Websites · 5 min read

Are Google Fonts GDPR-compliant?

The Munich Regional Court has ruled: embedding Google Fonts does not comply with the GDPR. What that means and how to deal with it, explained simply.

EElena Kroll · 05.09.2022
Are Google Fonts GDPR-compliant?

Google Fonts is a collection of more than 1400 typefaces made available by Google. They carry a free software licence, which means they are available to users free of charge. No licence fees are charged.

That makes them a great addition to any font library, one that agencies and freelancers as well as private individuals are happy to use. By now almost every website uses Google Fonts.

For that reason, the Landgericht München (Munich Regional Court) has caused a stir and attracted criticism. Since January 2022 Google Fonts have no longer been a grey area with regard to the GDPR (General Data Protection Regulation, in German Datenschutz-Grundverordnung).

Since the recent ruling by the Munich Regional Court of 20 January 2022 (case number 3 0 17493/20) it is official that calling up Google Fonts from a Google server breaches the GDPR.

Why Google Fonts are not GDPR-compliant

Website operators can decide whether or not they want to upload Google Fonts to their own server. If they do not, the fonts are loaded from a Google server when the website is opened. Since Google is an external service provider, data is transmitted from the user to Google.

What is passed on here specifically is the IP address. With this information, website operators could, working together with the authorities, trace the user. It makes no difference whether the operator makes use of that possibility or not.

Article 4 of the GDPR (cf. Art. 4 No. 1 GDPR) protects internet users against the transmission of personal data, including a dynamic IP address.

Google Fonts and the wave of warning letters

Of course it was foreseeable that there would be a wave of Abmahnungen (formal warning letters).

Private individuals are in theory entitled to compensation if their data is passed on to third parties without their consent.

There are, however, exceptions to this rule. One of them is where the website operator has the user's consent. It is important to note that such consent is not always sufficient. It must be specific and informed.

The amount of compensation depends on the quantity and type of data that was passed on. In the ruling mentioned above, the injured party was awarded a sum of 100 euros for non-material damage of an emotional and psychological nature. The loss of control and the discomfort were so great that they justified a claim for damages.

In the event of a repeated breach, an administrative fine (Ordnungsgeld) of up to 250,000 euros was threatened. The injured party had been able to prove that their IP address had been passed on to Google without their consent.

Our agency has observed a dramatic increase in warning letters over the past few months. Users contact website operators by email and demand various amounts in compensation, mostly in the three-figure range.

In doing so they refer to the ruling of the Munich Regional Court and justify their claim with the emotional impairment they have suffered.

Should these warning letters be taken seriously, or can they be ignored?

Illustration on cookies and the GDPR

How to deal with warning letters and claims for injunctive relief

In principle, private individuals are entitled to send warning letters. However, only data protection supervisory authorities and consumer associations may legally issue a warning letter that skims off profits.

A right to information under Article 15 (cf. Art. 15 No. 1, 2 GDPR) is, however, provided for. It gives the data subject the right to obtain information about whether their data is being processed and, if so, which data. It is advisable to consult a lawyer in order to check whether the warning letters are justified and how best to deal with them.

Finally, some operators decide simply to ignore the emails. It has to be borne in mind, however, that loading content from third parties is not legal and can have consequences. As in the case of the Munich ruling, a private individual decided to take the matter to court and was successful.

That can happen again; every warning letter you receive is a potential lawsuit. Recent experience has shown that in most cases the courts have found in favour of the private individual.

The solution to Google Fonts and the GDPR

Of course it is easiest if the website complies with the GDPR in every respect. We are aware that this is a challenge that takes a great deal of time. Time to research and to understand what breaches the GDPR and how to solve it technically.

At the same time it still has to be guaranteed that the site works flawlessly, looks appealing and collects data on user behaviour where possible. The situation is also constantly changing, which can make it difficult to stay up to date.

That is why we at ELECOS offer to check your website free of charge and to identify problematic or unlawful integrations.

We check not only Google Fonts, but everything that is loaded by the site before the user has given their consent via the cookie consent banner. We also explain the grey areas and support you in reaching a decision.

We then adapt the integrations and the cookie consent so that the site becomes GDPR-compliant. Exactly what we do is always discussed with the operator.

Together we find the best possible solution for reconciling the needs of the company with the requirements of the GDPR.

E

Elena Kroll

Writes at ELECOS about websites, data protection and productive working.