I have, and it's things you should have been doing anyway. I'm curious what your business is that complying is too onerous.
There are some parts that are inexact, like how must a company protect data and exactly what data is considered PII. Thing is, if you treat any data that could identify a person as PII and
a) Protect it as such
b) Keep a living document on your site listing the data you capture and why
c) Get and store consent
d) Allow a user to 'be forgotten' and/or export their data
e) If you change the data you capture or what you do with it, you must get consent again
If you follow those steps you have complied with the spirit of the law [1]. Too many companies today capture more data than they need to provide the service the user signed up for, and then sell that data later when the service can't support itself.
The high end of the fines are high, but that is the only way to get companies like FB and Google to fully comply. Hopefully spammers who I never gave consent to email me will also get put out of business, but they are like cockroaches and impossible to kill.
[1] There are other points like you can't force consent, i.e. download this white paper only after you consent to accept marketing emails.
The spirit of the law is not the letter of the law. And as we all know, a single violation of the letter of the law can result in fines of up to $20 million.
While doing business in Europe I sometimes got some things wrong, for example with taxes. I wasn't really punished even once - I just had to pay what was missing and correct the documents, even if the maximum punishment for what I did (or failed to do) was some years in jail.
You will not be fined 20 million for that. This argument is beyond absurd.
I don't know what is more absurd: people repeating this on HN or those who actually started to believe this FUD.
It's not FUD when that's what the law says in black and white.
Edit: typo (proportional->proportionate)
By whose definition? Germany might disagree with you.
You could totally eliminate the risk of meteorite impact on your business by relocating down a mineshaft...
I like the GDPR. It's a lot easier than ISO9001/27001 and actually nearly falls out if you have those.
How many times have we whined and opined about a lack of responsibility displayed towards our personal data? Now a major bloc in the world is trying to get to grips with that issue with some pretty decent legislation (IMNSHO.) Do you have any idea how difficult it is to get something like this ratified by the EU? Do you have any idea how diverse the EU actually is? Getting this thing out is a massive feat.
In the EU, we all have to comply with GDPR by default - all of us from cobblers to rocket scientists. I'm sure you'll manage.
We (UKoGBnNI) are still in the EU for now - next year we sort of leave (ish!!)
I've always whinged about those self serving bureaucrats in Bruxelles. Some of them are our own home brewed UKIP lot. It says a lot about democracy that UKIP or the SDP (int al) can even exist.
We'll see what happens to the little old UK post Brexit - it will be written up as both a triumph and a disaster and yet I suspect life will tick on, much as before.
GDPR on the other hand: that is important and worth paying attention to.
Bear in mind the UK use Sterling and the RoI use Euros. A NI person could work in RoI and be paid in EUR but pay rent etc in GBP. Obviously the reverse is true a RoI citizen might work in NI and be paid in GBP but needs EUR to live on. All a bit of a pain and of course the bank's exchange rate doesn't help.
It is easy to poke fun at those at the edges but I think on balance a bit of sensitivity might be warranted here. Little Britain might think that they (we) have some problems to deal with wrt Brexit.
I would suggest that we might look at NI and RoI and at least try to understand that the really important issues are right there - those issues and our responses to them are the ones that really define what sort of people we are now and will be in the future.
The rest is accounting.