You can actually opt out of that mechanism: you can use your own, untrusted CA. The point of CT is to improve trust, and I seriously have doubts trusting the 300 independant (?) CAs my browser "trusts" [0].
Sure, having an infinite, append-only log of domain names for which an HTTPS certificate ever was issued sounds like a GDPR issue. But if it also helps catch bad actors before they can even set up their phishing pages, I'm all for it.
Sure, having an infinite, append-only log of domain names for which an HTTPS certificate ever was issued sounds like a GDPR issue. But if it also helps catch bad actors before they can even set up their phishing pages, I'm all for it.
[0] https://hg.mozilla.org/releases/mozilla-beta/raw-file/tip/se...