A company doing business with other companies might find themselves in a position where they can comply perfectly. Not every company needs to collect PII, though these days every company likes to pretend they do.
A company doing business with other companies might find themselves in a position where they can comply perfectly. Not every company needs to collect PII, though these days every company likes to pretend they do.
This seems to ban third-party analytics by any US company. The cynic in me feels this is a little convenient in how it advantages EU organizations over foreign ones...
“The Italian SA reiterated that an IP address is a personal data”
[1] https://ec.europa.eu/info/law/law-topic/data-protection/refo...
Collecting most if not all analytics is forbidden, for sure, but analytics and metrics aren't inherently required for businesses.
And as a European, I'm very glad that's the case. I know, we're still not close to compliance with GDPR, but it has changed the privacy discussion more than any other part.
How is that something that is essential to providing a service?
I suppose that it's somehow "commercially advantageous", but there are many other commercially advantageous techniques that are simply illegal - such as taking a customer's money, but supplying zero in exchange.
A company's profit needs are not an end-run around consumer protection laws (which is what GDPR amounts to).
Personal data, not PII. The GDPR does not care about PII (except to the extent that the set of things that are PII is a subset of things that are personal data).