I think there might be some pretty draconian side effects to properly implementing GDPR, but I'd like to hear from someone who knows to what extent these things might be true:<p>* The legal tracked information includes IP addresses, which means all logs must be able to selectively expunge IP address info.<p>* You can no longer have soft-deletes as a safety mechanism to maintain referential integrity if your data is (as is common) related to a user/account as you are responsible for being able to expunge that data.<p>* There are no exemptions for first time visitors, which means you can't just put up a no-EU unwelcome mat and serve up any third party tracking.<p>* The penalties are pretty draconian for a small business.<p>* It looks like retargeting businesses might be in trouble? Maybe?