Earlier quoted context omitted.
> Anomyous telemetry is not PII. That depends. First, no data collection is "anonymous" when it is transmitted. Any anonymity must come later, and then is only possible if the company aggregates the data with other users and deletes the original data that was collected. PII/Personal Data are squishy terms. In the US, anyway, the legal definitions of what counts as "PII" leaves out an awful lot of actual PII -- so any…
> First, no data collection is "anonymous" Because no network connection is anonymous but as long as you aren't handling PII, GDPR has nothing to say about it. I could sell an app in the EU that just pinged my server once a day. As long as I wasn't keeping a record of who pinged what when, there is no PII. Otherwise everything is PII and you would need consent before every TCP handshake.
Data processing is not just about 'keeping a record'. Processing even for a millisecond is also processing.
> Otherwise everything is PII and you would need consent before every TCP handshake.
Consent is not the only ground for data processing. Normally, it would just be performance of a contract, as the user wants something from you.