9 ms·
After translating - the violation here is a website included third-party fonts from Google, and the fact that Google would be able to see their IP from the requ
by bArray 5y ago
After translating - the violation here is a website included third-party fonts from Google, and the fact that Google would be able to see their IP from the request violates GDPR?
Seems as though anybody who uses a CDN or third-party to load _any_ resources will violate GDPR by this measure? Seems like a pretty wide interpretation of this law.
- perlgeek 5y agoThat is exactly my reading as well.
- silviot 5y agoIANAL, but it sounds to me like a very important part of the story is that Google was not listed to end user as entity that would treat their data. Another way to read this could be: failure to inform users that their IP addresses were sent to Google resulted in a 100 € fine.
- bArray 5y agoSure, but this also seems bad for the small web. Imagine for example some small blog embeds a Youtube video into their static page - suddenly they are getting 100 euro fines all over the place. Also this entire case overlooks the point that this user was tech aware enough that they knew their IP was getting sent to Google, was deeply upset by this, but didn't get an ad blocker? This feels like a contrived use of GDPR.
- kiallmacinnes 5y agoHonestly, it's not that big a leap to reach this interpretation. 1) Your IP address is considered personal data, as it can be used to identify you. In general, everyone can see and agree with this. 2) In the absence of additional protections and/or contract terms[1], the transfer of personal data out of the EU is an offense under the GDPR (well, technically it's not out of EU, but transfer to a country without GDPR equivalence). So - embedding code / data from a 3rd party into your website results in a transfer of personal data. [1] The idea of additional protections/contract terms is even questionable, but that's a whole other thing...
- kleiba 5y ago1) Your IP address is considered personal data, as it can be used to identify you. In general, everyone can see and agree with this. Only if you're the sole user of that IP, which is e.g. not the case in a family.
- kiallmacinnes 5y agoI stand corrected - not everyone can agree! In reality, as a service provider, you have no ability to determine if the client IP belongs to an individual or not - so you have no choice but to assume it does identify an individual.
- _ixnm 5y agoThis is ludicrous. Nginx logs are regulated now? What if you just want to make a static website and get on with your life?
- isbvhodnvemrwvn 5y agoYou're not sending your nginx logs to Google, a well known advertiser, do you? In this case you can store IP addresses if you have a legitimate reason (e.g. you can show you need it for troubleshooting etc), as long as it's reasonable and doesn't infringe on the rights of the user, and you have documented it along with the retention strategy.
- rndgermandude 5y agoIt is enough to identify whoever is paying for the internet access, which is enough, in itself. And it might be enough to identify the actual user with "reasonable" certainty, e.g. if the user was home alone at the time the IP was used. Courts found that it doesn't have to be demonstrated that a user can be identified, the abstract reasonable risk that a user could be identified is enough to turn an IP address into PII (and this ruling explicitly mentions this).
- orra 5y ago
- curiousfab 5y agoThis is regulated in the GDPR, article 28. You may have an external "processor" of your data (which is almost always the case, because few people have full responsibility over their hosting setup), but this processor is bound to abide the rules of the GDPR, and you need some sort of contract with the processor. Since you have no control over what Google does with the data of visitors when you embed Google Fonts, it is not compatible with the GDPR (just like Google Analytics). https://de.wikipedia.org/wiki/Datenverarbeitung_im_Auftrag https://de.wikipedia.org/wiki/Datenverarbeitung_im_Auftrag https://www.gdpr.org/regulation/article-28.html https://www.gdpr.org/regulation/article-28.html This is a good decision by the court. Sure, web developers may not like it, but it may force them to improve on how they work.
- arlcode 5y agoThe court explicitly noted that the IP was exfilled to the United States where adequate data protection measures do not exist and that Google in particular is well known for invasive data collection The court also noted that there was an alternative in the form of embedding the fonts directly into the website. I'm not a lawyer, but the reasoning doesn't sound like CDNs are a problem in General, but that one should be very careful before connecting to US servers (which was always one of the goals of the GDPR)
- kevincox 5y agoThat has interesting implications for anycast CDNs. In fact do you now need a separate DNS name for europe to be sure that the DNS query doesn't get anycasted to another country ever?
- red_trumpet 5y ago(IANAL) They say that GDPR Art. 6 Par. 1, (f) (see [1]) is not applicable, so using a webfont from google is not "necessary for the purposes of the legitimate interests pursued by the controller". They explicitly say this is because you could host the font yourself. In my interpretation, another way could be to use Art. 6 Par. 1 (a), namely ask the user for permission before loading a Google font. [1] https://gdpr-info.eu/art-6-gdpr/ https://gdpr-info.eu/art-6-gdpr/
- ehnto 5y ago> Seems like a pretty wide interpretation of this law. That was my initial reaction, but I must admit I have since decided that was because it's an inconvenient truth to me. No one visiting mydomain.com should have to assume google.com is going to receive information about them without their prior consent, and there's usually no mechanism for consent prior to loading webfonts or CDN assets. It is very much in the spirit of the GDPR that all knowledge sharing should have prior consent, and this follows with that. You can see the industry flailing to compensate for the sudden increase in responsibilities it has been getting recently. It's not a wild west anymore, we should be a mature industry, and mature industries have regulations earned from previous failures to be ethical or safe. That's what I see happening, the industry is getting harder to operate in, but it's just reaping what it sowed.
- the_mitsuhiko 5y agoIt seems like if there were a data processing agreement with Google that they don’t process the IP for web fonts it would be fine too.
- somytsu 5y agoYes, I also think that. From this site [0]: "Virtually every business relies on third parties to process personal data. Whether it’s an email client, a cloud storage service, or website analytics software, you must have a data processing agreement with each of these services to achieve GDPR compliance." [0]: https://gdpr.eu/what-is-data-processing-agreement/ https://gdpr.eu/what-is-data-processing-agreement/
- rndgermandude 5y agoThere are some important points to mention: * the court explicitly stated that this case was about transferring personal data (the IP) without prior consent. If the user had consented, there would have been no case. * the court explicitly criticized using google, because google a) is known to collect user information and b) google is a US company and the European courts have found the US is lacking in privacy laws. So my reading is that the judgement would not apply if you transferred such data in certain circumstances, e.g. if you transferred such data to provide "essential services" and you have contracts with the data processor about how they can use and store the data that are in accordance with German privacy laws. * the court further stated that it sees no reason to transfer such personal data, as the website could have easily provided the fonts itself. This seems to be a crucial part of the courts reasoning, as it is a ruling on the plaintiff's claim that this use of google was exempt because it was "necessary" to provide the service.
- nightgarden 5y agoSo, soon on top of all the cookie notices that are already there, we are also going to have to consent initially before anything loads to downloading the javascript from 3rd party to manage all the consents? Lol.... Just what the internet needs...
- elygre 5y agoThere is also the option of not messing around with personal data. It would get rid of all the cookie notices that are there, as well as not adding new ones.
- nightgarden 5y agoThe point is that if you go by the logic of this court decision, you need a consent also for js libraries, images, etc. and their primary purpose isn't to gather data. So, to get rid of all notices, you would have to host absolutely everything yourself.