Understanding full well each standard solves different problems, for some of us in tech achieving compliance is a non-trivial amount of critical work and maintaining it similarly isn’t always something you easily drop everything and make happen in a day or two.
I think that’s 100% relevant and shouldn’t be immediately responded to as others have by assuming the relevance comes from a position of opposing the regulation or standing against user privacy
The problem with this is twofold:
a: 'Most' (by loudness or other perception) of the complaints are known to be bad faith because they're coming from malicious actors like Facebook or Google which we know are against user privacy (since that's their business model).
b: You have to go out of your way to build a site that interferes with actual user privacy, for example by actively adding Google Analytics scripts or faux-CAPTCHAs, or actively demanding a real name and actively doing something about it if the user lies to you. (Technically you get IP addresses by default, but much like mailing addresses, obscuring these pretty much has to be the user's responsibility, since how else would you respond to them.)
So if you want a assumption of good faith, you need to be clear that you're complaining about the bureaucratic compliance overhead (eg having a particular data processing officer or whatever GDPR calls it), rather than about having to change your object-level service to eliminate spyware that you went out of your way to incorporate in the first place.
Is this a bad thing? If we take privacy seriously then it shouldn’t be. We don’t see too many people fighting food or drug regulations intended to keep us safe because it might be costly for companies to comply. Maybe if a company cannot afford to comply with privacy regulation they should not be handling our personal information. I guess the reason it seems heavy handed in the tech/web world is that the barrier to entry started at next to zero and so much of what we put on the web is not monetised that any cost/compliance seems like a massive burden.
If you had less intervention with respect to privacy would there be more dynamic market-driven initiatives to fill the gaps? Would there be more incentive to develop technology that would be effective for privacy? I don't know.
Regulation is just hard because reality is complex and dynamic and regulation is often complex but not very dynamic.
This is hilarious. Because we had that, and it was lacking, to put it mildly. And some people still have that, in a way that's easy to compare (e.g. EU vs US, CA vs other states). For me, the results are in and obvious. Privacy regulations are the only thing that reflects the privacy externalities they might impose on society back onto them (and the shareholders).
However it does serve as a moat for players with more capital, and that's something we should also be mindful of. For instance, maybe we could have some of the requirements scale and only kick in when a product meets certain thresholds in terms of numbers of users.