I wonder if these kinds of discussions can be easier to have if concerns and critiques brought up were framed, from the start with an understanding that the cost to achieve and maintain compliance with the standard is a cost that gets paid either in money or work-hours (like for example SOC2 or PCI), that it can very tangibly halt non-compliance workloads and rollouts; instead of starting from a footing of assuming complaints are the cloaked dressing for being against user privacy.
Understanding full well each standard solves different problems, for some of us in tech achieving compliance is a non-trivial amount of critical work and maintaining it similarly isn’t always something you easily drop everything and make happen in a day or two.
I think that’s 100% relevant and shouldn’t be immediately responded to as others have by assuming the relevance comes from a position of opposing the regulation or standing against user privacy
> instead of starting from a footing of assuming complaints are the cloaked dressing for being against user privacy.
The problem with this is twofold:
a: 'Most' (by loudness or other perception) of the complaints are known to be bad faith because they're coming from malicious actors like Facebook or Google which we know are against user privacy (since that's their business model).
b: You have to go out of your way to build a site that interferes with actual user privacy, for example by actively adding Google Analytics scripts or faux-CAPTCHAs, or actively demanding a real name and actively doing something about it if the user lies to you. (Technically you get IP addresses by default, but much like mailing addresses, obscuring these pretty much has to be the user's responsibility, since how else would you respond to them.)
So if you want a assumption of good faith, you need to be clear that you're complaining about the bureaucratic compliance overhead (eg having a particular data processing officer or whatever GDPR calls it), rather than about having to change your object-level service to eliminate spyware that you went out of your way to incorporate in the first place.
Understanding full well each standard solves different problems, for some of us in tech achieving compliance is a non-trivial amount of critical work and maintaining it similarly isn’t always something you easily drop everything and make happen in a day or two.
I think that’s 100% relevant and shouldn’t be immediately responded to as others have by assuming the relevance comes from a position of opposing the regulation or standing against user privacy