As someone that worked in an EEA tech company when the GDPR was actually being implemented, it absolutely did a ton for improving how much focus there was on privacy and PII security. That has seemed to be true for the places I've worked since too, from what I've heard.
Most companies still have no good process for data deletion or export, and I am fairly convinced it would be even more dire if people hadn't started preparing for the GDPR years ahead.
Yes, but now with gdpr it's enforceable, what if twit decides to stop providing that data?
It was enforceable before too, thanks to the Data Protection Directive from 1995. GDPR is an harmonization of the various national transcriptions of the DPD, plus higher fines, a better cooperation mechanism, and data portability (which is a bit useless but it's nice to have). Cookie banners also predate GDPR (it was the ePrivacy directive).
> Yes, but now with gdpr it's enforceable, what if twit decides to stop providing that data?
Why would you want a law with high compliance costs to solve a problem that was already solved? It makes no sense to impose the costs unless the thing it purports to solve actually presents as a problem.