tool you use.
I think hosting it by yourself is the solution here, but it's getting difficult to keep up with all the rules, especially when the fundamental design of the web moves in the opposite direction.
Browsers partition their caches by origin and third-party origin (it's a bit more complex than that in reality) so common third-party resource e.g. fonts, used on one site won't be reused on another
Instead a fresh version of the font will will be fetched
Safari's done this since 2013 (?), and Chromium & Firefox adopting the same behaviour in 2020 (?)
Do you have a source for this? I believe(d?) it too, but when re-checking just now, I could not find any.
1. In Germany an IP address is considered PI under GDPR because it is easily associated to a natural person.
2. Google is open about the fact that they log IP address with Google Font request activity, which includes the page you are on.
3. GDPR requires justification by necessity to collect and/or send PI to a 3rd party without consent.
4. No consent was given.
5. It is not necessary in this case because it is possible to use Google Fonts in other ways that don't send PI to Google, without significant burden.
I'm not a lawyer but I am responsible for GDPR compliance at a German startup.
edit: typo
Leaking extremely sensitive user data, like their IP addresses, to third parties, enable them to finger print users.
Leaking those to third parties outside the EU, and in particular to companies whose revenue depends on this finger printing, like Google, just to serve a font, it’s the dumbest thing I’ve heard all week.
The whole purpose of the GDPR is to discourage this behavior, requiring websites to inform users of all their crappy unnecessary things they want to do before they do it.
The only reason Google gives you hot loading for free is to get your users data. Trading your users personal data to serve a font is brain dead.
IMO this fine of 100€ is too small. They should have made it 10% of their revenue to send the clear message that this is not ok.
100€ was fine in my opinion, because a) it isn't that big of an infraction b) it probably was their first offense and c) this legal ruling is indeed setting some kind of precedence and therefore was unexpected given industry practices. If the ruling stands and other courts follow a similar reasoning I would expect higher fines in the future.
As long as a sane Referer-Policy is set, the Referer won't be sent. Sure there's a lot more to browser fingerprinting but with just an HTTP request, all the data that would be known from it is the language and the user agent. Both of which are not unique data points and shared by thousands of other users. No cookies either in this case of Google Fonts.
You are logged in to to google and so are your family members.
You visit YouTube.com from IP X with device (user agent) Y.
Your family member visits YouTube.com from IP X with device Z.
Google Fonts gets a request via the API key of mydomain.de from IP X and device Y.
Google now knows that you visited mydomain.de
Edit: I stand corrected that Google Fonts doesn't use an API key. I suspect they still can correlate the font request with the domain, however I have no proof.
Consider this an example for other services like maps.
So it's actually interesting that the court only focused on the IP-address although the ruling would probably have been the same even if they widened the scope.
The request doesn't include cookies (and they're served from fonts.googleapis.com so wouldn't include google.com cookies).
So the question isn't how useful the single request is, but rather what can be done with a lot of these requests. And Google and Facebook are specialists in generating lots of said requests with services like google fonts and like-buttons. And once you realize that the sum of these requests is so valuable that they are considered personal information, you want to protect them with laws.
These laws, like the GDPR, are already in place and this is one of the instances where someone didn't respect such a law. So you can argue now, that this single request isn't so valuable, but isn't that true for every penny of a million dollars?
Your thoughts about a like button widget, or even Google Analytics are perfectly valid. But I am talking about this specific topic under discussion, Google Fonts.
If it is not technically necessary. And a CDN rarely is. I can show you some sites that do without.
Dynamic IP addresses are a piece of PII (personally identifiable information) to the maintainer of a website. That's because the maintainer can identify the person using their IP with the suport of the ISP and the responsible authority.
The use of fonts services like Google Fonts is not protected by 'Art. 6 par. 1 S.1 GDPR' because the use of the same fonts is possible without connecting to the Google Fonts servers.
The visitor of a website is not responsible to conceal their IP (e.g. with a VPN).
The revelation of the visitor's IP to Google is a violation of visitor's rights. Given that Google is known to collect personal information to the discomfort of the user, the violation can be deemed so severe that it is justified to demand damages.
