German regional court just dropped a total bombshell of a ruling today. Court decided that the way how virtually all modern websites function, is actually illegal under the European Union GDPR legislation.
And all this over a 100 euro fee.
Behind all the madness is a court case against an unnamed German website, a lawsuit filed by a single person. And because the website used a specific font.
The website had embedded the Google Webfont to its pages directly from Google Fonts' servers - just like appx. 50 million other sites do.
But how the Internet works, this also meant that the user's browser not only downloaded the website requested, but also the font needed to show the page as intended. And while the user had obviously given the permission to hand out his/her IP address to the website in order to be able to use it in the first place, he/she didn't give the consent to connect to Google servers (in order to get the font).
His browser - as it should - contacted the Google server in the background in order to get the font for the website. And obviously, any connection through the 'net will also reveal the users IP address. And according to the user, he/she had not given explicit permission to do that.
And court agreed.
According to the court, the website in question could have had the font stored locally on its own servers and thus, to avoid the connection to Google servers. And also, according to the ruling, now Google got the users IP address and can potentially do unholy things with it, like build a profile of the user.
Surely, Google's font library can be self-hosted, but it typically isn't, as loading it off Google's servers allows users browsers to find the very same font in cache more often, as different sites tend to use the same fonts (and cache is detected by the entire domain URL address of the font file).
But the ruling also effectively bans all kinds of embedding (without the user's explicit consent): whether it is YouTube videos embedded to news articles or to use CDN-hosted jQuery libraries on your website. Oh, obviously Instagram embeds and stuff like Google Analytics are banned, too.
Few weeks earlier an Austrian court ruled Google Analytics illegal in Europe.Permalink | Comments https://www.afterdawn.com/news/article.cfm/2022/01/31/embedding-illegal-europe-gdpr
Login to add comment
Other posts in this group
Sure, there were digital music players well before Apple introduced its first iPod back in 2001. But iPod was the device that made digital music a mainstream reality.
It also paved a way for new mus
After the initial developer edition, Google has now launched the first official beta version of Android 13 operating system.
While the developer edition, launched back in February, was meant for .. w
Sometimes history is shaped by small steps, leading into giant leaps. Those steps were taken in late 1990s by several tech companies - and as the result, the entire music business industry went throug
Google introduced a new measure for Android phones with its Android 12 operating system. The new measure, dubbed as Performance class indicates to app developers how good the phone is, performance-wis
Since late 2020, OnePlus has been struggling to push out its Android updates in timely manner, which has frustrated its loyal fans quite a lot. But finally, some relief is coming: Android 12 goodness
For recent years, Sony, has had a very limited selection of phones available globally. But even with a limited selection, company's track record for delivering Android updates hasn't been exactly a to