And the 'business' requirement is more about "doing business" in the state and not "the service provider is a legally registered business", so individuals also must comply.
I think you are underestimating the impact. Anything that stores account names or emails (forms, comment sections, commerce sites, ...) is a very broad list.
Even if none of this is true and you ONLY serve static content without analytics delivered to the user you are not guaranteed to be safe. Apache by default logs IP addresses [1].
[1] https://www.ptr.co.uk/blog/which-ip-addresses-have-accessed-...
I'm pretty sure some of the websites I'm running are breaking laws in about fifty countries, but I don't care because I don't live or do business there.
But but but, we gotta protect the children.
But but but, we gotta stop people from saying bad things that could hurt the feelings. Free speech bad. Must regulate speech.
Cycle forward a decade: the government is going too far! This is outrageous! Too much surveillance! Muh privacy. Who gave them all of this power?!?
Yeah, gee, who indeed.
Whether this is accurate or not, I think it's clear the deluge of privacy legislation will have the opposite of the intended effect in terms of empowering the facebooks, googles, etc who can afford an army of lawyers, privacy engineers, privacy ops people, etc.
Not to mention all the patent trolls. Have login functionality, there's another lawsuit threat you're going to have to settle for $10k.
But at the same time I’m very much not into great firewalls.
[0] https://www.howtogeek.com/701176/does-apple-track-every-mac-...
It's an arms race all the way to the collapse of the system (or revolution). Rinse, repeat.
How easy is it to hack an iPhone to make it run unsigned code, which reports to a remote server that it is running the latest iOS version (with the correct cryptographic proofs)?
Maybe other phones are more hackable right now, but I'm sure Apple wouldn't mind lobbying for a law that requires phones to meet the same standard as them, and that makes ISPs / mobile networks refuse access to any device whose Secure Boot implementation has been circumvented by "independent researchers".
Five years from now, the only people inconvenienced by such a draconian law will be 1) those whose phones run on completely Free Software, and 2) those who illegally import devices that use unpublished zero-days in order to commit highly profitable crimes online. Both groups will probably end up paying thousands of dollars per device, but governments will not care about the desires of either of them.