The EU regulators have been remarkably consistent in their rulings. The GDPR is quite clear that tracking for advertising purposes requires explicit consent and an opt-out. Meta's case has always been relying on a very generous interpretation of the 'contractual necessity' clause of article 6.
The only source of unpredictability is the apparent collaboration between the Irish regulator and Meta - this is the 4th time in a row they've been overruled. Much like our overruled tax arrangements we're apparently bending over backwards to keep tech multinationals happy for as long as possible.
It isn't Europe's fault that the tech industry's only business model for the past decade has been about misusing personal data in ways people didn't expect or consent to (otherwise GDPR would not be a problem again since people will willingly opt-in).
Besides, the EU isn’t like, banning clothing imports, which have all sorts of EU illegal stuff in their supply chains, because those are EU businesses.
Obviously people agree in principle that there are socially bad business models. I don’t think child labor and ad tracking are remotely comparable. Where do you draw the line? The honest answer is, whatever you get stylized-outraged about, because you have limited intellectual bandwidth and your job isn’t to figure shit out like this.
1. Showed you posts
2. Used what posts you liked to show you more posts you'd like
3. Also used that data to show you ads you're more likely to click on
4. Didn't give you a free choice on whether they did (3)
Would still be illegal under the GDPR.
You usually see the distinction between "functional" and "advertising" cookies in those annoying banners, where you of course can't disable the former as that data is core to the functionality of the website. And guess what, if you don't do any shady stuff with user data you don't even need to display any banner (the banner is for getting explicit permission from the user to potentially do shady stuff).
I’ve heard many “of course X or Y” pertaining to GDPR that turned out wrong. Because it’s a law interpreted by twenty-seven separate DPAs.
GDPR’s aims are good. But there is legitimate criticism in its design.
I don't blame Americans or others for not knowing this, but the amount of bad takes about the GDPR by Silicon Valley people in particular is so ridiculous. Every single comment section about a GDPR topic on HN has a bunch of Americans talking about how Europe is some backwards, regulatory hellhole, always talking from a position of total ignorance.
Again, I hear this sort of thing all the time. Then you ask lawyers and lobbyists and get a host of opinions, many of which stick depending on which DPA one approaches or complains to. As a competitive stick, it’s dangerously dynamic.
As is keeping an eye on competitors, particularly lightly-capitalised ones, and noting when they stray into grey areas. Bonus points if you can get multiple DPAs to issue simultaneous requests in obscure languages.
If someone asks us to delete under GDPR, we have to delete these as well.
Being roughly familiar with GDPR, I would be reasonably certain that you could keep a like as long as the identity it's attached to is deleted. Much in the same way as you may see reddit posts that just show a [deleted] user.