Yeah but with other states and countries saying their privacy laws applies outside of the border, seems like a bunch of duplication and conflicting laws. Kinda insane as soon as you put something on a server, you are expected to comply with laws all over the world. For example School Districts in Ohio are suing Facebook for selling ads to a charter school that went out of business.
If someone from California buys a summer house and registers a car to keep in Vermont to garage there and never drives it to California, I wonder if California considers Vermont violating their new privacy law since no opt-out but wonder if they could really enforce it on Vermont anyways. Seems like uncharted territory, but I know some companies have said they plan to follow the sticker privacy laws even if you live outside of California or Europe since it's easier to developed processes that way.
Seems like privacy law in the US is all over the place. One for banking, one for children, one for education, one for health, one for email marketing and then laws scattered all over the different states. Then I think there's even a specific law about library books checkout history too. So seems bad for startups or even mid size companies to keep up with it, especially if states start saying it applies even if you don't have a office in California.
Then if you have a service, legal requests for peoples data you have to handle and the more popular you are, the more common people might misuse your services. For example drug dealers were using Sony Playstations to communicate with each other and then Jussie Smollett for example, Google has to hand over a year of Gmail relating to the hoax he pulled(Maybe he talked to others using Gmail when planning it), but I think if he was a European citizen then providers have to decide to break US or European law, but some stuff is as clear as mud. I feel in that case they'd follow the warrant and deal with breaking European law as I don't think they'd have much choice as a catch 22.
So even if you are trying to do the right thing following the law - maybe even helping get a dangerous criminal of the streets, so many conflicting privacy laws and different agencies responsible for different ones too. Not sure though if Europe has gone after any companies for handing over data to a foreign government relating to a valid legal request where they have offices or data centers but seems you could be screwed either way when trying to decide how to handle the conflicts. Then there was a case involving Microsoft, just because you are a US company if you keep servers anywhere in the world the US can subject them to requests. So sounds like a mess for a company to decide how to handle these edge cases where things conflict, so standardizing on one would help give businesses clarity. Maybe even treaties too.