You can't go idly throwing away $30 million a year, even if you're Facebook. Yes, they can get away with it once or twice, but if that is your approach to unnecessary $30 million costs, you're not going to last very long.
If it's possible to stop breaking the law in a way that the revenue drop is smaller than $30M a year, they'll possibly do it at some point. However, it's possible that the drop would be bigger, in which case the $30M/y fine is just cost of doing business.
There's a staggering amount of inefficiencies in large corporations. Just because a corpo is doing something a certain way right now, doesn't mean it's necessarily the result of a higly optimized process or rational risk/benefit analysis.
Still, agreed would be better if it was a more punitive fine!
I'd guess a good chunk of us are worth £0 (or even negative) and then there is a long tail of increasing valuable users who interact with adverts and services.
Amazing how valuable some of the users must be!
It is better for them to do something big enough to hurt, but not big enough to get all of Meta's guns blazing. This will accepted, and we can start from there with the next step (applying this same ruling to a hundred other users, or in a hundred other courts)
A million here, a million there, and before you know it you are talking about real money - Everett Dirksen
To frame it differently: if all GDPR countries were to fine similarly it'd scale up to $3-4 billion annually and that would start to hurt a little.
Someone should sum all those fines, maybe then it will have a dent?
Moreover revenue is useless in this context, we should compare with profit anyways. And maybe profit against Norway particulary or any other country in question.