Earlier quoted context omitted.
The gist of these laws are all the same. Just respect ALL users' data from the start, and you shouldn't have any difficulty with compliance.
Many companies have to RADICALLY change their architectures just to support these laws. And often the costs will be enormous. How do you scan all the logs that might somehow have an association with the requesting user that are in cold storage and alter data on write only archived optical media? You have to make an entire copy of it with those data removed. It's not about just treating customers better. It's governme…
Yep. And there's nothing wrong with that.
That they may suffer a large expense to correct years of misbehavior doesn't make me sympathetic to them.