You'd have to be a consistant repeat offender, with no effort made at remediation, with no cooperation with the regulator, and probably handling sensitive or financial data.
Here's a list of recent actions taken. I think the current maximum fine is £500,000. Have a look through a few of these hopefully it's somewhat reassuring.
When I read things like this I realize how many companies are not treating user data as they should. Protecting user data should already be built into the company software and process.
Given FB revelations and additional scrutiny to Google, I see some form of this law coming to the US.
But, dispite this widespread non-compliance and fierce fines available to the regulators the sky hasn't fallen. Why do people think GDPR is sudden;y going to make things so much worse?
>Given FB revelations and additional scrutiny to Google, I see some form of this law coming to the US.
That would be good news for the EU, of course. Even before GDPR, entrepreneurs were routinely advised to incorporate in US instead, and the legislation likely added incentives for that.
>dispite this widespread non-compliance and fierce fines available to the regulators the sky hasn't fallen
Don't you really see how absolutely wrong is this? When law is composed in a way which makes it in practice only selectively applicable, it leads to erosion of justice, and invites for corruption.