There's a lot in the GDPR that I like, but having just been through a massive compliance effort, there's a lot in there that overreaches and is just there to leech money out of the companies that make an effort to comply.
Look at the ways that the US targeted online poker sites. None of them are in the US and subject to US law. But lots of banks are, and US lawmakers made it illegal for those banks to transfer money into or out of the poker sites and that basically worked.