1. Cookie popups. Enough said.
2. Its extraterratoriality claims. Yes, I know you also want it to apply to companies in, say, Japan. Bummer. Unless they signed a treaty agreeing to abide by it, their they're own sovereign entities and their businesses don't have to comply with remote EU laws.
3. The annual moderation report. I've lost an aggregate of several weeks of my life filling out reports where 99.9% of our moderation actions were to delete link farms, fake drug sales, phishing portals, and cockfighting fliers.
4. The misperception that GDPR means you have to delete everything. Uh, no. If we suspend joe.scammer@gmail.com's account for phishing, we're not obligated to purge every instance of that email address from our systems, especially not the one that gets to decide whether a new user is allowed to register for another account. And if "joe.scammer" deletes his account, we don't have to return "joe.scammer" into circulation so another user can register it, and simply saying that "joe.scammer is not available" is not disclosing sensitive data. And in any case, a company entirely outside the EU isn't compleleled to do it anyway (see #2).
Love the idea, strongly dislike the implementation.