- accept all - necessary only - reject all
So many websites outside the EU have a mass of dark patterns for which I increasingly reject all or leave the website.
GDPR is really simple.
Only store data that you really need to service the customer’s needs, always permit the customer to correct incorrect data and allow them to delete it unless you have a legal reason to keep it. Report GDPR failures within 72 hours where customer data has been compromised and treat PII carefully.
In the US - fuck the customer.
I know which I prefer.