This should probably be a blogpost, but for now anyway:
* The GDPR was a good try, but - inevitably, given the politics - a compromise. There are bits that I would change.
* I am massively unpersuaded that wholesale reform / revocation is the way to go. But then I am not trying to build a widespread surveillance or AI tool.
* DPA guidance is pretty good, in terms of scope and accessibility.
* Enforcement is inconsistent, and DPAs are generally underfunded (which may or may not be linked to underperformance).