GDPR and other EU privacy/safety regulations are good in principle but the task of auditing software for compliancy is going to lawyers, accountants (auditors), and business consultants. Is it because they are cheaper than developers? Not really, in most of Western Europe these people make the same or more than software developers.
So we now have nore non-tech people deciding what tech people can do and not do. Completely ridiculous.