> The CCPA only applies to companies with more than $25 million in revenue or access to the personal information of more than 50,000 people. This is refreshing, I wish GDPR had a revenue threshold like this.
Why is that? Surely if X is bad it should be bad for everyone rather than only for big companies.
I worry that regulations like GDPR benefit the existing monopolies, and make it too difficult/expensive for startups. The legal ambiguity of it, and the additional software requirements add a lot of roadblocks if you're a small company. I'd rather the burden be limited to established companies (but I guess that isn't quite fair either).
And for small/side projects, I just don't want to worry about this stuff.