Tech has already and will continue to interact with laws/lawyers. At some point open source libraries will appear to streamline compliance. For now it sucks but ya gotta muddle through or call it a day.
Tech has already and will continue to interact with laws/lawyers. At some point open source libraries will appear to streamline compliance. For now it sucks but ya gotta muddle through or call it a day.
GDPR requires restructuring of applications to keep data on a temporary basis with the consent of the users, to remove data after the fact, to selectively restore, and to allow users access to their own data. These are proactive steps required, and while applications written in the next six months will be built with those requirements in mind, it's still a fairly large burden for business-as-usual applications.
I don't want to trivialize compliance. Even ostensibly simple requirements are never quite that, and every second spent on them is time not spent on your product.
The GDPR requires mostly that you document what data is stored and how, and that you have a legitimate reason for doing it this way. Consent is not necessarily required.
> to selectively restore, and to allow users access to their own data.
So, you get a takedown/access notice, and then you take down/show that data. Compliance solved.