There are some built in problems when it comes to this sort of regulator-esque legislation.
If a company doesn't want to "do X," but is being forced to, the specific, legalistically deconstructed definition of 'X' gets very important. On the path between the kind of grand moral statements politicians trade in to the way corporate lawyers use language... a lot gets lost
A common 'X' is "inform customers of something": pharmaceutical side effects, the real interest rate on a loan, etc. This often leads to a cat and mouse game, where companies "inform" customers by way of 10,000 word small print documents they know no one reads. Then the regulator tries to stop it, saying this information must be part of all advertising. Then we get verbal small print. Etc.
This is why regulators exist, to play this cat and mouse game.
GDPR, cookie laws, and a lot of the laws which effectively govern business have these issues. Our legislative/political system just doesn't deal with this well. On one hand we have politics, that hates detail. On the other hand, a legal bureaucracy that hates principle. It also doesn't care for economics and isn't too worried about creating environments devoid of real competition, which is an unwanted side effect of getting "regulatory."
In any case, the real underlying problem here, IMO, is that 3rd parties should not have this kind of control in their hands in the first place.
HNers will probably reach for blockchains and smart contracts, but this could be build into credit cards or any payment method. It doesn't really matter.
Just put the ability to turn payments on/off in customer's hands. Send the service a notice. Done. We've built up all these "convenient" ways for customers to authorize repeat payment, without building in an off button. Now they're regulating the use of them instead They should have an off button. That's it.