> Can any site just 'do an end run around' the law by requiring their users to agree to allow them to collect whatever data they collect now or that they've already collected? If so, that seems like it'd be likely as helpful as current terms of service.
Under the GDPR you're not allowed to store personal data.
However, if you have purpose, and need data to fulfil that purpose, you can.
You can also ask for data, in clear terms, and if an informed user, freely choose to share, you might store that.
So, you sell shoes and magazines online. You need an address to ship both. You need a shoe size to ship the right shoes. You can demand to know the shoe size before you ship shoes - but not before you ship a magazine.
You can store order information (indeed have to, due to financial regulation). So you have a record of shipped shoe size and customer data.
You may not, without consent, store a permanent profile with shoe size and magazine preference. But it's OK to let users opt in to a profile.
> Another item mentioned is "Where possible, pseudonymize personal data.". What's a practical example of that?
Good question. Off the top of my head I can't think of useful pseudonymyzation related to the GDPR.
Perhaps things like hashing IP addresses for traffic stats, or using opaque identifiers for storing session interactions rather than linking directly to IP or real names. Useful pseudonymyzation is hard.