#5065 - Google fonts violating GDPR / General privacy around IP and referrer transfer to third parties / Need superset of cookie consent
| Identifier | #5065 |
|---|---|
| Issue type | Feature request or suggestion |
| Title | Google fonts violating GDPR / General privacy around IP and referrer transfer to third parties / Need superset of cookie consent |
| Status | Open |
| Tags |
Roadmap: Over the horizon (partial implementation) (custom) Type: Legal compliance / Privacy (custom) |
| Handling member | Deleted |
| Addon | core |
| Description | At the beginning of this year, a website in Germany was fined 100 euros for using Google Fonts which violates GDPR by collecting IP addresses. We can enable a Google Font via HTML_HEAD.tpl in v10 but the latest advice is to run these fonts locally.
This website ( https://google-webfonts-helper.herokuapp.com/fonts ) grabs all the necessary files to host a chosen Google font locally. Removing the option to enable a remote Google Font in the header and adding some documentation about how to serve these fonts locally might be advisable given a precedent has been set. |
| Steps to reproduce | |
| Additional information | https://www.bitdefender.com/blog/hotforsecurity/german-website-fined-100-euros-after-court-says-googles-font-library-violates-gdpr/
https://www.gdpreu.org/the-regulation/key-concepts/personal-data/ https://2gdpr.com/ |
| Related to | |
| Funded? | No |
The system will post a comment when this issue is modified (e.g., status changes). To be notified of this, click "Enable comment notifications".


Comments
"The unauthorized disclosure of the plaintiff's dynamic IP address by the defendant to Google constitutes a violation of the general right of personality in the form of the right to informational self-determination according to ยง 823 Para. 1 BGB," the ruling stated, as algorithmically translated. "The right to informational self-determination includes the right of the individual to disclose and determine the use of their personal data."
This is pretty absurd. An IP alone only identifies that some machine on a particular network was turned on at some time and went somewhere-unknown to request a common font. That's an incredible stretch of personally-identifying.
This judgement would block:
- hot linked images
- CDNs
- Any remote-hosted ad hosting platform
- Any remote-hosted analytics platform
If we were talking about referrers, that's another story. I can legitimately see why we would want to block referrers to Google Fonts and CDNs, as they have no business knowing it (actually we could consider Google Fonts a kind of CDN).
When it comes to hot linked images, or even outbound links, it becomes thorny. For privacy we could say no outbound link should pass a referrer, yet knowing referrers is very basic for digital marketing. It probably should be an option to block all referrers, on by default.
We can use "referrerpolicy" to limit individual a/area/img/iframe/script/link elements to not send referrers.
However, referrerpolicy does not allow granular limits on video/source/audio/object/track/embed/input (https://github.com/w3c/webappsec-referrer-policy/issues/160)
We need fine-grained control really. We also need WYSIWYG to be able to set that control.
I think it'll be a while until everything catches up.
Looking at our code, we currently have non-bundled addons that hotlink to Google for data-map embeds (COUNTRIES_ON_MAP and PINS_ON_MAP templates), eBay and Amazon for embeds, Facebook embeds, and Twitter embeds.
In bundled, we have Google Translate for language editing, and Google Analytics. Also any kind of media system remote video embed, like YouTube.
All this stuff is potentially going to want to be able to check referrers for security reasons, and if it's not by HTTP it could be by JavaScript.
I have disabled tracking on YouTube and Vimeo embeds using their method to do so.
Changes potentially for v12...
Add to privacy policy if:
1) Google Fonts is enabled (explain IPs may be leaked)
2) Google Analytics is enabled (not just about cookies as it is now) (explain IPs and origins may be leaked)
3) Google Translate is enabled for translating (explain IPs and origins may be leaked)
Add new privacy policy section regarding embeds, and document the following embeds could leak visitor IPs and origins and tie users to a remote site's own cookies, and that's all outside our control (as JS code we are not directly prescribing is running):
1) YouTube video (new option to disable YouTube embeds, so privacy clause only shows if enabled)
2) Vimeo video (")
3) Facebook video (" - and disabled by default)
4) oEmbeds (list all domains oEmbed is enabled for, or omits clause if no oEmbed domains are listed)
5) Data maps/eBay/Amazon/Facebook/Twitter (if the relevant non-bundled addons installed)
New privacy option to turn on <meta name="referrer" content="same-origin" /> in the header easily to entirely block referrers that aren't explicitly inclusion-listed. On by default. Must clearly explain that partners cannot enable embed/API access from your server or track your outbound links based on referrer - unless you are individually marking things up to allow referrers, and that is not currently possible for videos/audio. Partners could implement tracking via tracking IDs on URLs, or where applicable via the JavaScript code they run. In any case any such tracking should be reported by manually adding it to your privacy policy.
Disable all embeds until Cookie Consent (or some replacement) is properly agreed to. Needs to be more than a yes/no now.
Other stuff discussed in the privacy policy may need to be disabled too if not agreed to. Case-by-case basis, as we can't just disable IP block checks.
#4914 talks about a new privacy tutorial. Document stuff discussed here there too.
There is also https://cookieconsent.popupsmart.com/gdpr-cookie-consent/ which is free and allows a company logo and also what I assume is the older version (still claims GDPR compliance but offers more layout/theme options) @ https://cookieconsent.popupsmart.com/.
Another which is free @ https://tarteaucitron.io/en/ - easy to add services with autocomplete dropdown.