GDPR has a major problem though. It allows use of data for "legitimate" purposes. Of course, all of these businesses think of themselves and everything they're doing as perfectly legitimate. I wouldn't be surprised if some lobbyist worked that loophole in.
That wouldn't be a major issue if privacy authorities actually a) acted on complaints in a timely manner, b) issued the "effective, proportionate and dissuasive" fines that the law requires.
Most importantly, I believe some DPAs have already stated that "legitimate interest" cannot justify online advertisement. Now they "just" need to take a snapshot of the most popular 10000 websites in their country, then start issuing fines.
The only way around would be some regulation like GDPR, but then we end up with something like cookie banners that are only annoying and don't give you a reasonable option to opt out. Just like if you want to get a mortgage, you can't opt out if every single lender does it.
Same in Norway. However taxable income does not equal salary. And at least in Norway, you can log in and see who requested the tax data about you, and companies can't mine this data.
> only applies to user-supplied data, not all personal data
I don't believe this is correct: https://gdpr-info.eu/art-4-gdpr/
Maybe you're confusing this with the different lawful grounds for processing, and the fact that consent has quite strict requirements but there are other lawful grounds that don't require consent? https://gdpr-info.eu/art-6-gdpr/
GDPR protects against automated personal data processing, not against publishing of public - by the law - data.