Sad to hear, but most of the the stuff that gets said about GDPR online is BS.
(I have a law background)
actually you also don‘t always need a cookie banner (not mandated by GDPR) and being compliant is not as difficult as many consultants (who want to make money) say it is.
Still even though the idea of GDPR was great, but they didn‘t think about good and easy implementation. Which sucks and I understand the frustration.
The mere existence of regulation is part of the problem. Without precise understanding of the law, you don't know if your use cases are fine/excempted. The safe default assumption is that your site is not compliant with regulations until you can prove otherwise, involving a lawyer.
I have a law background, put am in the startup scene since 7 years as a founder.
Yes it is unnecessarily complex, but as I said: there is so much BS floating around. In reality if you have goodwill and yes invest a little time it is not that hard to be compliant and in praxis if you are not: usually there is the concept of warning before fining, so you do get a second chance.
actually you also don‘t always need a cookie banner (not mandated by GDPR) and being compliant is not as difficult as many consultants (who want to make money) say it is.
Still even though the idea of GDPR was great, but they didn‘t think about good and easy implementation. Which sucks and I understand the frustration.