Google Fonts and GDPR fines: what really happens in Spain (and the fear they sell you)

Short answer: in our review of October 8, 2026, no public sanction by Spain's data protection authority (the AEPD) for using Google Fonts is on record, so the fear of a fine is very inflated. That does not make it harmless: loading fonts from Google is a connection between your visitor and Google, and it hands over their IP address, and that part is real. What the AEPD does fine is badly set up cookies: the amounts we have been able to check run from €1,600 to €5,000 per infringement, and they are specific cases, not a price list. The fonts are worth fixing, and it is not a big job: on Thursday, August 13, between 18:37 and 18:42, we left five websites without remote fonts.
This is what really happened, what does cost money and what we did in our own house, with date and time.
| What is said | What the record shows |
|---|---|
| "The AEPD fines for Google Fonts" | No sanction is on record. The headlines you will see are about a 10 million euro fine on Google, from 2022, for something else |
| "You are going to get sued" | In Germany there was a wave of letters in 2022. The courts found it abusive and the Berlin prosecutor's office investigated the lawyer |
| "Using Google Fonts is illegal" | A German ruling from 2022 awarded 100 euros to a visitor. The Court of Justice of the EU (CJEU) has not yet ruled on the issue |
| "Fixing it is a big job" | We left five websites fixed between 18:37 and 18:42 on an August Thursday |
Where does the fear of a Google Fonts fine come from?
It comes from a real ruling, from a letter industry that was built on top of it, and from how it all ended. It is worth having the whole story, because the half that gets told on LinkedIn is only the beginning.
On January 20, 2022, the Munich I Regional Court (3 O 17493/20) ordered a website owner to pay 100 euros in compensation to a visitor. The site loaded its fonts from Google's servers, which makes each visitor's browser hand its IP address over to Google without anyone asking the visitor's permission. An IP address can be personal data.
What came next is what the people who sell fear leave out:
- Germany. A lawyer sent thousands of letters to websites found with automated crawlers, asking for about 170 euros from each. Around 2,000 people paid. In December 2022 the Berlin prosecutor's office searched his law firm and investigated at least 2,418 cases for fraud and extortion.
- Austria. Another claimant sent letters demanding 190 euros in 2022 to about 32,000 recipients. When the case went to court in 2023, she could not prove that the visitor's IP address had reached the United States: the court dismissed the claim, found it abusive and ordered her to pay the costs.
- The German courts. On March 30, 2023, the same Munich court (4 O 13063/22) declared those mass claims abusive.
Since 2023 the mass wave has not come back. The underlying question, however, is still open: on August 28, 2025 the German Federal Court of Justice (BGH) stayed a Google Fonts case (VI ZR 258/24) and asked the Court of Justice of the EU, among other questions, whether a dynamic IP address is personal data and whether an infringement provoked on a mass scale gives a right to compensation. As of October 8, 2026 we have not found a European answer. When it arrives, it will set the standard for the whole EU.
So why do we fix it anyway?
Because the technical basis is true even if the fear is exaggerated, and because fixing it has three payoffs and none of them is "avoiding a lawsuit":
- Your website gets faster. For years now, browsers have kept their cache separate for each site. Loading fonts from Google no longer saves any download: every new visitor downloads them anyway, with the toll of two extra connections. Serving them from your own domain removes that toll.
- That connection goes away, whatever the CJEU decides. With the fonts on your own server, your visitor no longer hands their IP over to Google through them. That does not by itself settle the rest of your data protection obligations.
- You stop depending on a third party for something as basic as your website looking right.
Every resource your website loads from someone else's domain (a font, an embedded video, a map, a library from a CDN) makes the visitor's browser connect to that third party and hand over the visitor's IP, without consent and without it appearing in your privacy policy. Fonts are the famous leak. They are not the only one.
How to self-host Google Fonts: we did it ourselves in August, with timestamps
Before telling you theory, here is what we did with the websites we look after, ours and our clients'. With times, because they come from each site's change history and not from memory.
