What's interesting about the GDPR is that it's ambiguous and vague and it seems like "we're ok with that", whereas in the U.S. ambiguity works against the legislators because a court is supposed to rule on the side of the defense if a law is too vague.
In the EU, it's basically expected that the courts will apply the law on a case-by-case basis, which opens the door to inconsistent application of the law and ultimately to selective prosecution.
In the case of Meta, it definitely seems inconsistently applied (even though I hate Meta and would never trust them again). They simply choose the seemingly worst offender (Meta) and try to kick it out of the EU, while leaving alone the actual worst offender (ByteDance). Prosecution becomes a case of politics rather than justice.