A) The law seems to extend beyond the borders of the EU.
B) It's extremely long and vague, doesn't really offer a lot of actionable advice, and nobody outside of privacy lawyers seems to really understand it fully.
C) The penalties are harsh.
Further muddying the waters, the EU and US already have some existing bilateral agreements with respect to data privacy [1], but does the GDPR supersede or unilaterally invalidate these...? Who knows?
[1] https://en.wikipedia.org/wiki/EU%E2%80%93US_Privacy_Shield