One example is data retention. Previously, data could and and was just keep around forever. With the GDPR, when you delete stuff, you can now expect it to actually be deleted from backend storage, usually within 30 days or less (yes, there are exceptions). This is nice, since it does limit your exposure in case of a breach. Speaking of breaches, they also have to be reported in a timely manner. Without the GDPR or equivalent, companies are free to suppress that as long as they want, and have done so.
Comments
The web "experience" was already a mess.
One example is data retention. Previously, data could and and was just keep around forever. With the GDPR, when you delete stuff, you can now expect it to actually be deleted from backend storage, usually within 30 days or less (yes, there are exceptions). This is nice, since it does limit your exposure in case of a breach. Speaking of breaches, they also have to be reported in a timely manner. Without the GDPR or equivalent, companies are free to suppress that as long as they want, and have done so.
I advise you to go back and read the law again. What you describe doesn’t happen and it’s not even enforced by it.
Storage limitation: https://ico.org.uk/for-organisations/guide-to-data-protectio...
Personal data breaches: https://ico.org.uk/for-organisations/guide-to-data-protectio...
Right to erasure: https://ico.org.uk/for-organisations/guide-to-data-protectio...