1. Showed you posts
2. Used what posts you liked to show you more posts you'd like
3. Also used that data to show you ads you're more likely to click on
4. Didn't give you a free choice on whether they did (3)
Would still be illegal under the GDPR.
You usually see the distinction between "functional" and "advertising" cookies in those annoying banners, where you of course can't disable the former as that data is core to the functionality of the website. And guess what, if you don't do any shady stuff with user data you don't even need to display any banner (the banner is for getting explicit permission from the user to potentially do shady stuff).
I’ve heard many “of course X or Y” pertaining to GDPR that turned out wrong. Because it’s a law interpreted by twenty-seven separate DPAs.
GDPR’s aims are good. But there is legitimate criticism in its design.
I don't blame Americans or others for not knowing this, but the amount of bad takes about the GDPR by Silicon Valley people in particular is so ridiculous. Every single comment section about a GDPR topic on HN has a bunch of Americans talking about how Europe is some backwards, regulatory hellhole, always talking from a position of total ignorance.
Again, I hear this sort of thing all the time. Then you ask lawyers and lobbyists and get a host of opinions, many of which stick depending on which DPA one approaches or complains to. As a competitive stick, it’s dangerously dynamic.
As is keeping an eye on competitors, particularly lightly-capitalised ones, and noting when they stray into grey areas. Bonus points if you can get multiple DPAs to issue simultaneous requests in obscure languages.
If someone asks us to delete under GDPR, we have to delete these as well.
Being roughly familiar with GDPR, I would be reasonably certain that you could keep a like as long as the identity it's attached to is deleted. Much in the same way as you may see reddit posts that just show a [deleted] user.