GDPR is about legality and covers the LinkedIn case you mention.
GDPR is about legality and covers the LinkedIn case you mention.
Do you see how GDPR doesn't apply, then? ...you're contradicting yourself.
I'd still question the legality of the data collection by altering the offered service without properly informing the affected users. Whether GDPR applies doesn't matter, and whether it's a free tier service doesn't matter either. You're a consumer of Cloudflare, so any consumer rights apply.
As a website owner, you are responsible towards your users for data collection (your architectural choices, your responsibility). This was my concern on GDPR.
Sibling comment says data collection is disabled in EU.
> Cloudflare needs the data. [...] If someone is mad, maybe they should pay or use a different architecture.
To "they would violate GDPR".
Are you ok with that behavior then? And are you basing your ethical decision solely on the current legislation?
When selecting free tier of such commercial MITM, opt-in RUM data collection is really far from the top ethical concern. I'm not saying it's a good thing and I'm not deploying their solutions to my websites.