This means that embedding any resource from a non-GDPR destination URL is a violation of GDPR law unless explicit opt-in approval from the user is first received.
If you are subject to GDPR law, then the above applies to all sites owned and operated by you and your subsidiaries. If you are not subject to GDPR law, then the above does not apply.
Resources could be hosted by http:, https:, ftp:, or any other protocol. Resources could be .js, .gif, .html, or any other format.
If you’re asking “can I dynamically detect the user’s country of origin and enable GDPR protections only if I determine they’re in that country?”, no: the user has a right to legal protection if they are a citizen of a GDPR-protected country and are residing in a GDPR-bound country, regardless of what their IP address is.
(I am not your lawyer, this is not legal advice.)
Nit pick: GDPR is written in terms of people "in the Union", not citizens.
If you have agreements in place with third party data processors to protect user privacy, this ruling does not prevent you from hot linking third party assets under that agreement. In effect, the third party acts as part of your infrastructure - just like you may already use a third party hosting provider, cloud database provider, auth provider, logging service, etc.
The GDPR constrains how PII is stored and processed. It doesn't stop you from using third party providers, but it does make you responsible for ensuring user privacy is protected, by delegation through binding privacy agreements and sufficient diligence.
Those types of agreements are already common. For example, if you're hosting on AWS providing service to users covered by GDPR, you should already have such an agreement. It's pretty straightforward. https://aws.amazon.com/compliance/gdpr-center/
Therefore if AWS offered a generic, third party font hosting or embedded video hosting service, you could hot link to that no problem.
Same with Cloudflare, Google Cloud, etc. as long as they provide the necessary agreements with you.
The problem with Google Fonts is there is no such agreement in place, you can't trust Google to not profile users statistically via font requests, and even if Google says they won't do that, you can't trust that their servers in the US won't be tapped by US authorities to monitor request logs, etc.
It's only possible to go this route if the country has the approval of the EU through the necessary legal frameworks. That's what Privacy Shield and its predecessor were, and both were deemed insufficient.
Your point about a data processing agreement is true, but I wouldn't rely on AWS/Cloudflare/Google until the EU and USA manage to get this stuff worked out.
There is literally no other business reason for Google to maintain Google Fonts, but to augment its tracking insights. None. That's the sole purpose of the very existence of Google Fonts.
We've literally spend tens of thousands of dollars on our font archive, but decided that we can't continue to use these fonts on projects anymore, due to "we can change the licence at any time" clauses and rent seeking behaviour, that is eerily similar of the stock photo industry licensing (which pretty much has ruined photographers) and scientific publishers (which pretty much have ruined science).
I hate google as much as the next guy, but our small design company is in their dept for creating google fonts, and we plan on contributing to the the repository if we ever create a font as part of a project.
I argue for downloading fonts yourself and hosting them yourself: https://google-webfonts-helper.herokuapp.com/fonts
But let's not pretend that isn't an extra step that some people regard as unjustified.
A secondary, but similar, issue, is that now all embeds are opt-in: streams, videos, everything must first be clicked on to even load the thumbnail.
A third, and less-important, issue is that advertising providers are basically over: the website, on load, can't query the third-party ad service to figure out what ad to display. Which I'm fine with, abstractly, but it's also a very large revenue issue.
This is fairly fundamental under GDPR. It's the 'data controller'/'data processor' split.
I suspect (but IANAL of course) that most CDNs would fail here, because the blanket agreements they offer are basically worthless.
But it's easy to imagine a CDN that has a different business model (charges a tiny amount pr. resource stored, for example), and is completely fine under the GDPR.
It would be so much better to just reduce and safeguard that information instead of handing it out to any rando with a court order.
I say this as someone who does use Google Analytics as well (which I am removing). But mostly for me it isn't a case of dropping all third party convenience services, but a case of remembering to be _mindful_ of what I'm doing.
Here's why: the driver is just doing what it's told to do. The responsible falls on the party who does the telling. If a website tells my browser to load resources from Google, it's not on my cpu or my nic or its driver or kernel or firewall or the browser.
No need to backtrack.
> The website has delivered an HTML document. It's up to the user to do what he wants with it and follow links or not.
Plus in theory fonts optimised for the respective combination of browser and OS. The former probably isn't as critical any more, as almost everything should support WOFF2 (or at the very least WOFF) these days, as for the latter – I know OSs each have their own font rendering peculiarities, but no idea how much the difference might be in practice.
Nowadays, cache is partitioned by website (https://developers.google.com/web/updates/2020/10/http-cache...)
My question is, why aren't we worried about the hops between a website and a user? There's who knows how many networks and routers in between them, and the packets might even hop outside the EU momentarily (!!!!!). Surely this needs some attention as well? Should we maybe consider an internal EU-only network? Or maybe the Commission could come up with a whole new routing scheme? I'm sure Europol would have tons of very sane ideas for one.
I asked about this below, apparently it's reasonable and strictly necessary. It's what the user expects. Even though it's technically possible for the infrastructure layer to provide full packet anonymity, until then it's the web developers responsibility. I do not agree with this, but that's my opinion.
Am I getting this correctly or not?
I cannot sign that I will sell my firstborn, but _technically_ I've read, understood, and accepted a contract
By default it should be <<opt-in>>, not <<opt-out>>.
You don't get to track me and then force me to tell you "don't track me", you should do nothing by default and ask me "may I track you?".
Companies don't do that because opt-out is sneaky and it means they can track, say, 95% of users.
With out-in, they get to track maybe 80% of users if they're allowed to use dark patterns (where they hide stuff or lie to the user what tracking actually does) and probably less than 10% if they're not allowed to do that.
The assumption from most people seem to be that they used a `<script>` tag or the like, with a Google URL. But the text does not imply that. On the contrary, it repeatedly uses the word "weitergabe" and "weiterleitung" ("forwarding"), which is just not accurate for this process - it seems to imply that the defendant actively made a connection to Google and sending the IP over it.
Of course, this might just be an artifact of the legalese and non-technical phrasing of the verdict. But does anyone know what actually happened, on a technical level?
As a user I don't want any of my data going to third parties at all.
As a website owner trying to provide a service to my users I want the best experience for them. This might be linking to third party services that are doing a better job than I could.
I only see this going one way. The user will have to agree to the sharing of their data with third parties if they want to view third party content, or want the fonts rendered in a better was. Link NPRs text version when you don't agree.
This is a serious question, I personally prefer to set my own font for web browsing so why do people feel the need to force fonts on me and load them from google of all places?
Also consent may not actually help here because the principle of data minimisation applies no matter what legal basis for the processing you use.
I understand the privacy sentiment, but I find this the opposite of how you beat a giant. The proper way for Germany and the rest of Europe should be the creation of a thriving environment of viable, privacy-aware FAANG competitors. Not putting barriers in every which way.
This is literally the day job for everyone on HN: checking so you don't accidentally log IPs.
-Benedict Evans
1) finally webmasters can feel the absurd amount of data they push on us for goddamned shiny JS that barely runs on my phone. Maybe they'll cut back a little
2) Hopefully this incentivises a bit more clear border segregation. More technical effort? Yes. Better for my privacy? Hopefully.
I don't like the language here though, specifically the lack of anything directly supporting my stance. But I prefer optimism and then realism
In my opinion, this should be _welcomed_ by WebDev community - this does improve privacy. In theory, DE court is right - your website should force user to connect only to itself.
I clearly see 2 ways of making this even simpler: use Lynx :-) or Tor Browser. The importance of Tor in today's business should increase. Yes, there are "shady" things there - but there they were in "clearnet" back in 90x ...
Makes sense.
Edit: in fact PII should not pass unencrypted, so if you don’t protect the IP (classified as PII) then you‘re not compliant.
Google will continue to be Google. Users will be faced with more annoying consent notices that they don't read. Website developers, of which I am one (bias disclosure), who are not very good lawyers will have more technical complexity in order to respect the law. Small companies who rely on services such as CDNs and font providers are now worried about having to host things themselves and the complexity that will ensue to be GDPR compliant (everyone's new least-favourite term). Hacker News gets a divisive flamewar over the subject and this will be yeeted from the front page.
The services (here: web fonts) could be supplied another way, so exposing the user's IP to google is not strictly necessary, from a technical POV.