Thursday, August 13. At 18:37 four fixes go out almost at once: the booking agenda, the forms, the diplomas and the business card stop asking Google for their fonts and serve them from their own domain. At 18:42 the fifth goes out, the one for a website we built for a client. All five, already checked in production.
Saturday, August 15, a public holiday:
- 14:50: we put in writing the method to detect these leaks on any website.
- 15:17: we set a one-year cache on the fonts of the five websites, so they load as fast as when Google served them.
- 15:41: second version of the method, after an investigation in which our system tries to knock down every fact with several AI agents. Three facts we took for granted did not survive the review.
- 15:42: we add the real AEPD sanctions.
- 18:42: we fix two more websites, a client's forms website and one of ours. They loaded programming libraries from third-party servers, and that also hands over the visitor's IP.
- 18:50: the scanner we built for this is saved.
Yes, it was August. Yes, it was a public holiday. And then they say nobody works in August.
What taught us the most was what had slipped past us. On Thursday we had left the fonts of our forms website clean. But fonts are only one of the ways of handing over a visitor's IP, and that same website also loaded libraries from outside servers. We did not spot it by hand: the scanner did on Saturday, running it in one minute across the websites we look after, ours and our clients'. Two had that problem and we fixed them that same afternoon.
While preparing this article we ran the scanner again on seven of our websites: on none of them does it find fonts or libraries loaded from third-party servers anymore.
The practical lesson: do not trust that you have fixed it, look again. One minute was enough for the scanner to find what we had missed by hand.
If you want to do it on your own website, what changes is where it is done. This is what each platform documents, with the panel route as it appears in its official help.
On WordPress:
| Platform | What happens by default | What you can do, and where | Official source |
|---|---|---|---|
| Elementor | If you pick Google Fonts and do not turn on the local setting, it loads them from Google's CDN. Available since 3.27 as an experimental feature; since 3.32.1 it is optional and off by default, so you have to turn it on | Elementor > Editor > Settings > Performance > Load Google Fonts Locally > Enable > Save Changes | Elementor help |
| Astra | It has a setting to download Google Fonts to your server. Its documentation does not say whether it comes turned on: check it | Astra > Settings > Performance > Load Google Fonts Locally. Available since 3.6.0 | Astra documentation |
| Kadence | It has a setting to host them locally, even in the free theme. Its documentation does not say whether it comes turned on: check it | Appearance > Customize > General > Performance > Load Google Fonts Locally. Available since 0.9.3 | Kadence help |
| GeneratePress | With the Default System Stack no font is downloaded. If you add a Google Font, it loads remotely unless you set it up locally | You need GP Premium (paid), 2.5.0 or later: Appearance > GeneratePress > Font Library to download them and Appearance > Customize > Typography to apply them | GeneratePress typography · GP Premium 2.5.0 |
| WordPress Font Library (6.5 or later) | Fonts you install from it are served from your own server. It does not change remote fonts loaded by a theme, a plugin or custom code | With a block theme: Appearance > Editor > Styles > Typography > Manage fonts. According to the current help, since 7.0 also at Appearance > Fonts (Install Fonts for Google ones, Upload for your own) | WordPress help |
| OMGF plugin | What gets requested from Google depends on your theme and plugins. OMGF finds compatible Google Fonts and replaces them with local copies; some detection needs the Pro version | Settings > Optimize Google Fonts | OMGF plugin page |
On other platforms:
| Platform | What happens by default | What you can do, and where | Official source |
|---|---|---|---|
| Wix | According to Wix, its Google Fonts are hosted on Wix. Custom elements, embedded code and iframes can load external fonts | To upload your own font: in the Editor, select the text > Edit Text > Fonts dropdown > Upload Fonts > Done, and pick it under My Fonts | Wix: Google and GDPR · Wix: upload your own fonts |
| Squarespace | It uses Google Fonts and Adobe Fonts, and according to its privacy text those providers can receive the visitor's IP when serving the fonts. Its built-in font packs use Google Fonts | You can upload your own fonts and apply them to your styles. In 7.1: Site styles > Fonts > text style > font dropdown > upload icon. In 7.0: Design > Site Styles > typography setting > font dropdown > upload icon. To avoid Adobe, use a built-in pack and do not pick Additional Fonts: that does not avoid Google | Squarespace: choose fonts · Squarespace: upload your own fonts · Squarespace: privacy text |
| Shopify | The fonts in its library are served from Shopify's CDN, normally under /cdn/fonts/ on your store's domain. A theme can add external fonts (usually in theme.liquid): do not assume they go through Shopify's CDN | Online Store > Themes > Edit theme > Theme settings > Typography > Headings or Body > Change > pick the font > Select > Save. For your own fonts: Content > Files, plus CSS or Liquid code | Shopify: theme settings · Shopify: fonts on the CDN · Shopify: your own fonts |
Checked against the official documentation on October 8, 2026. None of these settings guarantees on its own that no other connection to third parties is left on your website (a map, a video, a script): look at the Network tab again afterwards.
