GDPR only came in two or so years ago, it’s hardly out of living memory that we had standards more like the US
The trouble with the DPA was fines capped out at £500k and international enforcement was limited so large international companies like Google and Facebook could treat the law as an optional slap on the wrist while smaller international businesses effectively flew under the radar, the GDPR largely rectified both of these issues while modernising the laws in response to issues that generally didn't exist prior to the mid 2000s.