It certainly does. You need to weigh the users privacy with your interests and can’t just put them aside. Noncompliance leads to quite large fines. You can easily find examples of fines given.
The DPA’s are short on capacity, sure, and large corps will try to fight the fines in court. But to describe it as “just hoops whilst allowing everything” is unfair.
> You need to weigh the users privacy with your interests and can’t just put them aside.
Who said anything about putting them aside? There would be a process and highly paid lawyers confirming that selling user data is only for the user's ultimate benefit, as it allows to provide awesome services to the users, and it all will be outlined in a 100-page privacy policy which you will be sure to read on each site you use, wouldn't you?
> But to describe it as “just hoops whilst allowing everything” is unfair.
Can you quote me the place where GDPR prohibits this? Not says something like "weigh user privacy" and "take adequate measures" and so on - which can always be resolved as "we weighed carefully and we took measures and we decided selling the data was awesome and users love it" - but explicitly and unambiguously prohibits the practice? If you don't find it - that description is exactly what it is.