I think politicians really care about these things. But these big sweeping laws and changes are because of hubris (but then again, the job selects for that).
Society is damn complicated, everything affects everything. Making a change in one small part propagates quickly and unpredictably. But politicians don't internalise that (of course, if they did they would never get elected on the platform of "stuff is complicated, I don't know if this will help!").
So they see a problem. Our information is being used maliciously! We need to stop that! Protect the people! So some massive law gets passed with tons of unintended side-effects and it's captured by big corporations at the speed of light.
Besides, I don't see how stupidity and evil are mutually exclusive. Historically, they seem to always go hand in hand.
This isn't the first time the EU has done something that screws small businesses. VAT on digital goods was another case (there was no minimum threshold). At some point it'll start to seem intentional.
So... define "tech". If you mean "adtech", say that.
I do mean tech. An industry tends to breed more of the industry. Adtech is part of tech and a lot of online businesses rely on ads. If you remove that you also remove a large chunk of people that would work on this type of tech. Then some of them instead end up working for some US company. Europe has a much larger population than the US. Europe is largely as educated as the US. Where's our Microsoft, Apple, Google, Amazon, Samsung, Sony etc? We have SAP and that's it.
Edit: I like the idea of GDPR, but I cannot stand how people think it has no cost. A large portion of the internet relies on the ad industry.
Due to the minimal privacy implications, logs which (a) only store the minimal personal information feasible, (b) are deleted after a short period of time, and (c) are accessed in order to fix bugs or provide requested support are covered under the legitimate interests basis, according to my country's regulator.
> How do you track all of that data on developer machines?
I don't, it doesn't wind up on developer machines, it never gets copied out of the system where it's stored - it can be viewed "in situ". For the vast majority of personal data in the vast majority of companies, you're allowed to assume that employees who have a reason to access it are not stealing it. If you get to a point where you're not one of these companies, you know about it, because you're already doing things like "hiring a lawyer to write our privacy policy".
> How does your system delete data from all backups?
I don't, but my policy will state how long backups are stored for as recommended by my regulator, and my process for restoring from them will involve deleting data which has been deleted for legal reasons since the backup - basically, "re-run the DELETE FROM query for everyone who's asked for their data to be deleted".
> Do you have an automated system a use can request all their data from?
Nope, but that isn't legally required by the GDPR - it's an operational efficiency if you're the sort of company that gets a lot of GDPR requests. Manual processing is fine and likely operationally efficient, as long as you know where personal data is stored in your system.
> How do you validate that they are who they say they are?
My intention is to respond with "you can verify your identity by logging in at https://X/login with your username and password and sending us your 'support code' from the settings page", handle password resets via email according to industry standard, and anything else I can respond with "we cannot verify your identity using the information you have provided" because, well, I don't hold other information I can verify people with.
> How sure are you that all your processes are legally enough?
Given that I am not an adtech company and have documentation showing that I am attempting to comply, I expect that my regulator will follow the approach they've taken so far, which is to notify me of a potential breach of the regulations and allow me to fix it before attempting to fine me. By the time I am in court I will have known about a potential breach of regulations for several months, including communication with the user and regulator, and will have had an opportunity to either fix the alleged issue or talk to a lawyer about it.
Europe has a fair chunk of tech, btw. SUSE's here, Spotify's here, Adyen's here, BlaBlaCar is here, there's a variety of food delivery companies which are generally being far more sustainably successful than their US-based counterparts, Skyscanner are here. TransferWise is here. The difference is that our companies largely have a business model from an early stage, and US companies don't, so they take up huge amounts of the market for a short period of time and then go bust.
There's a cost to not having the GDPR - that of our individual privacy.