There’s no part of the GDPR that requires the current mess or where the current mess should help anyone, that is if I’m not
totally wrong.
In fact it is so far from the letter and spirit of the law that I find it odd that any company with a significant internet presence, that should have access to competent lawyers can misinterpret it so badly.
Then again, European companies burn themselves in USA all the time on basic stuff too; a UX designer I worked with described how they lost a lawsuit against a bloke after he had broken into a site, opened the machine, jammed something into the door sensor and started operating the machine, all while being influenced by drugs. The first part of the story ended when he got his hand jammed in some kind of shredder unit.
The second part of that story ends when their American legal team finds out there is no sticker that tells people not to put their hand into the machine and tells them they’ll likely lose in court and convinces them to settle.
After that nobody forgot about the stickers.
But to most Europeans I think it sounds outrageously stupid that you can break into a site, operate a machine after deliberately jamming the safety mechanism and still get a settlement because there was no sticker to tell him not to put his hand in the shredder.
So, for Americans, here is how I understand the GDPR law:
Except in special circumstances (criminal justice etc) you are not allowed to store customer data except as needed to run the actual service for your customers (and that doesn’t include monetizing by ads or spyware).
You can ask a customer for permission to store data, but the default is no, and - AFAIK - you are not allowed to penalize someone for not accepting.
The only grey area I see is where you default to not storing info and inform the customer that they can opt in to more personalized and possibly more meaningful ads.
See? Nothing there about popups. They should default to off, so meaningless in the first place, something no one seems to get. Or they get it but are deliberately doing it anyway, pretending not to get it like last time.
If someone else has a better understanding of GDPR, feel free to roast my understanding, - or add details to it. [I know there is a lot more.)
Also, FWIW, here is what I think is a good example of data collection done correctly under GDPR, the customer has a clear choice, the benefits are obviously linked to the data collected and the default is no: https://erik.itland.no/observation-gdpr-and-privacy-done-rig...