This isn't a case where there is non-GDPR functionality that can be severed and provided in the absence of GDPR consent.
This isn't a case where there is non-GDPR functionality that can be severed and provided in the absence of GDPR consent.
This kind of thing is exactly what I have been saying would happen with GDPR. Large companies will say “take all of it or leave it” - and for the most part they’ll get away with it. They have the power to do this, and very little will change for them. The difference is that they are now able to run without fear of startup competitors ever closing in on them, because no startup can get away with this same thing.
The natural effect of GDPR will be to consolidate power and data in the hands of the few companies that can both afford to comply and wield enough power in users’ lives to strong-arm them into giving consent to anything the company wants to do.
High illegal immigration from Mexico is, given geography and existing population demographics, a natural effect of the US’s per-country caps on family-based immigration categories.
From what I understand GDPR it allows data processing if this is needed to do the business, as it is in case of Facebook, so if someone refuses to agree for that, such person cannot use FB.
For example your gym might have video surveillance, which is fine, but it has to have a sign and they can't use the footage for anything else than for security reasons without asking you first and they have to delete it after a certain amount of time. They don't have to video tape you and then sell the footage to the health store next door in order to advertise to you in order to let you use the gym.
The normal operation of Facebook processes a lot of your information between login attempts, and not in direct response to yoour action; if they haven't gotten consent that satisfies the GDPR for that before May 25, they need to stop processing your information, which means they need to essentially completely disable and isolate your account, not just from you logging in, but from all visibility and interaction initiated by other parties.
While, in the abstract, a service they processes your information only in direct and immediate response to your UI interactions could adopt a granular permission model and seek consent for just what was necessary to handle each control interaction when you interacted with the relevant control (crappy UX, but it's possible), that's not the way Facebook works, nor is it something it seems Facebook could, with reasonable effort, be reengineered into. I'm not even sure pausing aall processing of your data until consent is received without deleting your account is something Facebook could reasonably be reengineered to do.
“Consent or delete your account” doesn't seem all that far from the choices Facebook practically has under the GDPR.