> People who say this quite simply haven't looked at the law or tried to comply themselves.
I have, and it's things you should have been doing anyway. I'm curious what your business is that complying is too onerous.
There are some parts that are inexact, like how must a company protect data and exactly what data is considered PII. Thing is, if you treat any data that could identify a person as PII and
a) Protect it as such
b) Keep a living document on your site listing the data you capture and why
c) Get and store consent
d) Allow a user to 'be forgotten' and/or export their data
e) If you change the data you capture or what you do with it, you must get consent again
If you follow those steps you have complied with the spirit of the law [1]. Too many companies today capture more data than they need to provide the service the user signed up for, and then sell that data later when the service can't support itself.
The high end of the fines are high, but that is the only way to get companies like FB and Google to fully comply. Hopefully spammers who I never gave consent to email me will also get put out of business, but they are like cockroaches and impossible to kill.
[1] There are other points like you can't force consent, i.e. download this white paper only after you consent to accept marketing emails.