#5065 - Google fonts violating GDPR / General privacy around IP and referrer transfer to third parties / Need superset of cookie consent

Identifier #5065
Issue type Feature request or suggestion
Title Google fonts violating GDPR / General privacy around IP and referrer transfer to third parties / Need superset of cookie consent
Status Open
Tags

Roadmap: Over the horizon (partial implementation) (custom)

Type: Legal compliance / Privacy (custom)

Handling member Deleted
Addon core
Description At the beginning of this year, a website in Germany was fined 100 euros for using Google Fonts which violates GDPR by collecting IP addresses. We can enable a Google Font via HTML_HEAD.tpl in v10 but the latest advice is to run these fonts locally.

This website ( https://google-webfonts-helper.herokuapp.com/fonts ) grabs all the necessary files to host a chosen Google font locally. Removing the option to enable a remote Google Font in the header and adding some documentation about how to serve these fonts locally might be advisable given a precedent has been set.
Steps to reproduce

Additional information https://www.bitdefender.com/blog/hotforsecurity/german-website-fined-100-euros-after-court-says-googles-font-library-violates-gdpr/
https://www.gdpreu.org/the-regulation/key-concepts/personal-data/
https://2gdpr.com/
Related to

#4914 - Radical Privacy (holding issue)

Funded? No
The system will post a comment when this issue is modified (e.g., status changes). To be notified of this, click "Enable comment notifications".

Rating

Unrated