In that regard, which law isn't sad?
Is it? I'm the marketing manager of a European app publishers with around 5 millions active monthly users (and many times more if we account for the SDK that we license to other developers). We operates cloud services as part of our offering too. We find it very easy to comply with GDPR.
As for me, I'm very glad as the end users to be protected by GDPR. I've had my data deleted or unpublished about a dozen times since the law has been enacted. And all the people around me are far more careful with how they share their data (and mine! e.g switching to Signal vs Facebook Messenger, or ProtonMail vs Gmail...).
I keep making the same settings over and over again with different websites. That should not be necessary.