Earlier quoted context omitted.
Have you read it? It's not that bad, unless you're thinking like an adtech programmer trying to find the exact edge case for the maximal amount of tracking you're allowed to do, because such a bright line does not exist and that fact infuriates adtech professionals. It is vague because reality is vague and complex; each specific case of alleged violation has to be interpreted by multiple humans; there is no algorithm…
It is regulation that imagines companies are a government bureaucracy. I have read GDPR and don't work in adtech. It is vague and it is pretty easy to find pathological scenarios that don't make much sense or impose an unusually high burden for no benefit. Every European law firm seems to agree with this assessment despite what proponents assert. Consequently, it forces a lot of expensive defensive activity in practi…
As laws go, it's crystal clear
> is pretty easy to find pathological scenarios
Laws in general don't try to tell you how to implement every single facet of every single human endeavor. Otherwise no laws would be written, and those that would get written would be incomprehensible monstrosities.
To not repeat myself, I have more here: https://news.ycombinator.com/item?id=47811648
For 99.999% of businesses GDPR is trivial. For 99.999% of the remaining businesses it's either covered by other laws (banking) or is only difficult to implement because they were ised to collecting user data en masse (any social netowrk or streaming service).
There are very, very, very few instances were GDPR cannot be applied using basic common sense.