> how these data protection laws are implemented in general and I wish the discussion would be about that instead
Let’s do that, shall we?
Before GDPR there were laws in each European country protecting private data (GDPR is basically Sweden’s data protection law in that regard).
Not a single “poor company that will need comply” gave a damn.
Then GDPR was introduced, discussed, amended. Quite publicly. Not one of the “poor devs that would be hit by it” gave a damn.
GDPR was passed and companies were given two years to adjust their software/systems/business practices to comply. Hardly any of the “let’s have a discussion shall we” devs gave a damn until the last few months of the transition period.
And only when they realized that they had to actually do something, something they should have done literally years ago, we had (and still have) this fake outcry of “boohoo these laws make us work hard and do right things and we don’t wanna”.
Cry me a river.