What does the AEPD really fine?
The AEPD fines cookies that are installed before the user decides, cookies that cannot be withdrawn once accepted, and reject buttons that reject nothing. Its cookie guide says so in writing (May 2024 edition): rejecting has to be on the same layer and at the same level as accepting. If you already use a cookie plugin (Cookiebot, CookieYes, Complianz, Borlabs), giving both buttons the same weight is usually a setting in the plugin itself. These are the cases we have been able to check with the resolution in front of us:
| What was happening on the website | Who | Amount | Case |
|---|---|---|---|
| Non-technical cookies before consent and a reject option that did not work | An individual with a film website | €1,600 (€2,000 reduced for early payment) | PS/00079/2023 |
| Non-technical cookies before any interaction and an inoperative "reject all" | Wallapop | €3,000 (€5,000 reduced for acknowledging the infringement and paying) | PS/00160/2025 |
| Impossible to withdraw cookie consent once given | Massimo Dutti | €5,000 (September 2023) | PS/00051/2023 |
| Google Analytics installed without consent | Chatwith.io Worldwide | €5,000 for the cookies (€12,000 in total with other infringements) | PS/00080/2023 |
| Repeat offence on three websites: third-party cookies without consent and no way to reject | Techpump Solutions | €90,000 (€30,000 per website) | PS/00524/2023 |
The honest picture for a small business with a website: the law that regulates cookies in Spain is the LSSI (Spain's e-commerce and information society services law, Article 22.2) and it allows up to 30,000 euros for a minor infringement, which is how the AEPD classified the Massimo Dutti case. In practice, the specific infringements in the table have stayed between 1,600 and 5,000 euros, but they are cases, not a price list. The 90,000 for Techpump is the extreme, for repeating the offence and for three websites.
To gauge where Europe is heading: in September 2025 the French authority (CNIL) fined Shein 150 million euros for placing cookies without consent, and Google 325 million euros for ads placed between Gmail emails and for cookies set when creating an account without valid consent. The European framework is shared, but each country applies it in its own way: for now, the difference is how hard each authority presses.
And the AEPD's 10 million euro fine on Google? It was not about fonts
If you search for "AEPD fine Google Fonts" you will see headlines about a 10 million euro fine on Google. It has nothing to do with typefaces. It is case PS/00140/2020, resolved on February 15, 2022: two fines of 5 million, one for passing data to the Lumen Project without a legal basis and another for obstructing the right to erasure. Mixing the two things up is precisely part of the fear being sold.
Does your agency or provider have the Article 28 processor contract signed?
It is the cheapest question in this article. In October 2022 the AEPD fined a software company for private clinics 60,000 euros for not having signed the processor contract (Article 28 of the GDPR) with its own hosting provider, after a security breach that affected about 135,000 people, health data included (PS/00576/2021).
