Earlier quoted context omitted.
> I think that currently pretty much every service, device and website violates the GDPR. Not really, my website doesn't :-) In case you're using Google Analytics, it's easy to make it compliant, you just activate IP anonymization, which you had to do anyway, out of common sense and because tracking by IP without consent was illegal anyway in countries like Germany. [1] https://support.google.com/analytics/answer/276…
> I'm sure the cost will be high for many companies, but that's just karma. What about for companies that do handle user data responsibly, but have trouble with the formal compliance costs?
There's also no such thing as responsible data handling for services tracking users without their consent. If no explicit consent was given, consent obtained with a layman explanation and with no dark patterns, then it shouldn't be legal.
The problem often isn't how the data ends up being used, the problem is that the data is collected in the first place.