That's just politics. It would be exactly the same at the national level.

That doesn't make it better. As far as I am aware the US does have rules that distinguish like that.

Implementing regulations for every company as if they are the same is what is absurd here.

The US are many things, but certainly not a model on the subject of personal-data protection.

Again that's missing the point.

There is a difference between making a law that punishes wrongful use of information and then forcing companies to do things a certain way. That's the point here which seems to be missed on most.

