I've not met 1 company who met all aspects of this law.
I'd guess this also means that any asset in a 3rd party CDN would be non compliant with gdpr
I've not met 1 company who met all aspects of this law.
I'd guess this also means that any asset in a 3rd party CDN would be non compliant with gdpr
The GDPR is Working as Intended.
Ironically the foreign big ones have enough resources to comply to the law, small local ones don't and will die/never be created in the first place.
> the regulating authorities can pick whoever they want to prosecute
It doesn't really work that way, at least not in germany, anyone can just sue (or threaten to sue) their competition over this (they already started) there is no such thing as this mythical benevolent authority who could stop this wanton destruction you are talking about.
This is wrong. Competitors (and only competitors) can send a cease-and-desist letter based on competition law, because ignoring GDPR gives an unfair advantage - even that only in Germany because the tool used here ("Abmahnungen") are a unique german thing.
They are also a common thing between companies that don't "like" each other and if you send one you can expect to get one back. Receiving one costs ~1000 € (goes to the opposing lawyer) so they don't hurt much and the only one profiting is the lawyer.
> the only one profiting is the lawyer
how would I not profit from my competition having to pay money, I don't care if I get the money.
Yep, that's what I've been saying all along, but people don't seem to understand.
The real cost of regulation isn't the cost of non-compliance and the punitive measures that follow. It is the cost of compliance, reporting, addressing an endless stream of complaints and requests for information.
Large companies have the resources to handle that, small ones don't.
This is the world we live in. When the market fails to protect users, eventually there might actually be consequences.
So constructively, how do we solve this CDN problem while causing the least harm to both businesses and users? Perhaps identify assets by cryptographic signature rather than URL?
What about all the networks between you and Amazon?