Excellent point, by the way. Under GDPR, embedding something like a Google font is only legal after user consent, simply because they can see your IP address when you connect.
This was confirmed again on Monday by a German court [1] (German link) for the case where they loaded something from Akamai on a university library website. This was specifically deemed problematic since the implicit connection was into the US.
Basically, this means if you operate in Europe you can’t use US cloud providers at all before user consent.
This was confirmed again on Monday by a German court [1] (German link) for the case where they loaded something from Akamai on a university library website. This was specifically deemed problematic since the implicit connection was into the US.
Basically, this means if you operate in Europe you can’t use US cloud providers at all before user consent.
[1] https://verwaltungsgerichtsbarkeit.hessen.de/pressemitteilun...