The user's IP is PII, and exposing it unnecessarily to third party is a GDPR violation.
The way this is phrased, the reasoning applies to basically every static resource loaded from a CDN or other third-party website.
What would a technical solution that respects privacy look like? The website making the call to Google in the background (minus user details) and forwarding the response onward? Why isn't it done that way, it feels like it's the more obvious solution if you're not trying to track users.
Early internet was very wary of 'hotlinking' because it costs money to serve things, people used to try to offload hosting costs to others. Now it seems people take that on willing with the expectation to make enough money to cover it.
Is it just scale, or is it the user info that makes these services viable?
Early Google used to use the argument that them making the web better was profitable, because more people using the web meant more money for them. Does that still apply? Would they still provide Google Fonts if they were legally bound to not use any user information they recieved?
In case of fonts: hosting it on your domain.
I don't think there is a solution right now. Maybe browsers can stop sending these headers to well known CDN domains by default.
This is particularly true for anything that comes as a „module“, like GDPR cookie notices (that are very frequently included via a JS snippet loaded from a third party site).
Because an IP address needed to receive a download. This kind of decision means that any hot linking of static media assets is now in hot waters.
A sensible judge would say IP address is not PII but a prerequisite to use Internet in the first place. Like a license plate on car e.g. other broken analogue of tracking. Like a power socket. However the definition of PII in Europe is overly capturing (saying this as an European.)
Like with IPs, they wouldn't be able to identify unique individuals with 100% certainty (as both IPs and cars may be shared), but they'd get pretty close. Certainly when it can be combined with other data.
So yeah, to me it makes sense that IPs are personal data.
The problem here is that every service could be provided another way. It seems that the only actual hosting option that doesn't leak a user's IP to a thrird-party is first-party only over Tor. Do we demand that every website is built that way? It turns out that outsourcing actually has a lot of value.
So where do we draw the line? Google Fonts apparently needs to be reimplemented first-party. What about Google Cloud CDN? What about an ISP that sees the user's IP in the packets?
Seems as though anybody who uses a CDN or third-party to load _any_ resources will violate GDPR by this measure? Seems like a pretty wide interpretation of this law.
* the court explicitly stated that this case was about transferring personal data (the IP) without prior consent. If the user had consented, there would have been no case.
* the court explicitly criticized using google, because google a) is known to collect user information and b) google is a US company and the European courts have found the US is lacking in privacy laws. So my reading is that the judgement would not apply if you transferred such data in certain circumstances, e.g. if you transferred such data to provide "essential services" and you have contracts with the data processor about how they can use and store the data that are in accordance with German privacy laws.
* the court further stated that it sees no reason to transfer such personal data, as the website could have easily provided the fonts itself. This seems to be a crucial part of the courts reasoning, as it is a ruling on the plaintiff's claim that this use of google was exempt because it was "necessary" to provide the service.
That was my initial reaction, but I must admit I have since decided that was because it's an inconvenient truth to me. No one visiting mydomain.com should have to assume google.com is going to receive information about them without their prior consent, and there's usually no mechanism for consent prior to loading webfonts or CDN assets.
It is very much in the spirit of the GDPR that all knowledge sharing should have prior consent, and this follows with that.
You can see the industry flailing to compensate for the sudden increase in responsibilities it has been getting recently. It's not a wild west anymore, we should be a mature industry, and mature industries have regulations earned from previous failures to be ethical or safe. That's what I see happening, the industry is getting harder to operate in, but it's just reaping what it sowed.
The court also noted that there was an alternative in the form of embedding the fonts directly into the website.
I'm not a lawyer, but the reasoning doesn't sound like CDNs are a problem in General, but that one should be very careful before connecting to US servers (which was always one of the goals of the GDPR)
Since you have no control over what Google does with the data of visitors when you embed Google Fonts, it is not compatible with the GDPR (just like Google Analytics).
https://de.wikipedia.org/wiki/Datenverarbeitung_im_Auftrag https://www.gdpr.org/regulation/article-28.html
This is a good decision by the court. Sure, web developers may not like it, but it may force them to improve on how they work.
1) Your IP address is considered personal data, as it can be used to identify you. In general, everyone can see and agree with this.
