Note that I'm certainly NOT a lawyer.
..but still here in European Union the preference has been (at least pre-GDPR era) to first give a written warning to service provider about not being inline with the regulations. This has also included a period during which the provider can fix it's behavior. If regulations are not met after given period only then (usually progressively and aligned with the extent of the business and real damages caused) monetary penalties will arrive. This is EU not US.
When looking here from Finland GDPR is not that big change as we have had quite strict national regulations in place since 1999. The biggest change here is that user should really be able to get all it's data removed permanently from whatever service she/he has previously used (usually referred with terms right-to-be-forgotten). Another big change is that it is not anymore up to only the actual end-user to raise a lawsuit about personal data losses but to give also for an authoritative entity possibility to raise that lawsuit without prior actions of the original end-user.