Earlier quoted context omitted.
I don't think this is a very well through out opinion of GDPR. GDPR applies equally to all companies that trade in Europe, not just US companies. So it's difficult to describe it as an attack on US companies. Additionally GDPR simply enshrines some pretty basic social norms around informed consent and transparency. It doesn't prevent anyone doing anything that's privacy invasive, it just requires that: 1) You tell pe…
As I've commented below it's disingenuous to say that GDPR applies equally to all companies when it was conceived with US tech companies in mind and is designed to alter their business models. 1) Some of the ideas in there are welcome. 2) When you put roadblocks in front of every data point it's difficult to develop a half decent pattern matching system. A consent prompt upon joining ought to suffice. > technology co…
In other words: I really doubt that this is a targeted attack on the US/US companies.
Finally, I think a lot of GDPR is at least as hard to implement for non tech companies as it is in tech/information type companies. The latter at least have lots of in house expertise in both tech and usually tech related law. It's just really expensive for them. More traditional companies that run some crazy IT system built by an outsourcer 20 years ago might have a bigger problem.
Disclaimer and source: implemented several GDPR components when working at Booking.com.