Is Google Fonts GDPR-Compliant?

Every visitor whose browser fetches a font from Google's servers has sent Google their IP address. A Munich court decided that needs consent. Self-hosting makes the question go away.

Is Google Fonts GDPR-Compliant? — Troiana insight cover

In short

Loading fonts from fonts.googleapis.com transmits each visitor's IP address to Google without consent, which a Munich regional court ruled in January 2022 to be a GDPR violation, awarding damages. The safe and simple answer is to self-host the font files on your own domain, which involves no third-party transfer, needs no consent, and typically loads faster. Google Fonts remains free to download and licence; only the hosted delivery is the problem.

What happens when a page uses Google Fonts the usual way

The common embed puts a <link> tag in the page pointing at fonts.googleapis.com, which returns a stylesheet pointing at font files on fonts.gstatic.com. The visitor's browser fetches both from Google's servers. Any request to a server carries the requester's IP address; that is how the internet works. So every visitor's IP address, a piece of personal data under GDPR, reaches Google, along with the referring page and the browser's user agent, before the visitor has agreed to anything.

Google states that it does not use the Fonts API to track or profile users and that requests are not tied to Google accounts. The court's view was that this does not matter: the transfer of personal data to a third party in the United States happened without a legal basis, and the visitor had no way to prevent it.

The ruling

In January 2022 the Regional Court of Munich ruled, in a case brought by an individual visitor, that a website's dynamic embedding of Google Fonts violated the visitor's right to informational self-determination under GDPR, because the IP transfer to Google occurred without consent and was not necessary for the site to function, since the fonts could have been self-hosted. It awarded €100 in damages and ordered the site to stop.

The ruling is from a regional court, not the Court of Justice of the EU, and it is not binding across the Union. But it was followed by a wave of demand letters to German site owners, and data protection authorities in several countries have since indicated the same reasoning applies to any third-party resource loaded without consent. The conservative reading is that the practice is a GDPR risk anywhere the regulation applies, which is any site with visitors in the EU or UK regardless of where the site is based.

What the actual risk is

For most sites, small and avoidable. Enforcement has mostly taken the form of individual complaints and letters rather than regulator fines, and the damages involved are modest. But the exposure is real, it compounds with every other unconsented third-party request on the page, and it is a signal in any privacy audit that the site has not been looked at carefully. The cost of removing it is close to zero, which makes carrying it hard to justify.

The same logic applies to fonts from Adobe, icons from a CDN, scripts from third-party servers, embedded maps and videos, and analytics. Google Fonts is simply the most common and the one with a court case attached.

The fix: self-host

Google Fonts are open-source and free to download; the licence permits self-hosting. Moving them to your own server removes the third-party request entirely, so there is no transfer, no consent question, and nothing to disclose.

  1. Download the font files from Google Fonts or generate a subset with a tool such as google-webfonts-helper, in WOFF2 format, for only the weights and styles the site uses.
  2. Put them on your own domain, typically in a fonts folder.
  3. Write the @font-face rules in your stylesheet, pointing at the local files, with font-display: swap.
  4. Remove the <link> to fonts.googleapis.com and any preconnect hints to Google's font domains.
  5. Check the network panel: no request to a Google domain should remain when the page loads.

This takes about ten minutes for a site with one or two families. If the site uses a CMS or theme that injects Google Fonts automatically, most have a setting or a small plugin to disable it and load local copies instead.

The performance bonus

Self-hosting is usually faster. The browser no longer opens a connection to a second and third domain before it can render text, cached fonts are no longer shared across sites in modern browsers anyway, and you control caching headers and preloading. Our notes on web font performance cover subsetting and preloading, both of which are only possible when the files are yours. The privacy fix and the speed fix are the same change.

A site could instead load Google Fonts only after the visitor consents through a cookie banner, with a fallback font for those who decline. This is legally defensible and technically fiddly, and it means some visitors see a different typeface. Self-hosting avoids the question entirely and is the recommendation in nearly every case.

What to check across the site

While fixing fonts, list every request the page makes to a domain you do not control. Each is a transfer of the visitor's IP address, and each needs either a legal basis, consent, or removal. A site with only first-party requests has a much simpler privacy policy and no cookie banner to justify. If you would like a pass over a site's third-party requests, book a call; it is usually an hour to list them and an afternoon to fix them.

Common questions

Is it illegal to use Google Fonts?

Using the fonts is not; they are free and openly licensed. Loading them from Google's servers on a page visited by EU or UK residents is what a Munich court ruled violates GDPR, because the visitor's IP address is sent to Google without consent. Self-hosting the same fonts on your own domain is fully compliant.

What data does Google Fonts collect?

When a browser fetches fonts from Google's servers it necessarily sends the visitor's IP address, plus the referring page and user-agent string. Google says it does not use this to track or profile people. The court's concern was the unconsented transfer itself, not what Google does with it.

How do I self-host Google Fonts?

Download the WOFF2 files for the weights you use, place them on your own domain, add @font-face rules pointing at them with font-display: swap, remove the link to fonts.googleapis.com and any preconnect to Google's font domains, and confirm in the browser's network panel that no request to Google remains. Most CMS themes have a setting or plugin to do this.

Does self-hosting fonts slow down my site?

Usually the opposite. Self-hosted fonts avoid connections to two extra domains, can be subset to only the characters you need, and can be preloaded and cached on your own terms. Modern browsers no longer share cached Google Fonts across sites, so the old caching argument for Google's CDN no longer applies.

Does this apply to websites outside the EU?

GDPR applies to processing the data of people in the EU, and the UK has equivalent rules, so a site anywhere with European visitors is within scope. Enforcement risk for a non-EU site is lower, but the fix costs nothing and removes the question, along with a privacy-policy disclosure.

Have something worth building right?