If your provider acts as a data processor (that is, it handles your customers' or visitors' data on your behalf), there has to be a contract that meets Article 28 of the GDPR: check that it exists and that it covers what that article requires. If they do not know what you are talking about, you already have a data point.
If your appointment form collects health data (a clinic, a dentist, a physio), also ask whoever runs your website where that data is stored and who has access to it.
What other leaks does your website have without you knowing?
From best known to least known:
| Leak | What happens | How to fix it |
|---|---|---|
| Google Fonts, Font Awesome, remote icons | The browser requests the file from a third party and hands over the IP | Serve them from your own domain |
| Embedded YouTube video | It connects to Google when the page loads even if nobody presses play. The privacy-enhanced mode (youtube-nocookie.com) reduces advertising tracking, but its official help does not guarantee that it avoids the connection before play | A thumbnail that only loads the video on click |
| Google Map on the contact page | Same as the video, and we have not found an official mode equivalent to youtube-nocookie.com | Replace it with a link to Google Maps, as Google's help explains, or load it only on click |
| WordPress themes and builders (Elementor, Divi) | They load Google Fonts on their own even if you did not ask for it. The most common blind spot on small business websites | Check it with the browser's Network tab, not with the theme panel |
| Programming libraries from CDNs (unpkg, jsdelivr, cdnjs) | The website works, but every visitor connects to a third party | Host them on your own server |
| Google Tag Manager | A German administrative court (Hannover, March 2025) held that the container itself already requires consent. It is a first-instance ruling and not a general rule for Spain | Set up consent mode (Consent Mode) instead of blocking the whole script, which can break your analytics |
| The cookie banner itself | The tool that helps you comply also loads third-party resources | Audit it like everything else |
| Embedded AI chatbots | A connection on load, where what the visitor types ends up, and a mandatory notice that it is an AI | Review the provider, the contract and the notice |
Does your chatbot have to say it is an AI?
Yes. Since August 2, 2026, Article 50 of the AI Act obliges you to tell people that they are talking to an AI system, unless it is obvious from the context. The notice has to be clear and arrive at the first interaction. The Digital Omnibus, the package that has delayed other parts of the Regulation, has not delayed this obligation. The maximum penalty for breaching it is up to 15 million euros or 3% of worldwide turnover, and for a small business the lower of the two figures applies. It is the newest item on the list: check whether yours has it.
If you are thinking of adding a chatbot to your website or WhatsApp, or reviewing the one you have, our chatbots page explains how the ones we build work. And if what worries you is what your team pastes into ChatGPT by hand, we have a guide to anonymizing data before pasting it.
How to anonymize data before using ChatGPT →
How do I check my website in 10 minutes?
Detecting it is done with Chrome:
- Open your website in Chrome and press F12 (on a Mac, Cmd + Option + I). Go to the Network tab.
- Reload the page and look at the domain column. If you want to go straight to it, type "fonts.g" in the filter.
- Every domain that is not yours is a connection from your visitor to a third party. Write the list down: that one is yours. The domain of your hosting or your CDN (for example, Cloudflare) is a provider of yours, a data processor: it is not a leak if there is a contract and it is declared.
With the list in hand comes the hard part: what is harmless, what has to be replaced and how to replace it in your case. Fixing it may need technical help: the platform table above has the official routes for the most common ones and, for the rest, ask their support or whoever looks after your website. To put it all in order we have prepared a checklist.
Frequently asked questions
Is it illegal to use Google Fonts on my website?
It is a disputed question. A German ruling from 2022 held that loading them from Google's servers, without consent, hands the visitor's IP over to Google, and awarded 100 euros in compensation in that case; the Court of Justice of the EU has not yet set a standard. In Spain no AEPD sanction for it is on record, and serving them from your own domain avoids the question.
Can I be fined in Spain for Google Fonts?
No public AEPD sanction for Google Fonts is on record as of October 2026. The 10 million euro fine on Google from 2022 that shows up in search engines was for the Lumen Project and the right to erasure, not for the fonts.
