Earlier quoted context omitted.
It's not that it's annoying, it's that I literally cannot answer "are we GDPR compliant?". If you search for GDPR IP address, you get a ton of different opinions. Do I need to sanitize logs? How does that fit in with the requirements for security compliance we are also subject to? At the end of the day, I am the one person who has to answer that question/is responsible for being GDPR compliant. I've spent hours doing…
So everything should be written out explicitly, because you'd rather complete a checkbox-ticking exercise rather than thinking about it and do the correct, ethical thing in good faith? Sounds like a win for the GDPR to me, we know rigid checkbox-ticking is ineffective. Apart from that, NIST 800-53/800-171 are catalogs of "security controls and associated assessment procedures" for "Federal Information Systems and Org…
What if my opinion of what is ethical differs from what regulators decide? Opinions are notoriously inconsistent, subject to bias, and easily used to discriminate.