Earlier quoted context omitted.
Bad law for the reasons above. Ie, onerous toward regular businesses Ie, used to greatly expand bureaucracy and overhead Ie, used by unelected bureaucrats to wage battles of personal vendetta against specific companies instead of doing what laws do, which is set unambiguous standards for all
GDPR compliance is actually trivial to implement if you manage your users’ data in ways that wouldn’t surprise them negatively. There's not much more. > unelected bureaucrats Does the American elect the IRS or the FTC bureaucrat?
I have officials in the EU on the record that IP addresses are deemed personal information and if your business uses AWS and unintentionally passed IP addresses over to any resource in the US, you are technically in violation.
Will you be hanged for this today? Probably not. But all it takes is one negative press cycle for the idiots there to interpret and enforce this as they have shown the willingness to do in the past.
The point about unelected bureaucrats isn’t the unelected part. It’s the lack of oversight or consequence or clear demarcation of legislative power from the executive.
The bureaucrats have taken it upon themselves to issue multiple specific rules that go over and beyond the text of any law. See the case of the CNIL in France. They had a court ruling around their rules for cookies on Google go against them and they continued to insist that they would enforce said law. They issued an “FAQ” on their website that indicated threatening language against businesses that flouted their previous comments that were now deemed incorrect by a court of law and had the audacity to press on.
Like I said, the EU is an abusive monarchy