Earlier quoted context omitted.
>because its based on principles rather than hard rules They tried hard rules, rather than principles with the cookie laws and the companies around the world turned a good idea into a shit-show of popups while continuing to behave like nothing happened. Honestly the more I read and the more I see how different business react I start to view the GDPR as EU finally showing that will not accept businesses viewing it as…
95% of my GDPR work has done nothing for actual privacy. If this is how the EU "represents the best interest of 500 million people," then no thank you.
I think a lot of that is down to decisions taken by US-based management that is simply clueless about how law works outside the US. And probably also only got their information from US-based lawyers that were either as clueless as themselves, or had incentives to make everything look very complicated.
On the other hand, most of the companies around me that have no links with the US were not particularily worried, and either consider that they are already compliant, conducted minimal work to be acting in good faith, or at worst are waiting for the regulatory body (CNIL here) to tell them what they are doing wrong, if that is the case.
However, I don't know any company that does shady things with their users' data, and things might be very different for those.