I'd say, for the companies I've met the cost they had with GDPR had a pretty good ROI even if there was no enforcement of GDPR. Not all companies see it that way, though.
Anecdotally, I enjoy being able to finally tell companies to forget me and stop sending me spam. It has actually worked very well for that. I also enjoy being able to report companies blatantly and maliciously infringing on my rights, because it finally makes me feel like maybe I'm not just some cattle to be exploited for someone else's benefit.
Another benefit of having the right to be forgotten is that I (hopefully) won't pop up in so many future data leaks. I've been fortunate so far that nothing serious has ever been leaked about me, and I've insulated myself well from leaking passwords because I use a new random one everywhere. I do however know a few people who have been burned this way and subsequently become the victim of identity theft. Being that the police lacks incentive and ability to do anything about this (I know this from personal experience, I do not live in a third-world country or even one that is moderately poor), the only cure for this problem is prevention. It helps me to sleep better at night knowing this risk has gotten smaller.
I agree on 20k not being very much given the circumstances. However this is the first time that a company had to pay for a thing like unhashed passwords at all. So I guess it's a step in the right direction.
It's honestly the first case where I heard that and I've been working with companies to become compliant since the start of the year (many still struggle to be fully compliant). Could you elaborate a bit?
This is starting to sound a bit thin, so I'm not really sure what this guy is talking about.
On the other side, when something goes wrong shooting an email citing possible gdpr infringement is now mostly enough to get an answer by a real human being.
So quite frankly, I see this as an overall positive thing.
This happens to me too. I see this as a major negative thing.
The first it happened to me, I felt it as a type of censorship. In this matter, GDPR raised a big wall between u.s. and europe.
The website achieved GDPR compliance. End of story.