established companies have no issues with fees, or legal requests.
gdpr is to protect the established companies from competition.
it is basically a reverse china ban. because china-style banning of competition is still considered bad in the eu.
1. Adding a dialog as the first step in an onboarding funnel that's already difficult to get users through
2. Handling non-consent. WTF! So if the user doesn't give consent to something that 99% of the population doesn't understand, I'm not allowed to prevent them from using the app. And so my engineering team needs to waste critical hours figuring out things like how to deal with crashes, or maybe how in the fuck we're supposed to fallback to not using services that we're built on (e.g. Firebase)!
3. Dealing with the fallout of #1 in the form of bad reviews that are the kiss of death to startups
This is like a living, breathing example of why GDPR had to be written the way it was, so that arrogant techbros couldn’t rationalize their way around to screwing everyone over for a quick dollar. It’s also a perfect example of why you get zero sympathy. “But maaaa, it’s hurting my funnel!” Good.
If you would have built your whole app on "free" services for which your users pay with their personal information, that would be problematic under GDPR. And rightfully so.
What if I decide that crash reporting is an essential service (it is), and the EU's lawyers decide that it's not? Who is going to pay my legal fees, and potential fine? I should be on the hook because some schmuck uses a service that I provide for free (which essentially means I'm paying for it with my time), and is upset that I may not be handling his data in the way that the EU says I should be? The sane solution would be to allow me to tell this individual that he cannot use the app if he doesn't consent. But here comes the EU telling me that I must allow him to use the app.
No, the EU only stipulates that you are not allowed to sell, leak or otherwise slander personal data from EU residents without their freely given consent, and makes you liable for that.
IANAL, but I think there is no reason to fear too much, though I would stay on the safe side regarding interpretation. And remember that anybody can report you for anything to the authorities, or sue you already; if you are prosecuted you'll have to pay your legal fees and fines whether it's about GDPR or not.
this is likely a big and unnecessary burden to most startups.
i believe in less regulation in general so my opinion could be biased.
While bigger businesses, with very established monetization models that don't comply with GDPR, are now in a pretty unfavorable place and have to scramble looking for alternative monetization models, forcing much bigger changes.
"GDPR, the European Union’s new privacy law, is drawing advertising money toward Google’s online-ad services and away from competitors that are straining to show they’re complying with the sweeping regulation."