> "what I can’t be sure of is what happens to data that passes through the various apps, WordPress plugins, cookies etc that are part of this blog, but not controlled or run by me."
This is a dumb argument, it's his personal blog, it's controlled by him. That including how much JS and social media trackers to stuff into each page.
With comments, it's easy. Somebody wants you to post the comment, which is why they submitted it. No extra consent needed, although maybe they'll want it deleted in future. Of course, an email address is required to post, but "it will not be published". Why exactly is it required then?
No, that's the point - consent is required for that. And for the consent to be explicit, some are advising it needs to be a Modal blocking dialog that prevents the user from using any other part of the website before dealing with it, and that demonstrates the user did actually scroll through all the privacy terms, not just ignored them and clicked the checkbox.
> This is a dumb argument, it's his personal blog, it's controlled by him. That including how much JS and social media trackers to stuff into each page.
That's fair. I know I've personally been deleting Google Fonts and Adobe Typekit and hosting my own webfonts instead as a result of this. I'm still figuring out how to best replace Google Analytics, and looking to remove any Twitter & YouTube embeds I had in old posts that could possibly track visitors. (I agree that is all a good outcome of GDPR.)
MailChimp recently sent out an email to their customers advising that all their current HTTPS Submit forms are not GDPR compliant. They're rolling out all new submit forms in May that have legalese that must be explicitly agreed to, in addition to the Email field & Submit button. It's a Modal blocking form so the visitor can't possibly do anything else.
Here is an example of their new modal submit form, it's a doozy:
https://kb.mailchimp.com/binaries/content/gallery/mailchimpk...
I don't do any "customized ads" or "direct mail", but apparently that boilerplate of legalese and "we use your email address to send you email, tick here to confirm you want email" is still required. It's a bit like the Cookie notifications all over again.
I realize I haven't directly responded to your blog comment submit button, but I hope this explains the motivation / understanding behind my comments here. I too would have thought an email field & submit form would be a reasonable expectation, but the form designed by MailChimp's lawyers is way more legalese & boilerplate than I ever anticipated would be required by GDPR.
(Honestly, I do also get the comments here about "you're not going to be caught or made an example of so don't worry" too. In practice I will do what I can to be compliant, listen to what my visitors & customers want, and hope for the best.)
If you say, "hey, provide your email, and I'll send you newsletters and you can unsubscribe at any time", and I say "sweet, sign me up", and then you only send me newsletters with no tracking or adtech, that's legitimate interest.
If you use a third party, if they store only the minimum necessary and don't use it for anything else, that'd be fine to. E.g. obviously they need my email address, but only for sending the emails.
And if Mailchip were decent, they'd just send out plain emails. The problem is probably their emails are full of tracking links and other adtech garbage, and who knows who they sell info on to?
Then again, they call themselves a marketing platform, not a newsletter service, or email sender. Kind of obvious.
Also, that's a shitty dialog. Mailchimp's private policy and terms are probably largely void under EU law anyway, just by being almost incomprehensible by the lay person. How am I supposed to give consent freely when it would take days to read? Probably best to avoid Mailchimp. Thanks GDPR!
Edit: ordering
[0] https://ico.org.uk/for-organisations/guide-to-the-general-da...
It seems obvious that comments won't cause an issue but because of the fluffy language of GDPR some interpretations could make simple things like this problematic.
Also, people seem to get hung up on consent. There are several lawful basis for processing data, consent is one of them. It's also the most abused, so it's the most heavily regulated in the GDPR. Ad-tech and the scummy parts on the web rely on "consent" (or lack thereof).
Normal website usage like eCommerce or even posting a comment can use other bases, like most legitimate interests - that's why they call it that.
Right to erasure is also fairly obvious as far as deletions go. Right to restrict processing is a bit trickier. Server location is also much more interesting, due to the infamous and rather shaky Privacy Shield.