My problem with the GDPR is the EU can't even be bothered to tell us what it is before the effective date. And the GDPR itself is quite vague; lots of balancing tests and blah blah with very little guidelines on what those mean in practice. So where do the guidelines come from? Funny you should ask. Consider the ICO -- the UK privacy commission -- has been promising final GDPR guidance for perhaps half a year now, an…
While I largely agree with you, for the most part enough guidance has been available that many companies have been preparing to handle GDPR. They should have done a far, far better job with this but it's not entirely a "We won't know anything until late Feb" kind of thing.
Say you have a large marketing database and you're trying to figure out the nuances of consent. Or you are a large bank and run on a fidgety mix of consent and legitimate interests. Three months is nowhere near enough time to get everything finished.