Between "no, we don't want either US companies or US government to have full unlimited access to any data they want" and "EU requires you to be extremely careful with user data, not siphon it willy-nilly and not transfer it to other jurisdictions just because" I chose option two.
The "undesirable side-effects" are being sold as undesirable first and foremost by US companies (and US government!) who assume that everything and everyone belongs to them.
Does it suck to be stuck between a rock (GDPR) and a hard place (the US' continuing desire to not care about user privacy)? Yes. What amazes me though is that the only side that gets blamed is GDPR.