Legal & Compliance

Third-Party Fonts, Embeds, and Website Privacy

Web pages routinely pull resources from domains the visitor did not choose: font CDNs, video players, maps, chat tools, social widgets, analytics, and advertising scripts. The initial HTTP request itself can disclose an IP address and browser metadata, so “no cookies” does not automatically mean “no personal-data transfer.”

What AllyProof checks

Before consent interaction, the browser records font requests and requests associated with common embed providers. The result identifies the destination and resource type. It does not infer the provider's full contractual role or declare that every cross-domain request is unlawful.

For Germany, AllyProof distinguishes remote fonts because the Munich Regional Court's 2022 Google Fonts decision found an unjustified disclosure of a visitor's IP address where the font could have been hosted locally. That decision is relevant evidence, not a rule that every font or every CDN use fails automatically.

Questions for human review

For each observed provider, establish:

  • what data leaves the visitor's browser;
  • the purpose and legal basis;
  • whether the request is strictly necessary before a choice;
  • whether a local or two-click alternative exists;
  • the provider's role and contractual safeguards; and
  • whether the privacy notice accurately names the processing.

Common technical remediations include self-hosting fonts, using privacy-enhanced embed modes, replacing an immediate embed with a consent-gated placeholder, and delaying optional tags until the relevant category is accepted.

Official sources

An observed request is evidence to investigate. Its legal outcome depends on facts that a browser scan cannot see, including purpose, agreements, necessity, and transfer safeguards.

Common questions

Are Google Fonts always unlawful in Germany?
No. The commonly cited Munich decision concerned remote loading that disclosed an IP address without consent where local hosting was available. Self-hosting fonts avoids that particular third-party request.
Can an embed transmit data without cookies?
Yes. Loading a resource from another server normally exposes connection metadata such as the IP address and user agent, even if no cookie is stored.

Want to review these signals on your own website?

Run a free compliance check