The court did not even see this issue, i.e. the distinction between issuing a suggestion or directive vs. actually executing the request directly. The court, in fact, states that the was the website itself that did the sharing. The ruling suffers from unsound reasoning.
It could be, however, that the website owner never brought up these arguments. The court does not have to do its own investigation. This is called the “maxim of disposition” in German law. Whatever both parties agree on what is true has be treated as true by the court.
So if the claim that the website itself issued the request to Google servers was uncontested, then this ruling is sound, based on the claims brought forth by the parties in this particular case.
If you are that caring about your privacy, you absolutely should use a browser that is configured in such a way that it doesn't leak your IP to anyone you didn't consent to.
I'm running systems that I'm modifying to the extent that satisfies me, but that's not the concern here. Right now I'm caring about everyone's default privacy level, not just my own. And in this ideal world, third party sharing is not opt-out.
Yes, definitely. Ad absurdum, browsers could be mandated to have the user opt-in to every single instruction that is executed. It's technically possible, the user has control.
I think it's a slippery slope to imagine/enforce a transfer of agency between the website user and provider, where the latter will try to make the opt-in appear as simple as possible. An ideal opt-in is more than the click of a button, it's an understanding. A button accompanied by a wall of text isn't understanding.
Code in the frontend is absolutely not "asking". I'd bet that most of the users have no idea what's going on in their browsers and devices, and those instruments then, in turn, shouldn't prey on this ignorance. I know that this is not how the world works, but a difference is that we could have control over this one.