Forum Moderators: webwork
Website fined by German court for leaking visitor's IP address via Google Fonts
Earlier this month, a German court fined an unidentified website €100 ($110, £84) for violating EU privacy law by importing a Google-hosted web font.
[theregister.com...]
* personal data can flow from the EU (and Norway, Liechtenstein and Iceland) to that third country without any further safeguard being necessary. In others words, transfers to the country in question will be assimilated to intra-EU transmissions of data.
The European Commission has so far recognised Andorra, Argentina, Canada (commercial organisations), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea, Switzerland , the United Kingdom under the GDPR and the LED, and Uruguay as providing adequate protection.
[ec.europa.eu...]
I don't know why people bother with fonts anyway.
I don't know why people bother with fonts anyway.
these files need to be hosted in the EEA or in an approved country*, otherwise you are in trouble.
When loaded from fonts.googleapis.com, an EEA visitor will in most cases be downloading the font from an EEA server. Same with the AdSense (a ping to pagead2.googlesyndication.com from NL comes back with 8ms latency). Ultimately the data collected on that EU server will be flowing to the US; but is that our responsibility?
We need to differentiate here:
Germany:
Also, to me, it looks like all sites using AWS, are hosted in the USA...