What it is
Loading a font from a third-party domain means the visitor’s browser makes a request to that domain and necessarily discloses its IP address; request headers can also include browser and referring-page information depending on browser policy and configuration. The request may occur without a cookie, which is why the scanner reports known font hosts as functional observations rather than declaring them advertising trackers.
It still became a live issue in Europe. On 20 January 2022 the Regional Court of Munich awarded a claimant €100 in damages over a website that embedded Google Fonts remotely, holding that transmitting their IP address to Google without consent infringed their rights, and rejecting the argument that loading the fonts remotely was a legitimate interest, since the operator could have self-hosted them. A wave of opportunistic warning letters followed.
What a scan matches
A verification scan drives a real browser and records the outbound requests observed during its configured journeys, so Google Fonts and web fonts is identified by request hosts and paths rather than by source-code claims. Requests on unvisited paths, after unperformed interactions or solely on the server remain outside that observation.
- fonts.googleapis.com and fonts.gstatic.com
- typekit.net and use.typekit.com: Adobe Fonts
- fontawesome.com: icon fonts
Controlling it with consent
Self-hosting removes the live request to the remote font provider and is usually the simplest privacy design. It also makes you responsible for font licensing, updates, subsetting, caching and performance, so verify those operational details rather than describing the choice as cost-free.
If you must load remotely, omit the stylesheet link from initial markup and insert it only after the relevant condition. That is technically possible but can cause visible font changes and is not automatic in the current script registry, which is a strong practical argument for self-hosting.
No named adapter: choose the appropriate control
The product ships named adapters for Google Tag Manager, Google Analytics, the Meta and TikTok pixels, and Klaviyo. Choose the control route that fits this technology: a custom HTTPS script declaration for a browser loader, an individual consent condition inside a tag manager, a platform or app setting, or a click-to-load placeholder for a frame. Server-side integrations need their own enforcement because a browser runtime cannot stop them.
What breaks if it is refused: No live dependency on the remote host if the font is correctly self-hosted. Blocking a remote font without a local fallback can change typography and layout.
Verifying it
A scan will show requests to fonts.gstatic.com if you are loading remotely. There is no cookie to look for: the request itself is the finding.
- Before a choice: optional tracking endpoints and optional identifiers are absent; any intentionally loaded necessary or functional surface matches the control model described above
- After rejecting optional categories: optional activity remains absent and the refusal persists across a reload
- After granting the relevant category: the expected loader or embed appears and the feature behaves normally
- After withdrawing: new optional activity stops; where the vendor supports a consent signal, verify that the signal is sent as well as checking network behavior
Common questions
Do Google Fonts require consent?
A simple remote font request may involve no cookie, so cookie storage is not the only issue; personal-data disclosure and lawful basis can still matter. A Munich Regional Court held against one remote Google Fonts implementation in 2022. That judgment is fact- and jurisdiction-specific. Self-hosting removes that particular live disclosure to the font host.
Can a consent banner block a remote font?
Yes, if the page omits the remote stylesheet initially and inserts it only after the relevant choice. A runtime cannot undo a request from a link already present in the parsed markup. Self-hosting is usually simpler and avoids a late font swap.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- Google Fonts: technical considerations
Vendor documentation
Checked
- Regional Court of Munich: Google Fonts judgment of 20 January 2022
Official documentation
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.