> GDPR has significant scope to enable DDOSing of commercial organisations with information requests
Another way of looking at it is that it adds significant incentives for organizations to make user data more easily accessible to users. There's no reason information requests _have_ to be expensive operations.
Another way of looking at it is that it adds significant incentives for organizations to make user data more easily accessible to users. There's no reason information requests _have_ to be expensive operations.