Earlier quoted context omitted.
And sure, by German law, your data will be deleted after you paid your fine. (Plus some time for processing and record keeping) This doesn’t make this a good analogy though. The GDPR does not prohibit storing private data, it just requires explicit and informed consent. It does not require deletion of data that is required to conduct a transaction, such a receipts, order data or adresses required to fulfil an order.…
The GDPR isn't as good as you think it is. It's going to turn into one of those laws where small software startups / or normal small businesses are just going to be in constant violation, because the amount of resources required to do it properly requires a team of 5 or 10 expensive software engineers. It's going to be a great way to nip small companies in the bud and consolidate this kind of stuff into bigger compan…
> https://www.brentozar.com/archive/2017/12/gdpr-stopped-selli...
I read his post, and wonder if the 'attorneys' he consulted are specialists in EU law, or were his standard ones. There's a lot of FUD around GDPR but the guidance is getting better, and people assume it's being 'policed' when the UK's body (the ICO) is more about guiding into best practices than punishment.
The comments (esp around medical records) suggest ignorance of how it's working.
Source: reading the GDPR and accompanying notes from the ICO; discussions with a large company's GDPR advisor, who was involved in drafting the legislation.
Disclaimer: this is not legal advice, I am not a lawyer, and you are an idiot if you act on anything I say.