[1] unless the data is needed for the website to work
[1] unless the data is needed for the website to work
Others give you the choice between targeted advertising and paying for non-targeted advertising, or three choices (free with targeted ads, paid with non-targeted ads, paid a lot with no ads).
Note how the Google and Instagram consent dialogs changed in the past year or so. I'm sure that wasn't voluntary...
This is currently being contested by NOYB.
It think it's a gray area right now though.
What the hell are you talking about? You can keep providing ads. If it's a paid service, you can keep providing a paid service. No one is asking you to do stuff for free.
They can show ads on the service. They can even ask people to opt in to targeted advertising.
What they can't do is harvest people's personal data to monetize the service.
In other words: You can give away potatoes for free. You can sell potatoes for money. You can sell potatoes for onions. You can, in many countries, even sell potatoes for sexual favors, although there will be some rules to protect against exploitation. What you cannot do, in most countries, is sell potatoes for kidneys, and you most definitely can't sell potatoes while surreptitiously removing customer's kidneys and hoping they don't notice or care enough because they have two and you're only taking one.
The most profound mistake is their lack of proper risk assessment, as well as proof and transparent documentation of real actual significant harm done to users, to warrant such discriminating privacy laws. In the process they are hurting everyone, including small personal blogs, news media sites, and large social media sites.
The data, if hacked, or spied on by employees, is still a privacy risk regardless if its used for targeting ads or not. The data still sits on the servers, because the applications depend on it to function properly. The number of ecommerce websites alone that do not properly handle personal data is scary; basically anyone with database access can also access all the personal data on customers. If a given CMS has a known exploit, then the data is in great risk of being leaked and abused. E.g. Never host a site on Wordpress without proper security in place.
Nevertheless. We should always maintain that the user is ultimately responsible. If they do not like Facebook, they just ought NOT to create a Facebook account. Dislike being watched when walking around in physical shops? Stay away from them. However, the actual risk to the individual user, from ads, is so miniscule that we practically have no substantive examples of harm done. The worst shit is falsehoods promoted via ads, but that is purely an policy/moderation problem. Fake pages and accounts are a much bigger problem than falsehoods promoted via ads.
Having a paid subscription model would be a valid opt-out of advertising (ads are often dishonest, so I would like to see that). The problem is, the data still sits on servers, and if leaked, this will, unlike targeted ads, pose an actual real risk of harm.
I am not against the GDPR or the EU, but it has been profoundly flawed from the beginning, costing website owners a lot of time and money trying to comply. I absolutely hate consent platforms, because they are just another third party dependency IMO...