Overthinking or not, it seems like you're agreeing with what I was getting at...
The post I responded to, I think, made a very good point about responsibility being on service providers rather than OSS contributors.
However, the wording about "providing the service to the consumer" seems a bit problematic; it leaves the door open to discussions about who the consumer is, and thereby who is accountable. I'm glad you brought up GPDR - it seems to take the right approach, with regards to protecting personal data no matter who's holding it.
The post I responded to, I think, made a very good point about responsibility being on service providers rather than OSS contributors.
However, the wording about "providing the service to the consumer" seems a bit problematic; it leaves the door open to discussions about who the consumer is, and thereby who is accountable. I'm glad you brought up GPDR - it seems to take the right approach, with regards to protecting personal data no matter who's holding it.