That all seems completely reasonable to me. It's certainly reasonable that a new start-up or side-project should use these considerations as part of their design, and I should think that an existing start-up or side-project that does not comply should look hard at why not.
If you think these demands are unreasonable, I'd genuinely be interested in knowing which, and why.
It's unreasonable, because it imposes an administrative cost on anyone that tries to do things on the side regardless whether they have good data handling practices or whether they have any intention of abusing the data. I would bet money on the fact, that JUST the fact that they must respond to a letter is enough to make some people go do something else. And who knows, maybe the side project could've been the next google.
For customers, how many requests would you expect? One in 100? One in 1000? If I store the data securely, and I only use it for the purpose it was intended, I can automate a response that (a) Sends them a copy of their data, (b) points them at the privacy policy saying I don't do anything unexpected with their data, and (c) offer a link to delete their data.
Once set up, these should not place a significant burden on the provider of a service.
I suspect we are arguing about how much work will be required. I'm saying that once set up, the administrative overhead is negligible, you are saying it isn't. Certainly the services I run have seen no increase in administrative load, I'd be interested to know who has seen a significant increase (once already set up) and why.
You're counting on an automated response mollifying users and being seen as reasonable by each of the EU's twenty-eight regulators. Perhaps that is true.
If so, a reasonable regulatory regime was produced. If it is not, or it is for a while and then one country decides to go ape shit, this was a bad law. Until we have more data there is regulatory uncertainty. Within that uncertainty is risk. That risk is unreasonable for non- or low-revenue generating projects.
Moreover, there is more precedent for such regulatory regimes becoming more, not less, onerous over time. That leads to incumbency bias, since Facebook and Google no doubt already have lobbyists for each of the national data regulators.
I frankyl don't understand why web site owners are entitled to a wild west, now-law zone?
That's a very dangerous sentiment to have. Identity theft is a very real thing. You can do pretty horrible things impersonating other people, things that will lead to people ending up in jail, things that can ruin whole families and drive people into poverty, desperation, and suicide.
It opens people up to blackmail, manipulation and a whole list of other, rather nasty, tactics.
On the extreme end, there's also the fact that not everybody lives in a "free country". In many places saying the wrong things, even online, can have very final consequences. In such cases, you not taking proper care of your user's data, sharing or leaking it all over the place, can result in people vanishing in some torture dungeon never to be seen again.
The consequences to me, personally? Not much. I haven't been blackmailed, I haven't been impersonated, jailed, or driven to suicide.
And in this, I am not unique, not unusual. Probably at least half of the adult US population has had all their information leaked just like mine was. The overwhelming majority of them suffered few to no consequences.
Adding legal costs like this de-incentivizes website owners which is now causing websites to shutdown EU access which I don't like.
I don't get why the EU thinks there are entitled to get content from the web while not abiding by the business model for targeted advertising companies.