Undue burden of what? Keeping their data in order? Ooh the terror?!
By happenstance i was working in one of those smaller businesses when the law first came to be and i was one of the dudes whose job was to make sure we followed the new regulations and it was hardly an ordeal. Now years later the amount of the time i spent monthly doing work with GDPR requests is so negligible, it really did not matter workload wise if the law even was there.
Is it really so hard to imagine things might work differently in somewhere else?
Uh. Hope you like the taste if your hat. The whole marketing indrustry in EU, from online adds to telemarketing has fundamentally changed the way they can and will advertise to, or contact their customers or potential customers.
Data breach notifications have been getting much better. GTPR demands that after finding the breach company has 72 hours time to notify customers effected, if later time there are any proof company has tried to cover databreach they get hit by the fines. By 2025 there had already been over 281 000 data breach notifications. Including notifications from big companies like Google, meta and amazon. Before GDPR those companies had no need to report any of those.
Fortune 500 companies have spended over €7.8 billion to comply with the law. Do you think none of that money has made any changes how they do busines?
But you are right. Its not perfect and big companies keep lobbying against it and there are new hurdles like AI that still needs to be figured out. But saying it has amounted to nothing or trying to belittle its effects is just playing in to the hand of those tech companies.
If it does not work, why would other countries and states like California bother to make their own similiar legistlations?