The laws are specifically designed to target US firms without affecting EU ones and enforcement of fines and the size of them is highly selective -- the most attractive targets with the highest willingness to pay without getting to the point where they would pull out of the market.
If you do not see the moral hazard in this, I don't know what else I can tell you. If the EU had a seriously competitive tech industry, many of these laws would have never been created, as the EU is not some moral believer in privacy (they fight against encryption domestically), they are just run-of-the-mill protectionists like all governments.