Google Fonts Illegal in EU
usecue.com
usecue.com
By this logic, it sounds like all forms of hotlinking would be illegal, not just fonts but images, js, css, etc. How does a modern website operate under this law? Are there other options besides: 1. locally hosted resources, 2. an annoying consent popup ?
Tangent: I found this 2018 article about a list of websites that block visitors from GDPR countries. I wonder how many of these blocks are still in place today. I assume they were removed after the websites became GDPR compliance.
https://econsultancy.com/gdpr-which-websites-are-blocking-vi...
As far as I understand it, the only situation where you are allowed to send a third party request without consent is one where there are no other ways to achieve whatever the request is in service of, and that whatever itself has to be something you don't need consent for ofc. Assuming I've got that right, then that's a no for images, JS and CSS.
As someone who has seen the web evolve from basic pages to the apps of today, the way “modern websites” are currently built is absolutely horrific.
Web developers don’t seem to have any qualms about pulling in random crap from random places, and those random places can pull in more crap. It makes it impossible to get a simple baseline for security without an army of people reviewing code, and the web devs just shrug and say “that’s how everyone does it now”.
If these laws pour cold water on some of this and force web devs to shape up, that’s fine with me.
Would it be legal if downloading the fonts off Google's servers was behind a cookie wall, along with the tracker codes and the like?
The time of CDNs like that is past, in part due to them not being effective, in part due to hungry data collection schemes. Don't use CDNs, reduce or avoid 3rd party communications on your website.
Legitimate tracking is fine, just don't share it with 3rd parties like google. I'm sure there's analytics options that can be installed on your own server.
Not that remarkable. If they do that then they are taking responsibility for informing users about legal requirements, and effectively volunteer themselves to monitor and interpret laws in all jurisdictions across the world (they do this anyway for their own legal concerns, but they won't want to accept responsibility for accurately assessing the situation for others).
Browser-specific features are what got the world in such a mess being tied to MSIE 6 for so long. i can't count how many times i heard "we have to use MSIE because it's the only browser which supports X" the first decade of this century. (Where "X" was normally "COM", which was frequently used in Enterprise-level web apps.)
The fewer browser-specific content-side capabilities (as opposed to non-web-page capabilities) there are in browsers, the better it is for the world.
Yes, ish. So not really.
If you add them all to the OS font store then all those fonts are available to other applications (probably good) but this may be an inconvenience to a lot of users by making it hard to find the few fonts they actually do use for other work (almost certainly bad).
If you don't add then to the OS font store then they only work with your browser.
Also, even if you did add them to the OS font store, it still doesn't work on other browsers unless they also have yours installed.
Also 100 fonts in a range of sub-styles (italic/not at least) and weights (at least bold/not) could be an extra 100Mb of stuff that you are adding to your installer and application footprint (potentially significant on small devices like non-flagship phones) which may be very rarely used (the majority of sites don't use Google Fonts).
Furthermore, how do you pick the 100? Is that enough to cover enough cases to actually be useful? A site using specific fonts is likely to want something really specific and there are approaching 1,500 options on Google Fonts, so the top 100 might not cover a significant proportion of sites using the service.
The point of web font loading is that a site can use what it wants without having to worry about whether it is already available on any given client device or not.
Why not just build this law into the browser?
Do you also need user consent before sending users to an edge cache like cloudflare?
This is what cookie banners are trying to emulate.
> Do you also need user consent before sending users to an edge cache like cloudflare?
Don't tell them! But, yes you do, if the operator falls under jurisdiction outside of the EU.
But my reading of https://advertising.amazon.com/resources/ad-policy/brand-usa... says you can host the logo yourself.
> Third-party vendors and sellers on our marketplace are permitted to display the “available at Amazon” logo in their ads to promote the availability of their products and services at Amazon. No formal review or approval is needed to use this logo.
And German law makes it really easy for lawyers to extort money by C&D letters.
Honest question: Can't we have an unified EU set of sane IP laws that supersede the shitty ones from Germany and make them illegal?
We abolished roaming charges and have a unified border across Schengen and a unified currency in the Eurozone and soon the whole consumer industry including Apple will be on USB-C.
If those were possible, surely we can fix EU IP laws.
Seriously, GDPR has been around for over four years now, everyone should have gotten the message now that sending data to third parties without consent is an absolute no-go.
Also, "Court Rules Websites Embedding Google Fonts Violates GDPR ", 97 comments, 8 months ago, https://news.ycombinator.com/item?id=30527427 .
The latter links to https://thehackernews.com/2022/01/german-court-rules-website... which starts:
> A regional court in the German city of Munich has ordered a website operator to pay €100 in damages for transferring a user's personal data — i.e., IP address — to Google via the search giant's Fonts library without the individual's consent.
See the link in the first sentence of the article and, if necessary, scroll down a bit to the "English Version" heading:
<https://rewis.io/urteile/urteil/lhm-20-01-2022-3-o-1749320/>
In short, importing a remote font exposes the user's IP to the font provider, which (that court has ruled) is a violation of the GDPR:
> The disclosure of the user's IP address in the above-mentioned manner and the associated encroachment on the general right of personality is so significant with regard to the loss of control over a personal data to a company that is known to collect data about its users, and the individual discomfort felt by the user as a result, that a claim for damages is justified.
Shouldn't the cloud be illegal too then? By hosting on AWS/GCP, you are leaking the IP addresses to the cloud providers after all!
For hosters where the data transmission is a technical requirement, you don't need consent at all, but you need to enter a data processing agreement ("Auftragsdatenverarbeitung" in German) with the hoster and make sure that data transmission and recording is as minimal as possible (e.g. anonymize IP addresses in logs, delete logs after 2 weeks, keep data in EU cloud regions if possible).
I'm still not convinced this is enough. The US "CLOUD Act" can force employees of a company to pull data even when hosted in foreign countries. If an ops engineer technically can give themselves access they can be forced to do so by the US federal government. That is my understanding anyway.
The Google Fonts FAQ pretty unambiguously states that Google does not use fonts for tracking individual users:
The Google Fonts API is designed to limit the collection, storage, and use of end-user data to only what is needed to serve fonts efficiently. The use of the Google Fonts API is unauthenticated and the Google Fonts API does not set or log cookies. Requests to the Google Fonts API are made to resource-specific domains, such as fonts.googleapis.com or fonts.gstatic.com. Font requests are separate from and don't contain any credentials sent to google.com while using other Google services that are authenticated, such as Gmail.
https://developers.google.com/fonts/faq#what_does_using_the_...
If that's all true, I don't see how GDPR would come into play.
Oh and promises from Google? We won't close Stadia?
Also this point is moot since the transfer itself is illegal.
So yes pulling anything from an Ad-Company is illegal.
[0] Kontrollverlust über ein personenbezogenes Datum an ein Unternehmen, das bekanntermaßen Daten über seine Nutzer sammelt und das damit vom Nutzer empfundene individuelle Unwohlsein so erheblich, dass ein Schadensersatzanspruch gerechtfertigt ist.