Okay so it's been five days since GDPR actually kicked in and I think I am more tired from email than I have been from anything tech-related in years. Not exaggerating. My personal inbox, the one I've had since like 2004, got something like ninety "we've updated our privacy policy" emails between the 24th and now. Ninety. I did not count exactly because counting them felt like it would take longer than reading them, and reading them was already not happening.
Some of these came from companies I genuinely don't remember signing up for. A parking app in Manchester. A newsletter about ceramics I apparently subscribed to in 2015 and never once opened. A UK-based fantasy football thing that I think I used for a single season back when I still had time for fantasy football. Every one of them wanted me to know they Care About My Privacy, in bold, usually with a big friendly illustration of a padlock or a shield, like the graphic alone was going to reassure me.
The thing nobody warned me about is how many US sites just gave up entirely instead of complying. I tried to read something on the LA Times site Monday night and got a blank page telling me the content isn't available in my region "as we continue to make improvements." Same with the Chicago Tribune, same with a couple of smaller regional papers whose names I'm blanking on right now. That's such a strange outcome for a regulation aimed at protecting people, the actual result, for a chunk of the internet, is those people just get nothing. I don't think that's what anyone in Brussels was going for, but here we are.
And can we talk about cookie banners for a second. I know this is a small complaint in the scheme of things but I've clicked "accept all" so many times this week on autopilot that I genuinely have no idea what I've agreed to anymore, which feels like it defeats the entire point of asking. A couple of sites did the thing where "reject" is a tiny gray link buried under a big blue "accept" button, which, come on. If your consent flow is designed to make declining annoying, that's not really consent, that's just friction with extra steps. I'm not a lawyer and I'm sure someone will email me about this (please don't, my inbox has had enough this week) but it seems like a pretty obvious loophole that's going to get closed eventually.
On the flip side, I will say a few of the emails were actually useful. One old cloud storage service I'd forgotten I still had an account with sent theirs, I logged in out of curiosity, found about four gigs of old photos from a trip in 2013, and deleted the account entirely because I didn't need two backups of two backups. So credit where it's due, the forced reckoning did get me to do a little digital cleanup I'd been putting off for years. Silver lining, I guess, even if it wasn't the intended one.
I also want to note, mostly for my own amusement later, that there were complaints filed the very first day against some of the biggest players over how they're handling consent for things like ad targeting, the kind of complaints that take years to resolve and will probably still be crawling through some regulatory process long after I've forgotten I wrote this post. That's the part that's going to be genuinely interesting to watch. Not this week's email flood, which is just noise, but whether any of this actually changes what happens to your data once you click through the banner. My money's on "very slowly, and not before a lot of lawyers get paid."
Anyway. If your inbox looks like mine right now, you're not alone, and no, you don't have to read all of them. I promise the ceramics newsletter people are not going to sue you for marking their compliance email as spam.
In smaller, non-GDPR news, I finally caved and set up a Falcon 9 Block 5 folder in my bookmarks because I want to actually track the reuse numbers properly this time instead of half-remembering them. More on that another day, once there's more than one launch to compare against.