Skip to main content
G
Performance Monitoring Medium complexity

Google Fonts

por Google

Define cookies
Não
Envia PII
Não
Rastreamento entre sites
Não
Consentimento necessário
Functional
Mecanismo de transferência
EU-US Data Privacy Framework

Visão Geral

Google Fonts is a web font service that loads font files from Google's CDN (fonts.googleapis.com and fonts.gstatic.com). On each page load, the visitor's IP address and browser information is transmitted to Google's servers. While Google states it does not use this data for tracking, the IP transmission constitutes personal data processing under GDPR.

Capacidades de Detecção

Signature count
2
Detection methods
network

Impacto no Desempenho

Impacto no Desempenho

Requisições por página
3

Erros Comuns

  • 1 Loading Google Fonts from CDN when self-hosting is trivial - download the font files and serve them from your own domain to eliminate all third-party data transmission
  • 2 Assuming Google Fonts is strictly necessary because it is a functional resource, ignoring that self-hosting achieves identical functionality without data transmission
  • 3 Not including Google Fonts in the privacy policy because it is not perceived as a tracking service
  • 4 Using Google Fonts CDN for performance benefits without recognising that modern browser cache partitioning means CDN fonts are re-downloaded per site anyway, eliminating the caching advantage
  • 5 Loading multiple font families from Google when only one or two weights are actually used, increasing unnecessary requests to Google

Considerações de Conformidade

The LG München I ruling (January 2022, Az. 3 O 17493/20) is the landmark case for Google Fonts. The court ruled that loading fonts from Google's servers without consent violates GDPR because the visitor's IP address is transmitted to Google in the US without necessity - the fonts can be self-hosted.

Self-hosting: The definitive remediation. Download font files from fonts.google.com and serve them from your own infrastructure. This eliminates all third-party data transmission while maintaining identical visual appearance. Tools like google-webfonts-helper automate this process.

Cache partitioning: Modern browsers (Chrome 86+, Firefox 85+, Safari) partition the HTTP cache per top-level site. This means Google Fonts loaded on site A are re-downloaded on site B, eliminating the historical CDN caching advantage. Self-hosting has no performance penalty.

Mass claims: Following the München ruling, mass automated claims for EUR 100 per Google Fonts violation became common in Germany and Austria. Some courts have since pushed back on abusive mass claims, but the underlying ruling stands.

International transfers: Google is certified under the EU-US Data Privacy Framework, which may change the legal analysis. However, the simplicity of self-hosting means there is no justification for the third-party data transmission regardless of transfer mechanism.

Serviços Relacionados

Precisa de ajuda para governar Google Fonts?

Nosso diagnóstico de governança identifica lacunas de conformidade em todo o seu conjunto de tags.

Inicie seu Diagnóstico de Governança

Todos os nomes de produtos, logotipos e marcas comerciais são propriedade de seus respectivos titulares. A sua inclusão aqui é apenas para fins de identificação e não implica endosso pela Obscurity Ltd.