https://www.cnil.fr/fr/loi-78-17-du-6-janvier-1978-modifiee
since 1978 and I didn't see anybody on HN panicking at the thought of doing business with french citizens, although these laws are tougher than GDPR. Remember than the latter is enforced at the country level, it's not Europe who is going to fine your business. Which means maybe Czechia will let you fly with whatever you are doing with personal data, and maybe Spain won't because they have tougher user data protection laws. My point is GDPR didn't create a new legal risk that wasn't there before. It's just that people here didn't care before for some reasons.
Now I see all these "GRPR compliant"(whatever that means) seals on different products, but where they even "CNIL compliant" before? Is that framework "CNIL compliant"? How many of you did a declaration to the CNIL before harvesting data from french citizens?