Hacker News new | past | comments | ask | show | jobs | submit login

> For your specific question, a website loading an external font resource would likely fall under legitimate interest since the font is necessary for the website to function.

Google Fonts was ruled to be non-compliant: https://www.theregister.com/2022/01/31/website_fine_google_f...

You can work around this by just uploading the font to your own website.




Specifically, a website operator using Google Fonts was ruled to be non-compliant, for not disclosing that they were doing so, and refusing to honour their preference of the user.

I think a pure-play hosting service is probably fine for hosting fonts and relying on legitimate interest, but that's not Google, who is not being paid directly for hosting the fonts, and who actively wants to use the users' information for marketing purposes that the user clearly does not want.


So using jQuery from a CDN would also cause a fine?


I'm no lawyer, but I think that will depend on a number of factors. One important distinction is whether the CDN is based in Europe (or a country that has received an adequacy decision) or not. The details of your data processing agreement with the CDN will also matter, I assume.

In practice, I doubt someone will go through the legal trouble for something like jQuery. If you want to be sure, self-host your resources; it's not like using CDNs will give you any speed advantage anymore with modern browsers isolating websites.


Depends on the CDN.

If you pay the CDN, and they're not using your customers' data to make money, then probably not.

If you don't, or they do, then it's a violation of EU law if you do not allow (at least) EU users to easily control the use of that CDN. If you are making money, and you try telling the regulator that for your business, that you need (legitimate interest) to have jQuery hosted by a CDN that is using EU personal data illegally, then you might get a fine if they are reachable by the EU, because very few judges are going to believe that bullshit.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: