Earlier quoted context omitted.
2. would we an extremely bad law. Even if purely "social" factors will be worked out and we come up with a perfect definition of when and how this should apply — how the fuck do you mean to enforce it? It will make only more trouble and bureaucracy for tech people (I mean actual programmers) with no useful output. Because you cannot realistically enforce it. Data either belongs to somebody, or it doesn't. Either you…
The original comment said: "[...] with strong guarantees that the data of end user who has opted for paid service is kept private and not monetized anyhow." As an "actual programmer" myself, I don't see how that would be so burdensome to implement. The data is somehow segregated so that it's excluded from being sold to advertisers in any form. The user can have their data deleted permanently at any time. It obviously…
Oh, but you will see, when your manager (who doesn't really understand the implications of various technical decisions, by the way) will order you to do something completely meaningless (in your opinion), because the regulatory documents (made by people who understand and care for the implications of technical decisions far, far less than your manager) say something meaningless, contradictory and hard to interpret in the first place. If you aren't familiar with such situation it's probably because you are not working in a regulated industry, not because these things "solve themselves" in practice. No, in practice they don't.