- The UK ICO's Guide to the GDPR is a good step. Kudos to those who got the budget passed to do that. https://ico.org.uk/for-organisations/guide-to-the-general-da...
- Produce clear example cases before things are litigated. That way, you don't run into the problem of "Well, nobody really knows how things are going to shake out and people are trying to stay in the middle of the pack in terms of compliance" (Which is what I heard from an entrepreneur at a panel at Slaughter & May)
- Hire someone to write The Manga Guide to GDPR Compliance, in the style of https://nostarch.com/mg_databases.htm Or in the style of http://lawcomic.net/guide/?p=1585.
- Post video courses with the same sort of content.
Part of the problem here is that law firms have a strong incentive to publish SEO-optimised content which proclaims that compliance is difficult and confusing and that you should hire an expert law firm.
At that point, the discussion would be all about all the "jobs we would destroy" and "businesses opportunities we would shut down!", and heavy lobbying would make sure it gets nowhere.
The information you provide to people must be concise, transparent, intelligible, easily accessible, and it must use clear and plain language.
https://ico.org.uk/for-organisations/guide-to-the-general-da...
They recently came out with a new screen asking users to consent to a bunch of things, so they weren't compliant until then, and I wouldn't bet they are now.
Liability means that mistakes are (hopefully) punished more proportionally to their effects, which allows one to scale measures as the business grows. Meanwhile, the transparency means that any potential issues are easier to spot, making it possible for suits to be brought. Note that transparency towards users has been shown to be rather ineffective, similar to how no-one reads the eula.
No it doesn't. Everything was working completely fine before.