> At the end of the day, what certs you trust is a personal decision. It's not a democracy; there is no need for an entire country to agree on which certificates are trusted and mandate that by law. Pick the ones who you trust, and your choice need not affect my choice. (Most of us delegate to browser vendors, OS vendors, or our employer, of course, but that is a choice. Don't like Apple's set of root certs? Delete the ones you don't trust, or use Firefox, or use Chrome.)
This isn't entirely true. Let's disregard for a moment the spy agency's wet dream that this law introduces (likely fully intentionally). The more benign intent of this law is to prevent foreign entities from the EU (Mozilla, Google, Apple) from having the final say on whether two kinds of EU organizations (site operators and root CA operators) can successfully reach their clients.
Of course you in your capacity as a consumer don't care whether I trust the same root CAs as I do. But a site operator very much cares whether all of their target audience trusts their site, and by extension the root CA that they are paying, and would like for their government to guarantee this trust.
The theoretical problem that this law is theoretically intended to protect from is browser vendors imposing hostile requirements on certificates which cost EU companies money and/or access to clients. It's a form of protectionism, ultimately.
Of course, the law is clearly being influenced by EU members' security agencies as well, who would love to have the ability to issue fake certificates for any site on the internet. With this new law, they would only need to infiltrate/coerce/fool their local root CA and local auditors, and they'd get free reign over encryption everywhere in the EU at least.