Earlier quoted context omitted.
Hi! Please also look into the collector.githubapp.com analytics endpoint, the request does not seem to be compatible with GDPR in its current form. Either unique IDs tied to the user will have to be removed, or express consent will have to be requested. https://news.ycombinator.com/item?id=25461825
This is just not true. See my comment elsewhere in this thread: Why is it not GDPR compliant. You do not need consent under the GDPR. You need a (documented) "lawful basis for processing" personal information. Consent is just one of several lawful bases and honestly it's the most useless one, if you need consent your business model is screwed. It's perfectly possible for GitHub to process personal information without…
Sure, you can argue that, but it has no merit.
The only reason that you can write that sentence with a straight face is due to the current affairs of the web. You know the thing that GDPR tries to rectify.
And analytics do not need personally identifiable information.
Try the three-part test suggested here: https://ico.org.uk/for-organisations/guide-to-data-protectio...
Purpose test: You can argue it has legitimate interest. And with a big enough loop-hole it might even pass despite it having no merit.
Necessity test: Absolutely not.
Balancing test: No chance.