Why can't I load some 3rd party tools?
What author is claiming, essentially, that in a mere 2 month from now, you can sue almost any European publisher for data privacy breach. Outrageous claim require outrageous proof.
You can, you just need assurance that they're also GDPR compliant if you want to be GDPR compliant.
If the third-party violates GDPR, but requires your website to run on (e.g. third-party JS, other types of beacons), I think judges are going to have a dim view on that, and so you can't simply claim that it's them, not you. (There may be mitigations, e.g. if you have a contract with them that spells out GDPR compliance, but then they break that - but how many people have contracts for the JS they embed?)
Edit: One way this argument could be laid out is that by including such third-parties in your website, you're instructing the browser to load them, and therefore effectively forwarding GDPR-related data to them. Technically, this isn't really too different from a REST API call you'd perform on the server, or an AJAX call (although the server call doesn't necessarily forward e.g. the IP).
So if your interpretation is correct, and GDPR affects even completely anonymous users, I'll be seeing and clicking "consent box" each time I go read a newspaper or just do general browsing. Like the "we use cookies" stuff, but on steroids.
EDIT: but still, I find this hard to believe, tbh. It means no ads served to anonymous users, and this has consequences I can't even imagine.
Well, it's 2018, and most publishers rely on some 3rd party ad-tech to serve the ads. They don't have direct contracts with advertisers, and definitely has no tech in house. If 3rd party calls are prohibited, their ad revenue disappears overnight.
Will be interesting to see how it develops.
As for consent, you have to be able to refuse. A consent box popping up each time would be the dumbest way to do this, but not that different than those full-screen email/newsletter begging boxes we have now.
If we agreed that even incognito browsing contains the traces of PII, publisher has to get my consent, explicitly, that's the whole point of GDPR. I see no other option than to do popup window for each new visitor (where new == has no associated cookie). What are other options?
How will this work with Google Analytics and things like that? Will random e-shop be required to notify Google to stop using/delete PI for random persons upon request?
Seems like it's machine-identifying information. You can't tie it to a real-world name and email (which the top voted comment claims is the essence of GDPR).
They acquired your name, birthdate, address, etc. And they didn't aquire it through your website.
Calling IP address or screen size "person" identifying information seems a stretch to me.
It realy is very much like environmental regulation. Before things like the EPA etc. came to be, it was a toxic 'everything goes' type of environment. Transition to a regime where businesses are held to data responsibility might be painful at first, but ultimately hugely beneficial to all.
The same goes for ad networks. YOU are responsible for making sure the ad network is compliant. If you include a non-GDPR complaint ad network script on your site and somebody complaints, then you are in for it because you were ultimately responsible for that network being able to track the user on YOUR webpage.
If Facebook is GDPR compliant and has consent from the user then you are in the clear. If Facebook is not GDPR compliant and tracking people who aren't users then a EU or local court will set up a campfire under their asses (German courts already have).
IP addresses are definitely personal data (PII and Personal Data are different, the GDPR defines and cares only about the later, PII is mostly an US term used interchangeably with PD on the internet) German and EU courts have ruled that since an IP can be traced back to a person, it's personal data. Unless you have a good reason to log it (hint: firewall and webserver logs) then you need consent for it.
The GDPR definition of personal data is VERY broad, and it explicitly includes things like:
* name, email, date of birth, etc (probably no surprise here)
* any user behaviour (what you look at, what you click on)
* uploaded content (what you write, your uploaded avatar etc)
* ip addresses, device ids
* beliefs, ethnicity, sexuality, health data (additional restrictions apply here)
* biometric data, genetic data (additional restrictions apply here)