Earlier quoted context omitted.
For sure, GDPR is causing headaches for companies that were secretly selling your data. But it's also a big problem for companies that were (perhaps sloppily) logging & storing data for their own reasons or maybe even for no real reason. I think the latter is much more common than the former.
I think there's also a sizable number of companies that basically were already compliant... but aren't sure. It's not like you can submit your processes to the EU for approval. You don't actually know if what you're doing is OK unless, some day, a regulator decides it isn't.
Unless, of course, one is shortsighted enough to compromise business in order to avoid being bothered with law compliance, a rather common attitude among the aggressive startup-minded audience of Hacker News. I look forward to GDPR-like laws in the USA.