You're right about the 20M euros. I can't imagine where that number comes from and I don't like anything arbitrary about law.
However, I still don't agree that foreign governments can operate unconstrained by statute. Again, I'll point you to article 83 of the GDPR. It starts off with some vague statement about how supervising authorities need to make sure that fines are effective, proportionate and dissuasive. That's bullshit, but if you read further, they add quite a bit more substance to the argument.
I've just been linking to article 83, but it's likely worth quoting once in this thread. Part of it reads:
---
When deciding whether to impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to the following:
(a) the nature, gravity and duration of the infringement taking into account the nature scope or purpose of the processing concerned as well as the number of data subjects affected and the level of damage suffered by them;
(b) the intentional or negligent character of the infringement;
(c) any action taken by the controller or processor to mitigate the damage suffered by data subjects;
(d) the degree of responsibility of the controller or processor taking into account technical and organisational measures implemented by them pursuant to Articles 25 and 32;
(e) any relevant previous infringements by the controller or processor;
(f) the degree of cooperation with the supervisory authority, in order to remedy the infringement and mitigate the possible adverse effects of the infringement;
(g) the categories of personal data affected by the infringement;
(h) the manner in which the infringement became known to the supervisory authority, in particular whether, and if so to what extent, the controller or processor notified the infringement;
(i) where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned with regard to the same subject-matter, compliance with those measures;
(j) adherence to approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42; and
(k) any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits gained, or losses avoided, directly or indirectly, from the infringement.
(source - http://www.privacy-regulation.eu/en/article-83-general-condi...)
---
Also, consider that GDPR isn't a huge change over existing EU privacy legislation. The scariest change in GDPR is that it gives the European Union tools to force non-European companies to comply. While that is scary, if a non-European company has been showing a good faith effort to comply with existing EU privacy protections, they shouldn't have much to fear unless something fucked up happens.
To summarize my position, if a company is already complying with EU privacy law, they don't have much to fear. If a company is not complying with EU privacy law, they have a problem, but seeing as how the first draft of GDPR came out almost six years ago I don't feel particularly bad for them. And finally, if a company was found not to be in compliance, it would be hard to justify the maximum fines if they were showing a good faith effort to become compliant.
The wildcard here would be what would happen if a popular company suffered a massive data breach. Consider for example, the time that LinkedIn accidentally lost a whole bunch of unhashed passwords. On one hand, that's a massive breach, LinkedIn did a very poor job as data stewards and it's a perfect opportunity for a maximum fine. On the other hand, what would be the political ramifications? And where would liability flow?