Then GDPR should blame the browser vendors for shipping with JS execution enabled by default and demand that JS execution for all browsers be turned off by default. To repaint the stories spun by the grand parents: If I hold up a dagger and announce the fact, why would you run into the dagger anyway without protection? Put on some armor, dude. The client browser had all the information it needed to not make the request (geolocation, external resource, purpose of external resource) and yet it did. I know this is just shifting blame but it's also a good argument for returning HTTP 451 to EU clients and be done with it.