> Do you actually work for a small to medium-sized EU business?
I did. And I do.
> Because I do and the amount of money we need to throw at compliance, both in direct costs and dev hours, is immense.
It's not immense, with emphasis. It's just the cost of doing business.
If you run into having to do compliance or certification, it means that you're doing something that requires you to be, you know, compliant.
For example, financial institutions have to be compliant. And we, as society, really-really want them to be compliant and responsible for what they are doing. Not like Equifax in the US.
> And we're not doing ads, user targeting, or any other such "nasty" industry practices.
It doesn't matter, if you do it or not. The "immense" cost of compliance is just your business deciding to cut corners and then realising that no, you shouldn't cut corners, and then scrambling to fix that when you were most likely caught red-handed.
I worked at a company which was a bit lax with its practices, and then had a run-in with an unexpected audit. Omg, you wouldn't believe, but the cost of compliance with laws was immense as we rushed to meet al requirements before the deadline imposed on us. Had we not been lax, this wouldn't even be a problem.
> I used to be think GDPR was a good thrust for user privacy but years later what I see is an adorned web already suffering under the weight of its own crap super-adorned with these cookie banners that impact my actual, day to day life of the net.
Ah yes. Another person who complains about compliance, and then immediately pretends that the state of the web is the result of a law.
No, the web is the way it is now precisely because these companies flaunt and break the law. All those cookie banner with dark patterns? They are illegal. The only real downside of GDPR is that it's not enforced as rigidly as required, and nowhere on the required scale.
As for compliance with GPDR, it's essentially zero added cost for small companies with greenfield projects. For small-to-medium companies the cost of GDPR compliance is the function of data practices. If it's "immense" for you, this only means that you were already siphoning user data you didn't need and did nothing to protect it. I can't feel sorry for you.
> Our German clients have screamed and hollered (thanks, Schrems II!) to bifurcate our clouds so that one side is AWS and the other is a German cloud that moves with the glacial pace
Once again, you blame your own technical decisions on the law. Of course German customers would want their data in Europe. Why wouldn't they? Data on American servers is basically forfeit, and can be examined, analysed, and seized by the US at any moment. Wow, I can only imagine why German customers would not want that. Whatever might be the case, hm?
> German cloud: let's make setting up
Once again: it was your decision. AWS (and GCP, and Azure) literally provides a service to European customers where they keep data in Europe only, and that is more than enough for most any compliance (I know banks in Europe who use AWS and/or GCP). [1]
So, your poor technical decisions have lead you to suffer increased costs, and you blame that on laws. Keep it up, it's a good way to stay in business.
[1] AWS: https://aws.amazon.com/compliance/eu-data-protection/, Azure: https://blogs.microsoft.com/eupolicy/2021/05/06/eu-data-boun..., GCP https://support.google.com/cloud/answer/6329727?hl=en