EMZETT.
Login

Google Fonts and Data Protection

In short: Anyone who loads fonts directly from Google servers transmits visitors’ IP addresses to Google. This can violate the GDPR.

In more detail: In 2022 the Regional Court of Munich I (case no. 3 O 17493/20) awarded a website visitor 100 euros in damages because a site had embedded Google Fonts dynamically without his consent.

In Depth

What is the problem?

With dynamic embedding the browser requests the font from fonts.googleapis.com. Google thereby receives the IP address. A transfer to the USA needs a legal basis and information.

Solution

  • Embed locally: host the font files yourself. Then there is no connection to Google. In Next.js this works with next/font (download at build time).
  • Or obtain consent (consent).
  • Mention the use in the privacy policy if fonts are loaded by third parties after all.

At Emzett

Fonts are delivered from our own server. There is no connection to Google Fonts. See GDPR, tracking.

See also: GDPR (DSGVO), Personal Data, Tracking, Cookie-Einwilligung (TDDDG)