EDIT: since everyone seems to be mentioning the 4% rule, I'd just like to point out that I'm not denying the existence of this, just denying that it is actually effective. Google has violated antitrust before, and walked away with a "big" fine that's a slap on the wrist. They've violated GDPR before as well once or twice, and got a "record breaking" 57MM$ fine. The 4% rule exists and clearly isn't enforced well. I kn…
The European Union has decided that growth based on clandestine tracking of users, selling their PII without consent is not a legitimate growth tool. You know, like the way we outlawed violence as a "growth tool" Your other claims are more reasonable. But they would lead me to the conclusion we need bigger fines on bigger businesses. Not absolutely bigger, as the law already does, but relatively bigger. The more powe…
If GDPR wants to be effective they need a ridiculous company-breaking fine for big abusers like COPPA and the like. Something like a per-user fine for violations that means they either can't do business in the EU or they have to become compliant otherwise risk being basically destroyed (for reference, violating child protection laws in the US can break and have broken companies before).
EDIT: also as for the tracking growth comment -- I agree on this, but the effects of GDPR on growth tools reach far beyond this. Even basic metrics are hard to get without a bunch of hoops. Even if you store no data you have to have a bunch of checkboxes and banners everywhere. Just for using Google Analytics that just relies on what they know about your computer (fingerprinting), and uses no PII at all, you need a banner and privacy policy. The laws are making it hard to use even basic analytics without fearing a misstep.