I'm an attorney who's spent the last year or so working on GDPR compliance for a US SaaS provider some of whose clients have EU employees. My understanding is that it's true that EU enforcement is more in the spirit of "how can we get you compliant?" before doling out fines (vs. the US where it can be more "let's make an example of this company by hitting them with a big fine" and scaring others into compliance). I a…
"This e-mail was sent to those individuals on the database where no “opt in” or “opt out” information was held"
Sounds like they were basically on a fishing expedition - if the individuals hadn't explicitly opted in, Honda shouldn't be sending them emails.