What is the difference between a fine and compensation?
A fine is imposed by an authority, such as the AEPD in Spain. Compensation is set by a court in favour of the person who claims it: in Munich, in 2022, 100 euros for a visitor to a website. The lawyer's letters in Germany were not fines either: they were demands for money, of about 170 euros per website, which the German courts ended up declaring abusive.
How much does the AEPD fine for the cookies on a website?
In the cases we have been able to check, between 1,600 and 5,000 euros per infringement, and 90,000 in a case of repeat offending on three websites. The LSSI allows up to 30,000 euros for a minor infringement. These are specific cases, not a price list.
How do I know if my website loads Google Fonts from Google?
In Chrome, press F12 and open the Network tab, reload the page and filter by "fonts.g". If fonts.googleapis.com or fonts.gstatic.com appear, your website is requesting them from Google.
How do I serve the fonts from my own server?
You download the font files (woff2 format), upload them to your website and declare them with an @font-face rule. In WordPress there are several routes: Elementor, Astra and Kadence include a setting to load them locally, and there is also the OMGF plugin. In Wix, Squarespace and Shopify it depends on the platform (and, in Shopify, on the theme). The official routes for each are in the platform table in this article. It is worth giving them a long cache so they do not load slower than before.
What happens if I do not have the data processor contract signed?
If your provider acts as a data processor, not having that contract is an infringement of Article 28 of the GDPR. The AEPD fined a software company 60,000 euros for not having it signed with its hosting provider, after a breach that affected about 135,000 people.
Does my AI chatbot have to say it is an AI?
Yes: since August 2, 2026, Article 50 of the AI Act requires a notice, clear and at the first interaction, unless it is obvious from the context.
What to do now
Download the 10-minute checklist. It is free and we do not ask for your email. It is designed so you can see for yourself what your website loads, and so you can send it to whoever looks after your website.
Download the 10-minute checklist (PDF, in Spanish)
Printable version (white background, PDF, in Spanish)
If F12 means nothing to you, go straight to the checklist's questions for whoever looks after your website and send them over.
And if you know someone with a website, send them this article: you save them the next scare email.
Would you rather we look at it together?
Jorge has 20 minutes in his calendar to go through it with you.
Sources and scope of the October 8, 2026 review
This is an indicative review of public resolutions, court rulings and regulations; it does not certify that any website complies.
- Judgment on Google Fonts: Landgericht München I, January 20, 2022, 3 O 17493/20.
- Mass claims declared abusive: Landgericht München I, March 30, 2023, 4 O 13063/22.
- Berlin prosecutor's office investigation (at least 2,418 cases): LTO, December 21, 2022.
- Austria, 2022 and 2023: press release from the lawyer of those affected, OTS, October 9, 2023 and heise.de (Bezirksgericht Favoriten).
- BGH, order of August 28, 2025, VI ZR 258/24: decision hosted at Curia.
- AEPD, cookie guide, May 2024 edition.
- AEPD, resolutions: PS/00051/2023, PS/00079/2023, PS/00080/2023, PS/00160/2025, PS/00524/2023, PS/00576/2021 and PS/00140/2020 (links in the text).
- LSSI, Articles 22.2, 38 and 39.
- CNIL, September 1, 2025: Google and Shein.
- Verwaltungsgericht Hannover, 10 A 5385/22, March 19, 2025 (Google Tag Manager, first instance).
- Regulation (EU) 2024/1689, Articles 50 and 99: consolidated version on EUR-Lex and European Commission FAQ on Article 50.
- Official documentation of the platforms in the table (Elementor, Astra, Kadence, GeneratePress, WordPress, OMGF, Wix, Squarespace and Shopify), of YouTube and of Google Maps: links in the text, checked on October 8, 2026.
Written by
Jorge Marín Pérez · Founder of Soul IA
I help SMEs automate their customer service and processes with AI, from Málaga. What I write here comes from what we build every week for real businesses.
Want to know what you could automate in your business?
Talk to Soul IA