Any big tech still operating in the EU did. A lot.
Any big tech still operating in the EU did. A lot.
And actual changes happens on many of these cases. An entity getting fined three of four times for different offenses doesn't mean they never fix any of the issues.
An easy example could be Google, who've been a target of so many of these complaints, and made many adjustment, up to building separate data centers with separate management rules to deal with the EU situation.
No doubt it made them spend a lot of money on lawyers to figure out the best way to keep doing it, but what good is that?
Pre-GDPR, you'd open your logs to any random company promising to come up with something that could remotely help your marketing department. Nowadays, you'll have to vet your partners and audit how your data is handled internally. It's hard to come up with concrete examples when it's basically every single company above a decent size, as they typically don't want to work against the law.
Same for the retention period, the very type of log that you'd open for internal harvesting (you could still be collecting the info, but keep it way more confidential to the point no one outside of your SRE team has access to the totality of it)
It's as if you were asking what changes the PSI and DSS compliance laws had on the card processing field.