See the link in the first sentence of the article and, if necessary, scroll down a bit to the "English Version" heading:
<https://rewis.io/urteile/urteil/lhm-20-01-2022-3-o-1749320/>
In short, importing a remote font exposes the user's IP to the font provider, which (that court has ruled) is a violation of the GDPR:
> The disclosure of the user's IP address in the above-mentioned manner and the associated encroachment on the general right of personality is so significant with regard to the loss of control over a personal data to a company that is known to collect data about its users, and the individual discomfort felt by the user as a result, that a claim for damages is justified.
And German law makes it really easy for lawyers to extort money by C&D letters.
Honest question: Can't we have an unified EU set of sane IP laws that supersede the shitty ones from Germany and make them illegal?
We abolished roaming charges and have a unified border across Schengen and a unified currency in the Eurozone and soon the whole consumer industry including Apple will be on USB-C.
If those were possible, surely we can fix EU IP laws.
Seriously, GDPR has been around for over four years now, everyone should have gotten the message now that sending data to third parties without consent is an absolute no-go.
Also, "Court Rules Websites Embedding Google Fonts Violates GDPR ", 97 comments, 8 months ago, https://news.ycombinator.com/item?id=30527427 .
The latter links to https://thehackernews.com/2022/01/german-court-rules-website... which starts:
> A regional court in the German city of Munich has ordered a website operator to pay €100 in damages for transferring a user's personal data — i.e., IP address — to Google via the search giant's Fonts library without the individual's consent.
Shouldn't the cloud be illegal too then? By hosting on AWS/GCP, you are leaking the IP addresses to the cloud providers after all!
For hosters where the data transmission is a technical requirement, you don't need consent at all, but you need to enter a data processing agreement ("Auftragsdatenverarbeitung" in German) with the hoster and make sure that data transmission and recording is as minimal as possible (e.g. anonymize IP addresses in logs, delete logs after 2 weeks, keep data in EU cloud regions if possible).
I'm still not convinced this is enough. The US "CLOUD Act" can force employees of a company to pull data even when hosted in foreign countries. If an ops engineer technically can give themselves access they can be forced to do so by the US federal government. That is my understanding anyway.