← All guides

External fonts and CDNs: avoid unnecessary third-party connections

Without a tracking code, a website can still contact third parties every time a page is viewed - for example for web fonts, JavaScript libraries, icons or style sheets.

Why local files are easier

For an external resource, the visitor's browser establishes its own connection to the resource provider. Self-hosted files, on the other hand, are delivered via the website you are already visiting.

Typical candidates

Control Google Fonts, public JavaScript CDNs, external icon fonts, CSS framework CDNs and images loaded from third-party servers in the network panel. Host locally where possible and update regularly.

CSP as additional control

A restrictive content security policy can block unexpected external sources. It does not replace inventory, but it does help to make new unintended dependencies visible.

Requirements

Access to templates, style sheets or asset configuration and a list of the currently externally loaded resources.

Dismantling

If local provision is not technically possible, specifically integrate the external resource again and document the origin, purpose and resulting third-party requests.

Related guides

Sources and verification

This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.

Important: IP processing is not IP storage

An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.

↑