Earlier quoted context omitted.
If you're careful about how you store personal data in the first place, meaning you start a greenfield project today, being compliant with GDPR is a breeze. You make it sound like there is a ton of paperwork to fill out because of GDPR if you start a business today, which there isn't.
>If you're careful about how you store personal data in the first place Unfortunately this is a really big "if" looking at typical businesses. They have no idea about how compliance should work and they also hire barely qualified people to marketing teams (often interns), who may accidentally add some privacy-breaking stuff. To prevent that they hire an external DPO and then deal with the paperwork for that DPO, who…
Consider if wire fraud wasn't illegal before, but next week there is a new law coming into effect that makes it illegal. Of course all the companies who were doing wire fraud since before will struggle to be compliant, some might not even be feasible to run anymore if their core business becomes illegal.
Again, sounds like it works as expected, compliance for organizations who been ignorant for a long time is expected to be more cumbersome.