2) In the absence of additional protections and/or contract terms[1], the transfer of personal data out of the EU is an offense under the GDPR (well, technically it's not out of EU, but transfer to a country without GDPR equivalence).
So - embedding code / data from a 3rd party into your website results in a transfer of personal data.
[1] The idea of additional protections/contract terms is even questionable, but that's a whole other thing...
They say that GDPR Art. 6 Par. 1, (f) (see [1]) is not applicable, so using a webfont from google is not "necessary for the purposes of the legitimate interests pursued by the controller". They explicitly say this is because you could host the font yourself.
In my interpretation, another way could be to use Art. 6 Par. 1 (a), namely ask the user for permission before loading a Google font.
The whole thing, including guides, is much shorter than the spec for HTML: https://html.spec.whatwg.org/multipage/
Probably clearer, too.
And just like for specs there are even better third party doc sites you can use: https://gdpr-info.eu/
Dry reads, but it's not like RFCs are heart wrenching novels either :-D
Edit: clarification
on the other hand, always host your fonts
I'm not kidding. Countries like Denmark and Estonia are light-years ahead of Germany in terms of eGov and mobile payments.
Outrageous!
And yes that means they can not integrate services from surveillance states like the USA or China without asking the user first, as the EU government thinks only their agencies should be allowed to run mass surveillance against their citizens without consent.
And the EU is not the only one who thinks like that. Pretty soon services controlled by foreign powers will be unacceptable in most of the world. Currently in the USA this is limited to hosting government and military secrets on foreign systems, but i bet if some chinese network would start to creep all over the civilian american web, reporting back to their ministry of national security, the rules would change quickly. For now the USA uses its position to spy on everyone, and i don't mean "nations" or "governments", i mean everyone. American patriots don't see a problem with that, but we know what you do in Utah, and it's a crime against humanity.
For the multinational corporations this whole situation of GDPR-vs-CloudAct means massive restructuring, splitting into smaller entities that service regional markets and moving the top level corporate group somewhere with minimal regulation to minimize conflicts. And such legal splits rupture their core business, at some point they can't have chinese hardware in us datacenters being administrated by indian technicians providing services to russian tourists in brazil anymore.
Maybe this is the last battle the nation states fight with the global corporations and it instead breaks nationalism in favor of streamlining compliance and getting shit done. I can only hope that the global rules emerging say no to mass surveillance and yes to data privacy, but abusing human rights has always meant power and profits, and so i fear the future is dystopian.
If so, how do we avoid breaking the web while keeping privacy needs in balance?
One thing that I feel would help: Massive decentralization. Self-hosting of content and regular synching of the hosted content on the server sides; or tunneling, think duckduckgo.
Self-hosting would make knowledge storage more redundant which protects against (also partial) network blackouts.
On the other hand this knowledge is then harder to control. Removing or redacting content would have to rely on the particular sites to "pull the updates" from the upstream. Copyright will also be problematic: each site would have to make copies of content with the (probably commercial) intent of serving it to consumers.
Still I can't help to think we need more decentralization and self-hosting.
The paper-pushing world created by GDPR and these non-technical bureaucrats is just absurd and only a burden for smaller companies trying to get things done.
GDPR is clear about processing personal data. If you're a website, you're a data controller, and you are responsible for the security/confidentiality/etc. of that data. If you want to use external services that's cool, but you need a formal data processor agreement in place that maintains your control of the data, and you need to list that in your privacy policy.
So, can you embed fonts? Yes, it's not a problem: either they should have directly embedded self-hosted stuff and not used the supplier, or ensured a proper data processor agreement was in place. Post-Schrems II, the latter becomes more difficult if the supplier you're contracting with cannot promise the level of control over privacy/etc. that you need as a data controller, however.
The alternative position is to say that it's OK to embed resources that basically allow large corporates like Google to track your activity across the web without an agreement in place. That's obviously not OK under GDPR.
https://news.ycombinator.com/item?id=16910675
you'all buried the comment as you didn't want to listen but, as I said back then, reality doesn't care about fake internet points.
but hey, you liked gdpr right? it's going to be fun for ambulance chaser around europe: https://news.ycombinator.com/item?id=16910301