The assumption you're making here is that GDPR is one and done. In all likelihood, most major jurisdictions are going to introduce privacy laws at some point. If you don't build your international service to allow for different rules in different jurisdictions you're going to have to follow the strictest of those laws. Heck, I'd put money on some countries forcing some web services to record some data for law enforcement purposes and other countries barring facebook from recording the same data for privacy reasons.
So really, you have to build this system in a way that can be tailored to each market you operate in.
This is so sad.
The form usually proceeds by stating a view. You think attribution is more important than the propagation (or content) of the view, and that is fine. For me, the content and propagation usually rank higher.
In the case of FB, I think we all had enough proof that the quest for money is above everything. According to the latest leaks about their execs, even above human lives.
So, at this point, I find any attempt to defend them, even hypothetical, sad.
GDPR doesn't penalize or prevent innovation. It just forces it out into the open.
This is a nice summary.
Good!
This is like saying that prescription-drug regulations are limiting speed/freedom. When those things are dangerous to the user, they should be limited!
And I still don't agree that it slows anyone down. Want to launch a new feature quickly? No problem, go ahead and launch it. All you have to do is add an opt-in dialog at the beginning.
As far as freedom goes, we've seen the abuses of that freedom and it's time to limit it.
Compared to the freedoms of millions and billions of uses my 'developer freedom' is pretty far down the list of things that matter. As developers we are servicing people, they are not our lab rats.
If you don't want facebook to track you don't make an account on their website and don't click any of the stupid buttons on their website.
They still build a shadow profile of you from mentions and photos that friends upload.
It also tracks us through its widgets on other sites.
It requires a lot of effort to fully opt out.
Being open and honest with people really doesn't slow down development all that much.
[0] https://aws.amazon.com/compliance/gdpr-center/
[1] https://www.microsoft.com/en-us/TrustCenter/Privacy/gdpr/def...
So far, I don't think any cloud providers show you ads based on your usage, but it's only a matter of time :) / :(
In the case of Facebook, it makes sense that they wouldn't want to offer privacy protection to their livestock.
1. The administrative/maintenance cost of complying: this is sunk if you have European users at all.
2. The cost of the measures to your business model, if personal user data is a central part of your business model.
3. The adminstrative cost of maintaining radically different user data management systems for EU -vs- non-EU users.
Doing number 3 is only worthwhile if it's a lower cost than number 2. I would guess 3 would be higher than 2 for most companies. Clearly, 2 is extremely high for Facebook.
So no, I don't think that response is universal.