If the GDPR is in fact to be interpreted in this literal way, and assuming Google Analytics doesn't take any measures to become compliant, we will need to replace Google Analytics on our platform with a self-hosted, open source analytics tool like for example Motomo.
If this includes other tools like Google Tag Manager, those tools will need to be replaced as well.
Should we assume that Google is on top of this and will "publish a fix" in order to become compliant? It's not a small actor so it surprises me that we have so little official guidance and/or assurance that they are on top of this. Are they paralyzed?
What should we do here? What are you going to do?
Worst case for us, I guess, is to go back to 90's style web programming where everything is self hosted, which is fine I guess, but quite far from how the world commonly works right now.
I don't even want to think about the fact that GDPR might even ban the usage of Azure and other cloud vendors, because of the simple fact that the CPs (and any hosting company) will definitely get the IP address of a web visitor regardless.
Powerful as though they may be, I don't know if Google is powerful enough to fix the US laws. I think the problem here is that if US laws do not guarantee privacy protections for people abroad, then it doesn't matter what a US company does. They can't publish a fix.
The only surefire fix may very well be to stop using services run by companies in a hostile regime.
Yes, it's quite the shock. I'm not going to do anything because everything I run is already fully hosted in Europe by European companies.
Azure's primary business isn't to collect data about users, Google's is.
Hosting providers and CDNs are legally very different from third-parties that you insert into a website.
Having all resources under the same domain is a great boost to performance. Self-hosting fonts can speed up website loading anywhere from 250ms to 1s.
Not sure how big your company is, but if you don't serve millions of users monthly, you could check out the self-hosted analytics platform I'm building: https://www.uxwizz.com/