… I mean, WTF. Mozilla, you had one job …

  • PII is being processed, even if it’s not being sold to advertisers. The underlying protocol works based on some session identifiers that uniquely identify a device to the aggregators. I don’t think that’s GDPR proof per se.

    I don’t think any DPA will have a problem with this system assuming they implement their side of the system correctly, but I wouldn’t be too sure about Mozilla following the GDPR. They’ve defaulted to a lot of data collection without explicit consent over the years.