Global Consensus on these laws or a scanner app letting the startup owner know what you have unwillingly violated is highly wanted.
Global Consensus on these laws or a scanner app letting the startup owner know what you have unwillingly violated is highly wanted.
It only gets very complicated when you start forwarding that data to 3rd parties, intensively tracking + storing user behaviour and engineering patterns aimed at deceiving how you use the data.
If you're that worried about keeping up to date on these types of rules, you can subscribe to the EU data protection newsletter, which will be a fairly decent overview on what's going on: https://edps.europa.eu/press-publications/publications/newsl...
You don't have to worry about data laws unless you're trying to walk that line - and you should not. If you act reasonably and don't even attempt to track people unless they explicitly ask you to (which is what opt-in informed consent means) then you don't need to bother with the nuances. Megacorps are hiring privacy lawyers primarily because they want the lawyers to answer "what can we add/change to somehow keep doing this prohibited thing" instead of just stopping it.
When I hear from "unwillingly violated", most of the time it somehow comes from an organization blatantly and willingly violating the principles; indiscriminately harvesting data and basing their business model on that. Even for a startup, getting a quick 30 minute consultation on data privacy isn't a big deal, and compliance is trivial if you're willing to abandon prohibited ideas - GDPR compliance is primarily tricky for those who want to see what is the maximum amount of evil that is still legally permitted.