There's a lot of nuance that could swing things in any direction. The devil is always in the details.
Can't we just look at how the previous incarnation was enforced to get an idea? Also, I think we can say it's a damned if you do damned if you don't situation. Unenforced, the law is worthless and punished only those who abided. Equitably enforced hurts a lot of smaller players. Inequitably enforced has everyone praying they are on the good side of the enforcers. Viewing through the enforcement lens can make it clearer the value, or lack of value, of the legislation akin to the value of previous versions.
To the topic of the article, the enforcement lens needs to be used as well. Even if people agreed with the potentially impending copyright laws, legislators need to take enforcement concerns seriously. This is why baby steps are ideal.
So? The goal of the law is user data privacy and control. It doesn't matter if the abuser is Google or someone operating a site from their dorm, violation and misuse of user data is still the same.
What you'll find is that accomplishing a goal is about implementation not intention. In many cases, inadequate attempts actually work against the goal.
The issue is that competition is a powerful consumer protection mechanism. A regulation that prohibits 15% of current hostile practices but also impairs competition can allow the major incumbents to be 500% more hostile to customers because the customers now have no alternatives.
It allows the incumbents to do all the bad things the law doesn't prohibit but they couldn't do if their customers had a choice.
Gdpr is a response to the prior attempts to let the industry “self regulate” not actually doing anything.
Does it over regulate? Personally I don’t think so - people talk about the complexity but that’s mostly due to the need to be absolutely explicit everywhere, and need to ensure that there aren’t loophole that can be abused by some company with enough lawyers.
Until now there was no way to guage the truth in anything they tell you and no penalties for lies.
At least the EU does something about this data gathering mania (as for why, see Bruce Schneier's essay "Data is a toxic asset so why not throw it out?" [2]); the USA, for example, doesn't (yet). The USA just repealed net neutrality. Its good in a way because now we can watch the long term effects from the other side of the pond. I suggest Americans do the same with GDPR. Observe and learn from each other.
[1] https://en.wikipedia.org/wiki/EPrivacy_Regulation_(European_...
[2] https://www.schneier.com/essays/archives/2016/03/data_is_a_t...
Last I checked one of the biggest datahoarders of all, facebook, did not actually delete your data when you told them to, instead the squirreled it away somewhere in a data warehouse just in case.
US based companies are not subject to EU law. The only reason a US based company might care about the the GDPR is if they have assets in the EU that the EU could seize. Other than that, we will happily ignore the EU's attack(s) on memory.
It's about information imbalance. Without mandatory minimums it is too easy for businesses to hide faults from consumers. I don't want websites to use business judgment when deciding whether to protect consumer privacy. I want them to fear massive retaliatory fines should they not do the bare minimum necessary to protect the public from harm.
EU countries had data protection laws for years before GDPR. Moreover, GDPR is only partially more strict than the existing Swedish data protection laws. I cannot name a single company that gave a damn about these laws.
That's why GDPR, even with all it's ambiguities, is a good thing.
GDPR isn't a well thought out regulation because the regulators couldn't even take the time to give examples of how to to migrate common internet infrastructure in order to be compliant. Instead they just threw out their shitty law and told the world to figure it out.
This new link tax further proves to me that the bureaucrats in the EU have no idea what they are doing and have no technical knowledge.
And that is the goal, isn't it?
To drive out smaller competitors from online spaces so that only the big boys can play.
${SOCIAL_NETWORK} isn't a well thought out business because the owners couldn't even take the time to consider common privacy expectations in order to respect their customers. Instead they just threw out their shitty service and told the world to figure it out.
This new practice of blocking EU users further proves to me that the execs in ${SOCIAL_NETWORK} have no idea what they're doing and have no good intentions.
If you're talking about the GDPR, from what I understand you can sign your privacy away. What can't be done, is to require you to sign your privacy away as a condition to use some service, unless there's no way to provide that service without using your personal data.