Earlier quoted context omitted.
> Scummy companies took the path filled with the darkest of patterns because they want to suck up as much data as they can to sell to 3rd parties. I take exception to that. I have worked for many companies that are not in the least bit "scummy" and have popups. Even our government sites here in Norway have the popups [1]. All this points to is again that the regulation is bad. And again, because of the lack of certif…
I'm not sure what you're looking for, given how the rest of compliance works? What is the compromise? I suspect people would hate it even more if every company needed to go through an official gov GPDR certification. In the US, SOC2, and EU, ISO, are voluntary (not gov), and generally doesn't happen till most companies hit 8 figure revenue (and earlier in enterprise). What I would expect to start happening is, simila…
Regulation that is clear, in the sense that people can know whether they are complying with it or not and know how to become compliant with it. I explained the problems with GDPR at length now, I think it's pretty clear I don't want the problems.
I also want the national agencies to do what their job is — not their job according to me, their job according to the EU, which is defining certification that is acceptable to them. What about my expectations are unclear?
> In the US, SOC2, and EU, ISO, are voluntary
How are these relevant here? How does these being voluntary make GDPR less of a dumpster fire? GDPR is not volutary, in case that was unclear to you at this point.
So okay, other things — not the GDPR — are not dumpster fires, and how GDPR would not be a dumpster fire if it was different. Agreed. I did not say anything about SOC2 and ISO, and I did not say GDPR would not be a dumpster fire if it was different. My concern with GDPR is not it's acronym.
But the EU won't fix it, they never fix anything — they have no incentive to fix it, in fact, Eurocrats are incentivized to not fix it. They just keep smearing more crap on the crap sandwich.