What I've seen from the world at large is not large multinationals failing at handling private information properly, but rather them not trying to handle private information properly. I.e. it's not because they're incapable of doing so if they wanted, but that they didn't even attempt to do so. GDPR is a way of forcing some of them to stop handling the information, and forcing those who do to actually start trying.