Gdpr is a response to the prior attempts to let the industry “self regulate” not actually doing anything.
Does it over regulate? Personally I don’t think so - people talk about the complexity but that’s mostly due to the need to be absolutely explicit everywhere, and need to ensure that there aren’t loophole that can be abused by some company with enough lawyers.
Until now there was no way to guage the truth in anything they tell you and no penalties for lies.
Last I checked one of the biggest datahoarders of all, facebook, did not actually delete your data when you told them to, instead the squirreled it away somewhere in a data warehouse just in case.
At least the EU does something about this data gathering mania (as for why, see Bruce Schneier's essay "Data is a toxic asset so why not throw it out?" [2]); the USA, for example, doesn't (yet). The USA just repealed net neutrality. Its good in a way because now we can watch the long term effects from the other side of the pond. I suggest Americans do the same with GDPR. Observe and learn from each other.
[1] https://en.wikipedia.org/wiki/EPrivacy_Regulation_(European_...
[2] https://www.schneier.com/essays/archives/2016/03/data_is_a_t...